Getting Data In

Getting Data In
Community Activity
danielbb
I created a KV Store lookup using the "Splunk App for Lookup File Editing" app, however when I look at Settings>Looku...
by danielbb Motivator in Getting Data In 04-11-2025
0 4
0
4
b17gunnr
Hello folks,My organization is struggling with ingesting the Cisco Firepower audit (sys)logs into Splunk, we've been ...
by b17gunnr Path Finder in Getting Data In 04-11-2025
0 3
0
3
samuel-devops
 Commands used to run docker image: docker run -d -p 9997:9997 -p 8080:8080 -p 8089:8089 -e "SPLUNK_START_ARGS=--acce...
by samuel-devops Explorer in Getting Data In 04-10-2025
1 15
1
15
jni
Hi,We're setting up a Splunk enterprise instance in an air-gapped environment. In addition to this, the server is sit...
by jni Explorer in Getting Data In 04-10-2025
0 7
0
7
man03359
Hi,I am a splunk admin and we are re-assigning the orphaned knowledge object to my name as a temporary solution. I ne...
by man03359 Communicator in Getting Data In 04-10-2025
0 1
0
1
splunklearner
AWS logs to SplunkWe need to onboard AWS cloud watch logs (from Kinesis) to our Splunk. We have all our Splunk instan...
by splunklearner Communicator in Getting Data In 04-09-2025
0 10
0
10
TheJagoff
I have multiline events where it is required to capture the error messages.The events are separated by "FAILED".I nee...
by TheJagoff Communicator in Getting Data In 04-09-2025
0 5
0
5
Karthikeya
we got a requirement to on-board new platform logs to Splunk. They will have 1.8 TB/day data to be ingested. As of no...
by Karthikeya Communicator in Getting Data In 04-08-2025
0 18
0
18
Karthikeya
I was newly aligned into a project and didn't have proper KT from the left ones. I have queries regarding my current ...
by Karthikeya Communicator in Getting Data In 04-07-2025
0 5
0
5
doli
I am looking for a document to integrate Cisco cyber vision integration with Splunk. 
by doli Splunk Employee Splunk Employee in Getting Data In 04-07-2025
0 4
0
4
splunkreal
Hello,we have Windows servers from two environments, we want WinEventLog source (Windows Events logs) to go in "windo...
by splunkreal Motivator in Getting Data In 04-07-2025
0 5
0
5
toporagno
HI everyone,I need to check my logs to see if a user has MFA enabled or not. I've already configured Microsoft Azure ...
by toporagno Explorer in Getting Data In 04-06-2025
0 1
0
1
christal654
OS Version: Server 2019I'm trying to install Splunk UF in my test lab. Using the GUI install, I put all the necessary...
by christal654 Observer in Getting Data In 04-05-2025
0 5
0
5
tech_g706
Hi,I setup the syslog-ng to receive syslog from devices and splunk HF on the same server will read those logs files.H...
by tech_g706 Path Finder in Getting Data In 04-05-2025
0 3
0
3
Na_Kang_Lim
As the title suggests, I am having multiple Universal Forwarders sharing the same Instance GUID due to the mistake of...
by Na_Kang_Lim Path Finder in Getting Data In 04-04-2025
0 9
0
9
karn
I have disabled input (generic S3) of aws add-on for a year. After I enable it, it ingests old data so I disable it a...
by karn Path Finder in Getting Data In 04-03-2025
0 2
0
2
tawm_12
Hi everyone,I'm seeking advice on the best way to send application logs from our client's Docker containers into a Sp...
by tawm_12 Engager in Getting Data In 04-02-2025
0 2
0
2
Na_Kang_Lim
As the title suggests, I am having multiple Universal Forwarders sharing the same Instance GUID due to the mistake of...
by Na_Kang_Lim Path Finder in Getting Data In 04-02-2025
0 1
0
1
bhavesh0124
I'm ingesting data into Splunk via the HTTP Event Collector (HEC), but the data is wrapped inside a "data" key instea...
by bhavesh0124 Explorer in Getting Data In 04-02-2025
0 5
0
5
jitbahan
I have installed akamai add on for splunk in our HF. https://splunkbase.splunk.com/app/4310 I followed the documentat...
by jitbahan New Member in Getting Data In 04-02-2025
0 7
0
7
zafar
Hi,Windows UF stopped sending events. I saw this event in _internal index'message from ""C:\Program Files\SplunkUnive...
by zafar Engager in Getting Data In 04-02-2025
0 3
0
3
Zoe_
HelloHas anyone encountered the situation of incomplete log transmission using UDP 514? Would changing to TCP be usef...
by Zoe_ Observer in Getting Data In 04-01-2025
0 2
0
2
ArtieZ
Hi,We recently upgraded the Heavy Forwarders (HF) of our Splunk Enterprise. After the upgrade the Universal Forwarder...
by ArtieZ Loves-to-Learn Everything in Getting Data In 03-31-2025
0 8
0
8
Kyles
I've been using dbxquery connection=my_connection procedure=my_procedure to build reports and a few that my DBAs have...
by Kyles Observer in Getting Data In 03-31-2025
0 1
0
1
Namchin_Bar
Dear Splunk Support,I am encountering an issue while configuring Splunk to filter logs based on specific ports (21, 2...
by Namchin_Bar New Member in Getting Data In 03-31-2025
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...