Getting Data In

Getting Data In
Community Activity
andrewtrobec
Hello,I don't understand why a file coming from a windows based UF does not get indexed properly.  By this I mean tha...
by andrewtrobec Motivator in Getting Data In 02-25-2022
0 4
0
4
user1717
I've followed this guide to install SC4S and connect with Splunk:https://splunk.github.io/splunk-connect-for-syslog/m...
by user1717 New Member in Getting Data In 02-25-2022
0 1
0
1
nls7010
I want to pick up logs from the same directory that have *.out and *.log in them, is there a way to create one monito...
by nls7010 Path Finder in Getting Data In 02-25-2022
0 1
0
1
tgeilinger
Hi Guys I followed the Instructions Here: https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/MonitorWindowsdataw...
by tgeilinger Engager in Getting Data In 02-25-2022
1 1
1
1
Autom8teMe
I have an external API subscription that I want to call when a specific field in my Splunk event is present (e.g. Cit...
by Autom8teMe Observer in Getting Data In 02-25-2022
0 0
0
0
roscolaw
Have a log that is confusing me on how to extract the time. From hour 01:00:00 to 23:59:59, it's fine, but the vendor...
by roscolaw New Member in Getting Data In 02-24-2022
0 0
0
0
uagraw01
Hello Splunkers!! One a everyday basis one of my Splunk instances goes down and i am getting below error. Please sugg...
by uagraw01 Motivator in Getting Data In 02-24-2022
0 7
0
7
daniel333
All, Is there a way to make a Universal Forwarder reindex all its inputs? thanks -Daniel
by daniel333 Builder in Getting Data In 02-24-2022
0 5
0
5
clozach
Hi all, We'd like to make our syslog-ng server HA. Which is a heavy forwarder instance. The plan is to clone our sysl...
by clozach Path Finder in Getting Data In 02-24-2022
0 13
0
13
VijaySrrie
Hi All, How do we know whether typing queues are blocked or not? Is it from Internal logs? From the backend of the se...
by VijaySrrie Builder in Getting Data In 02-23-2022
0 2
0
2
arangineni
We are getting /var/log files monitored from the endpoints and sent to Splunk using syslog-ng on a single TCP port. N...
by arangineni Explorer in Getting Data In 02-23-2022
0 8
0
8
Karthikeyan
Hi Experts, I have installed an application in windows server which uses 3 services(like AAA, BBB, CCC) to measure th...
by Karthikeyan Engager in Getting Data In 02-23-2022
0 0
0
0
AHBrook
Hey everyone! I've successfully set up a link from Splunk Connect for Kubernetes on our OpenShift environment. It out...
by AHBrook Path Finder in Getting Data In 02-23-2022
1 3
1
3
blbr123
Hi All, Our client as sent the syslog data using SC4S to our dev endpoints but we are unable to see the logs in our e...
by blbr123 Path Finder in Getting Data In 02-23-2022
0 1
0
1
priya1926
hi, I have a event ----------------------- DISK INFORMATION ---------------------------- DISK="/dev/sda" NAME="sda" H...
by priya1926 Path Finder in Getting Data In 02-23-2022
0 2
0
2
boromir
Hi all,  I am facing strange behavior,  for which I can't find anything in the docs. I have a source that generates C...
by boromir Path Finder in Getting Data In 02-21-2022
0 1
0
1
rahul2gupta
Hi, We are facing issue that we are unable to forward logs into Splunk via rsyslogd. They are forwarding as shown bel...
by rahul2gupta Path Finder in Getting Data In 02-21-2022
0 0
0
0
stanwindiasjlp
Hello wonder if anyone got this app working for rss feeds?. https://splunkbase.splunk.com/app/2646/#/detailsBroad fee...
by stanwindiasjlp Observer in Getting Data In 02-20-2022
0 1
0
1
Vivek_1404
Even after enabling move_policy=sinkhole, why is data still in there, verified that the path included in the monitor ...
by Vivek_1404 Engager in Getting Data In 02-19-2022
0 1
0
1
maha110192
Hello splunkies!I'm trying to be and admin and I'm doing an exercise but I cannot find the way to configure my inputs...
by maha110192 Explorer in Getting Data In 02-18-2022
0 2
0
2
lostcauz3
I have a directory that is being monitored on a splunk heavy forwarder./app_monitoring      The above directory will ...
by lostcauz3 Path Finder in Getting Data In 02-18-2022
0 4
0
4
JMondares
Hello, I'm currently undergoing a sizing exercise to determine how large of a Splunk license I need, and was wonderin...
by JMondares Explorer in Getting Data In 02-18-2022
0 4
0
4
EatMoreChicken
If I had logs for the `_internal` index and logs for a `linux_os` index on a Heavy Forwarder, does the HF prioritize ...
by EatMoreChicken Explorer in Getting Data In 02-18-2022
0 5
0
5
ChrisW-TX
Using HF to forward all events to Indexer and external syslog. When using syslog with tcp all processing basically st...
by ChrisW-TX Loves-to-Learn Lots in Getting Data In 02-18-2022
0 3
0
3
noott211
Props.conf [mysourcetype] EVAL-field1=trim(field1) Field1 must contain all fields for that source type. Is there a wa...
by noott211 Path Finder in Getting Data In 02-18-2022
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...