Getting Data In

Getting Data In
Community Activity
splunklearner
AWS logs to SplunkWe need to onboard AWS cloud watch logs (from Kinesis) to our Splunk. We have all our Splunk instan...
by splunklearner Communicator in Getting Data In 04-09-2025
0 10
0
10
TheJagoff
I have multiline events where it is required to capture the error messages.The events are separated by "FAILED".I nee...
by TheJagoff Communicator in Getting Data In 04-09-2025
0 5
0
5
Karthikeya
we got a requirement to on-board new platform logs to Splunk. They will have 1.8 TB/day data to be ingested. As of no...
by Karthikeya Communicator in Getting Data In 04-08-2025
0 18
0
18
Karthikeya
I was newly aligned into a project and didn't have proper KT from the left ones. I have queries regarding my current ...
by Karthikeya Communicator in Getting Data In 04-07-2025
0 5
0
5
doli
I am looking for a document to integrate Cisco cyber vision integration with Splunk. 
by doli Splunk Employee Splunk Employee in Getting Data In 04-07-2025
0 4
0
4
splunkreal
Hello,we have Windows servers from two environments, we want WinEventLog source (Windows Events logs) to go in "windo...
by splunkreal Motivator in Getting Data In 04-07-2025
0 5
0
5
toporagno
HI everyone,I need to check my logs to see if a user has MFA enabled or not. I've already configured Microsoft Azure ...
by toporagno Explorer in Getting Data In 04-06-2025
0 1
0
1
christal654
OS Version: Server 2019I'm trying to install Splunk UF in my test lab. Using the GUI install, I put all the necessary...
by christal654 Observer in Getting Data In 04-05-2025
0 5
0
5
tech_g706
Hi,I setup the syslog-ng to receive syslog from devices and splunk HF on the same server will read those logs files.H...
by tech_g706 Path Finder in Getting Data In 04-05-2025
0 3
0
3
Na_Kang_Lim
As the title suggests, I am having multiple Universal Forwarders sharing the same Instance GUID due to the mistake of...
by Na_Kang_Lim Path Finder in Getting Data In 04-04-2025
0 9
0
9
karn
I have disabled input (generic S3) of aws add-on for a year. After I enable it, it ingests old data so I disable it a...
by karn Path Finder in Getting Data In 04-03-2025
0 2
0
2
tawm_12
Hi everyone,I'm seeking advice on the best way to send application logs from our client's Docker containers into a Sp...
by tawm_12 Engager in Getting Data In 04-02-2025
0 2
0
2
Na_Kang_Lim
As the title suggests, I am having multiple Universal Forwarders sharing the same Instance GUID due to the mistake of...
by Na_Kang_Lim Path Finder in Getting Data In 04-02-2025
0 1
0
1
bhavesh0124
I'm ingesting data into Splunk via the HTTP Event Collector (HEC), but the data is wrapped inside a "data" key instea...
by bhavesh0124 Explorer in Getting Data In 04-02-2025
0 5
0
5
jitbahan
I have installed akamai add on for splunk in our HF. https://splunkbase.splunk.com/app/4310 I followed the documentat...
by jitbahan New Member in Getting Data In 04-02-2025
0 7
0
7
zafar
Hi,Windows UF stopped sending events. I saw this event in _internal index'message from ""C:\Program Files\SplunkUnive...
by zafar Engager in Getting Data In 04-02-2025
0 3
0
3
Zoe_
HelloHas anyone encountered the situation of incomplete log transmission using UDP 514? Would changing to TCP be usef...
by Zoe_ Observer in Getting Data In 04-01-2025
0 2
0
2
ArtieZ
Hi,We recently upgraded the Heavy Forwarders (HF) of our Splunk Enterprise. After the upgrade the Universal Forwarder...
by ArtieZ Loves-to-Learn Everything in Getting Data In 03-31-2025
0 8
0
8
Kyles
I've been using dbxquery connection=my_connection procedure=my_procedure to build reports and a few that my DBAs have...
by Kyles Observer in Getting Data In 03-31-2025
0 1
0
1
Namchin_Bar
Dear Splunk Support,I am encountering an issue while configuring Splunk to filter logs based on specific ports (21, 2...
by Namchin_Bar New Member in Getting Data In 03-31-2025
0 2
0
2
Karthikeya
Hi all, I am trying to pull Akamai logs to Splunk. Hence installed this app in HF  - https://splunkbase.splunk.com/ap...
by Karthikeya Communicator in Getting Data In 03-31-2025
0 21
0
21
bedrocho
                          I want to route dataI want to split one sourcetype into two.When I click Extract New Fields...
by bedrocho Explorer in Getting Data In 03-30-2025
0 4
0
4
SplunkStudent2
I'm looking for training that would cover at when deploying a TA if it would have to go to the indexer level rather t...
by SplunkStudent2 Engager in Getting Data In 03-30-2025
0 3
0
3
Karthikeya
We are installing modular input (akamai add-on) to get akamai logs to Splunk.In our environment, we have kept modular...
by Karthikeya Communicator in Getting Data In 03-30-2025
0 8
0
8
StephenD1
I've noticed an issue with one of my syslog indexes. I have a syslog server centralizing and forwarding syslogs for 6...
by StephenD1 Path Finder in Getting Data In 03-28-2025
0 1
0
1
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...
Top Solution Authors