Getting Data In

Getting Data In
Community Activity
spluzer
Hey Splunksters,I have an Azure VM that I put a forwarder on that is supposed to reach out to my on-prem deployment s...
by spluzer Communicator in Getting Data In 11-03-2021
0 5
0
5
Jhyde517
Last week a large portion of our Windows hosts reported in with a different "host" value. This is causing all sorts o...
by Jhyde517 Loves-to-Learn in Getting Data In 11-03-2021
0 0
0
0
Jason
I have a few windows machines Light Forwarding in to a central indexer, sending just WinEventLogs for now. For most h...
by Jason Motivator in Getting Data In 11-03-2021
4 12
4
12
mnikolov2793
Hello,I have been struggling with something that probably is common sense to experts. Part of the Splunk messages tha...
by mnikolov2793 Observer in Getting Data In 11-03-2021
0 3
0
3
rewtroy
With the AWS Add-On for Splunk (version 5.0.3) we can pull logs from a CloudFront S3 bucket via the "Generic S3" type...
by rewtroy Explorer in Getting Data In 11-03-2021
0 2
0
2
djoiret
Hello,I am using "Splunk_TA_juniper" and I noticed a new problem with timestamp: there is a one hour offset for the t...
by djoiret Explorer in Getting Data In 11-03-2021
0 4
0
4
robertlynch2020
Hi - I have a command to clean fish buckets in a forwarder - if i want to take back in data for testing etc...cd var/...
by robertlynch2020 Influencer in Getting Data In 11-02-2021
0 1
0
1
skyebrenzo
Hi!What's the best strategy if I want my AWS Lambda logs get ingested directly to SplunkCloud? I don't want my Lambda...
by skyebrenzo New Member in Getting Data In 11-02-2021
0 0
0
0
sharmaa5
Hi All, I'm using network toolkit's external lookup ping for monitoring server down in my environment, but after incr...
by sharmaa5 Engager in Getting Data In 11-02-2021
0 0
0
0
mercierj
My apologies if this question seems mundane or was answered elsewhere but I have searched to no avail.  I am complete...
by mercierj Explorer in Getting Data In 11-02-2021
0 7
0
7
rahulg
 i want to suppress alert for next 4 hoursi am trying to use throttle along with each result trigger conditionsplunk ...
by rahulg Explorer in Getting Data In 11-02-2021
0 2
0
2
cbreezier
I've set up a generic S3 input and it's working pretty well. However, I sometimes get duplicate events.I believe the ...
by cbreezier Engager in Getting Data In 11-02-2021
2 1
2
1
rahulg
I have props.conf[source::tcp:7660]TRUNCATE=10000000LINE_BREAKER = {\"timeNO_BINARY_CHECK = trueSHOULD_LINEMERGE = fa...
by rahulg Explorer in Getting Data In 11-02-2021
0 6
0
6
Raghul_S
Hi,I've added a new row to an existing lookup file for testing the query and now I need to delete the last couple of ...
by Raghul_S Engager in Getting Data In 11-01-2021
0 1
0
1
fatemabwesnet
Hi, I wanted to ask if multisite Splunk clusters can run different Operating systems without any issues.For example, ...
by fatemabwesnet New Member in Getting Data In 11-01-2021
0 4
0
4
steveo2
Hi! I'm trying to collect the local splunk server Windows Application event logs.   I would like them in non_XML form...
by steveo2 Engager in Getting Data In 11-01-2021
0 0
0
0
ssoftility
What are the configurations required to forward specific log messages to Splunk.Every  log message that contains "Sca...
by ssoftility Loves-to-Learn in Getting Data In 11-01-2021
0 3
0
3
Stefanie
The Splunk Documentation has steps to upgrade a Universal Forwarder to a Heavy Forwarder. But not any steps on downgr...
by Stefanie Builder in Getting Data In 11-01-2021
0 2
0
2
izyknows
Hello,I'm trying to setup Splunk in a lab environment. I've got one windows client which I want to send logs over to ...
by izyknows Path Finder in Getting Data In 11-01-2021
0 3
0
3
neeravmathur
Hi Guys,We have a requirement where we need to index emails  to be ingested into splunk. I know a couple of apps are ...
by neeravmathur Path Finder in Getting Data In 11-01-2021
0 4
0
4
jariw
Hi,we have got a inputs.conf with :[monitor:///home/.../.bash_history]disabled = 0crcSalt = <SOURCE>whitelist = \.bas...
by jariw Path Finder in Getting Data In 11-01-2021
0 0
0
0
priyanka_231019
Hi, We are able to fetch update logs from our WSUS server using add-on for windows. However, we want to display appro...
by priyanka_231019 Explorer in Getting Data In 11-01-2021
0 0
0
0
willcwhite
In my props.conf, I have LINE_BREAKER=field1 this breaks the events how I want but it removes field1 from every even...
by willcwhite Explorer in Getting Data In 11-01-2021
0 2
0
2
altink
Pulling database events with Splunk DB Connect I noticed that:1. New (non-existing) fields are created2. text fields ...
by altink Builder in Getting Data In 10-29-2021
0 0
0
0
akshgpt25
Hi, When i am using Splunk admin username and password, am able to get the indexes via below codeHttpService.setSslSe...
by akshgpt25 Explorer in Getting Data In 10-29-2021
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors