Getting Data In

Getting Data In
Community Activity
pdominicb
I have events with URLs, and the URLs contain parameters with KV values in them. Splunk auto extracts the KV pairs, b...
by pdominicb Explorer in Getting Data In 05-22-2026
0 10
0
10
loganallen
I am trying to implement a postfilter in Splunk Connect for Syslog to drop east-west (internal-to-internal) Fortigate...
by loganallen Loves-to-Learn in Getting Data In 05-20-2026
0 0
0
0
Karthikeya
We have to pull logs from Tencent COS (Cloud Object Storage) to our Splunk instances which are hosted on AWS. Tencent...
by Karthikeya Communicator in Getting Data In 05-19-2026
0 7
0
7
volly
iv just created a new account.iv have admin role assigned to my user account iv given admin role all permissions, yet...
by volly New Member in Getting Data In 05-18-2026
0 2
0
2
spl_aficionado
We recently found out that we couldn't send TCP data as Syslog because it didn't have the proper header, but streamin...
by spl_aficionado Path Finder in Getting Data In 05-16-2026
0 4
0
4
wellsjp
We use HEC to ingest data from multiple sources but are starting to see the requirement for OAuth and other security ...
by wellsjp Loves-to-Learn Lots in Getting Data In 05-15-2026
0 5
0
5
arthy-velusamy
We are trying to ingest JSON data to Splunk Ingest Processor. Sometimes JSON data is getting ingested properly and ma...
by arthy-velusamy Observer in Getting Data In 05-13-2026
0 1
0
1
jni
Hi,I'm ingesting journald logdata, and would like to exclude all rows with "apparmor=ALLOW".To me, the journald-filte...
by jni Explorer in Getting Data In 05-12-2026
0 7
0
7
0xAli
Hi Everyone,While using Syslog-NG to monitor network traffic and write it into file,  I want to ask about the Log fil...
by 0xAli Path Finder in Getting Data In 05-11-2026
0 6
0
6
gitau_gm
I am observing inconsistent forwarding of Windows Security Event ID 4624 (Successful Logon) from multiple Windows hos...
by gitau_gm Explorer in Getting Data In 05-08-2026
0 9
0
9
kvm
Hi,I'm required to integrate the Alogsec  Security Management Suite (ASMS) logs via API method to cover the richer vi...
by kvm Explorer in Getting Data In 05-05-2026
0 3
0
3
zapping575
One of my sourcetypes is a CSV file (with CSV header)I was using this sourcetype stanza in props.conf:[foo_bar] INDEX...
by zapping575 Communicator in Getting Data In 04-29-2026
0 1
0
1
BluFalcon
I was wondering if any one has successfully onboard KnowBe4 data? I don't see a TA or App on Splunkbase.
by BluFalcon Engager in Getting Data In 04-27-2026
0 8
0
8
gnagasri
Sample events - working in regex101 : https://regex101.com/r/LuC6ZQ/1| rex field=_raw "nsssvcip\=(?<host>\d+\.\d+\.\d...
by gnagasri Engager in Getting Data In 04-26-2026
0 4
0
4
becksyboy1
Hi All,Has anyone tried to ingest Claude OpenTelemetry logs into Splunk? I'd be interested in understanding what appr...
by becksyboy1 Engager in Getting Data In 04-24-2026
0 4
0
4
Solitus31
Hello,we are trying to use splunk_app_uf_remote_upgrade_windows to upgrade our UF using Deployment server.I have inst...
by Solitus31 Explorer in Getting Data In 04-20-2026
0 2
0
2
Kat7
Hello, I would like to automatically send the audit logs from PDQ Connect into our Splunk environment.  I can manuall...
by Kat7 Explorer in Getting Data In 04-19-2026
0 3
0
3
ljo4497
Hi, We currently have a centralized WEF collection server that collects all windows logs across the environment.This ...
by ljo4497 Explorer in Getting Data In 04-15-2026
1 9
1
9
duesser
I have data of the following structure in Kafka.{"id": "ABC", "name": "lukas", "timestamp": 1775567475, "payload": 37...
by duesser Path Finder in Getting Data In 04-12-2026
0 7
0
7
durnan13
Hello Everyone!We have what we have been told is not a complete ideal setup where we have searchable data for 90 days...
by durnan13 Explorer in Getting Data In 04-11-2026
0 11
0
11
uagraw01
Hello Splunkers1!I am encountering an issue with field extraction related to the sourcetype. My requirement is to map...
by uagraw01 Motivator in Getting Data In 04-08-2026
0 9
0
9
splunkettes
When restarting an indexer in our cluster, I first put the cluster in maintenance mode. The indexer restarts within m...
by splunkettes Path Finder in Getting Data In 04-08-2026
0 4
0
4
cjharmening
Hello all,  Starting end of next week my team will be doing a POV of Splunk ES as a possible replacement of our curre...
by cjharmening Loves-to-Learn Lots in Getting Data In 04-07-2026
0 3
0
3
Beerman
After upgrading to Debian 13 Journald input is not working anymore with Splunk 10.x.This error I found in the interna...
by Beerman New Member in Getting Data In 04-07-2026
0 5
0
5
spulivarthi700
Hey team,If we want to reduce pressure on our Splunk indexers and our data is routing through Cribl, what does Splunk...
by spulivarthi700 Loves-to-Learn in Getting Data In 04-01-2026
0 2
0
2
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors