| Hi All,Has anyone managed to map CrowdStrike Falcon FileVantage (FIM) logs to a Datamodel; if so could you share your... by becksyboy Contributor in Getting Data In 04-23-2025 0 3 | 0 | 3 | ||
| Hi, I have onboarded palo-alto traffic and threat logs via HEC and SLS (Strata logging service). These logs are JSON ... by Splunkers2 Observer in Getting Data In 04-23-2025 0 1 | 0 | 1 | ||
| For multiple sourcetypes, linecount is 2, while clearly, it should be 1. Has anybody encountered this case? by danielbb Motivator in Getting Data In 04-22-2025 0 8 | 0 | 8 | ||
| Not sure this is even possible, but I'll ask anyway...I have application(s) that are sending JSON data into Splunk, f... by BogeyMan Loves-to-Learn Lots in Getting Data In 04-22-2025 0 1 | 0 | 1 | ||
| Hi,Unsure what is the root cause as i was trying to do some minor adjustment to ignore the [ ] at the transforms.conf... by ws Path Finder in Getting Data In 04-22-2025 0 3 | 0 | 3 | ||
| Hi,I'm facing an issue where the same data gets indexed multiple times every time the JSON file is pulled from the FT... by ws Path Finder in Getting Data In 04-22-2025 0 10 | 0 | 10 | ||
| In earlier versions of splunk i remember there use to be an option to disable active user and it will then show as st... by Mridu27 Engager in Getting Data In 04-22-2025 0 3 | 0 | 3 | ||
| Hi,I need recommendations on typo3 logs source type.Be default, I set source type as "typo3" in inputs.conf but logs ... by tech_g706 Path Finder in Getting Data In 04-21-2025 0 3 | 0 | 3 | ||
| I'm looking for a way to split a JSON array into multiple events, but it keeps getting indexed as a single event.I've... by ws Path Finder in Getting Data In 04-21-2025 0 15 | 0 | 15 | ||
| Hi Community, I'm trying to extract search results using REST API and I'm facing the following problem. 1. I'm using... by siddharth1479 Path Finder in Getting Data In 04-18-2025 1 11 | 1 | 11 | ||
| I've been writing new pipelines to my Edge Processors when I discovered that no destination values are showing up for... by Bobert Observer in Getting Data In 04-18-2025 0 0 | 0 | 0 | ||
| I've read through some of the Splunk documentation and previously one of my colleagues already configured the "Window... by tangtangtang12 Loves-to-Learn Lots in Getting Data In 04-17-2025 0 2 | 0 | 2 | ||
| We have 40 dc server sending logs to onprem indexers but i see on Deployment server i can see only on App which has o... by Hemant_h Engager in Getting Data In 04-17-2025 0 2 | 0 | 2 | ||
| I have 40 Windows 2012 domain controllers (forwarding through heavy forwarders to cloud), that intermittently stop se... by dionrivera Communicator in Getting Data In 04-17-2025 0 15 | 0 | 15 | ||
| Hello All,I have log file which has the following content in json format, I would like to parse the timestamp and con... by sabollam Loves-to-Learn Lots in Getting Data In 04-17-2025 0 11 | 0 | 11 | ||
| As we have recently enabled various audit settings on our domain, we now have 4662 events being generated on the DCs.... by stemerdink Engager in Getting Data In 04-17-2025 0 3 | 0 | 3 | ||
| Hello Experts,In Splunk ITSI, we’re able to see the alerts in the Alerts table, but those alerts are not being reflec... by manideepa Engager in Getting Data In 04-16-2025 0 1 | 0 | 1 | ||
| So the title is pretty self explanatory. I have been approached and requested to trim logs. I had initially installed... by Abass42 Communicator in Getting Data In 04-16-2025 0 5 | 0 | 5 | ||
| Based on the article provided below we have updated our Atlassian settings to pull the Bitbucket logs into our Audit ... by anandhalagaras1 Contributor in Getting Data In 04-16-2025 0 4 | 0 | 4 | ||
| We are collecting the sourtype of the data we are currently receiving by changing it as follows.[A_syslog]TRANSFORMS-... by blanky Explorer in Getting Data In 04-16-2025 0 2 | 0 | 2 | ||
| We have a architecture of 3 site multi cluster which contains 6 indexers (2 in each site), 3 search heads (one in eac... by Karthikeya Communicator in Getting Data In 04-16-2025 0 16 | 0 | 16 | ||
| Hello from Splunk Data Manager Team,We are excited to announce the preview of Data Manager for Splunk Cloud. Before y... by wni Splunk Employee 3 22 | 3 | 22 | ||
| Dear Splunk Community,I need some advice on how to get DB Connect configured. I'm hitting a brick wall trying to get ... by arusishere New Member in Getting Data In 04-15-2025 0 4 | 0 | 4 | ||
| Upon installing the Akamai SIEM I am not seeing the data input option for "Akamai Security Incident Event Manager AP... by cmutt78_2 Explorer in Getting Data In 04-15-2025 0 7 | 0 | 7 | ||
| Hi There,I have noticed that the cloud monitoring console is reporting a critical bucket. I only have one and have at... by jamie1 Communicator in Getting Data In 04-15-2025 0 3 | 0 | 3 |