Getting Data In

Getting Data In
Community Activity
becksyboy
Hi All,Has anyone managed to map CrowdStrike Falcon FileVantage (FIM) logs to a Datamodel; if so could you share your...
by becksyboy Contributor in Getting Data In 04-23-2025
0 3
0
3
Splunkers2
Hi, I have onboarded palo-alto traffic and threat logs via HEC and SLS (Strata logging service). These logs are JSON ...
by Splunkers2 Observer in Getting Data In 04-23-2025
0 1
0
1
danielbb
For multiple sourcetypes, linecount is 2, while clearly, it should be 1. Has anybody encountered this case?
by danielbb Motivator in Getting Data In 04-22-2025
0 8
0
8
BogeyMan
Not sure this is even possible, but I'll ask anyway...I have application(s) that are sending JSON data into Splunk, f...
by BogeyMan Loves-to-Learn Lots in Getting Data In 04-22-2025
0 1
0
1
ws
Hi,Unsure what is the root cause as i was trying to do some minor adjustment to ignore the [ ] at the transforms.conf...
by ws Path Finder in Getting Data In 04-22-2025
0 3
0
3
ws
Hi,I'm facing an issue where the same data gets indexed multiple times every time the JSON file is pulled from the FT...
by ws Path Finder in Getting Data In 04-22-2025
0 10
0
10
Mridu27
In earlier versions of splunk i remember there use to be an option to disable active user and it will then show as st...
by Mridu27 Engager in Getting Data In 04-22-2025
0 3
0
3
tech_g706
Hi,I need recommendations on typo3 logs source type.Be default, I set source type as "typo3" in inputs.conf but logs ...
by tech_g706 Path Finder in Getting Data In 04-21-2025
0 3
0
3
ws
I'm looking for a way to split a JSON array into multiple events, but it keeps getting indexed as a single event.I've...
by ws Path Finder in Getting Data In 04-21-2025
0 15
0
15
siddharth1479
Hi Community, I'm trying to extract search results using REST API and I'm facing the following problem. 1. I'm using...
by siddharth1479 Path Finder in Getting Data In 04-18-2025
1 11
1
11
Bobert
I've been writing new pipelines to my Edge Processors when I discovered that no destination values are showing up for...
by Bobert Observer in Getting Data In 04-18-2025
0 0
0
0
tangtangtang12
I've read through some of the Splunk documentation and previously one of my colleagues already configured the "Window...
by tangtangtang12 Loves-to-Learn Lots in Getting Data In 04-17-2025
0 2
0
2
Hemant_h
We have 40 dc server sending logs to onprem indexers but i see on Deployment server i can see only on App which has o...
by Hemant_h Engager in Getting Data In 04-17-2025
0 2
0
2
dionrivera
I have 40 Windows 2012 domain controllers (forwarding through heavy forwarders to cloud), that intermittently stop se...
by dionrivera Communicator in Getting Data In 04-17-2025
0 15
0
15
sabollam
Hello All,I have log file which has the following content in json format, I would like to parse the timestamp and con...
by sabollam Loves-to-Learn Lots in Getting Data In 04-17-2025
0 11
0
11
stemerdink
As we have recently enabled various audit settings on our domain, we now have 4662 events being generated on the DCs....
by stemerdink Engager in Getting Data In 04-17-2025
0 3
0
3
manideepa
Hello Experts,In Splunk ITSI, we’re able to see the alerts in the Alerts table, but those alerts are not being reflec...
by manideepa Engager in Getting Data In 04-16-2025
0 1
0
1
Abass42
So the title is pretty self explanatory. I have been approached and requested to trim logs. I had initially installed...
by Abass42 Communicator in Getting Data In 04-16-2025
0 5
0
5
anandhalagaras1
Based on the article provided below we have updated our Atlassian settings to pull the Bitbucket logs into our Audit ...
by anandhalagaras1 Contributor in Getting Data In 04-16-2025
0 4
0
4
blanky
We are collecting the sourtype of the data we are currently receiving by changing it as follows.[A_syslog]TRANSFORMS-...
by blanky Explorer in Getting Data In 04-16-2025
0 2
0
2
Karthikeya
We have a architecture of 3 site multi cluster which contains 6 indexers (2 in each site), 3 search heads (one in eac...
by Karthikeya Communicator in Getting Data In 04-16-2025
0 16
0
16
wni
Hello from Splunk Data Manager Team,We are excited to announce the preview of Data Manager for Splunk Cloud. Before y...
by wni Splunk Employee Splunk Employee in Getting Data In 04-16-2025
3 22
3
22
arusishere
Dear Splunk Community,I need some advice on how to get DB Connect configured. I'm hitting a brick wall trying to get ...
by arusishere New Member in Getting Data In 04-15-2025
0 4
0
4
cmutt78_2
Upon installing the Akamai SIEM I am not seeing the data input option for "Akamai​ Security Incident Event Manager AP...
by cmutt78_2 Explorer in Getting Data In 04-15-2025
0 7
0
7
jamie1
Hi There,I have noticed that the cloud monitoring console is reporting a critical bucket. I only have one and have at...
by jamie1 Communicator in Getting Data In 04-15-2025
0 3
0
3
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...
Top Solution Authors