Getting Data In

Getting Data In
Community Activity
twinspop
Self-answered question follows. Perhaps it will help someone else in the same boat. I have a file called portal-serv...
by twinspop Influencer in Getting Data In 05-19-2025
0 2
0
2
splunkville
[cmd_data=list cm device recusive]splunk auto extracts just [cmd_data=list]End result - be able to filter on cmd data...
by splunkville Observer in Getting Data In 05-16-2025
0 1
0
1
token2
Hello all,I am reviewing the Splunk add-on for vCenter Log and the Splunk add-on for VMware ESXi logs guides and have...
by token2 Path Finder in Getting Data In 05-16-2025
0 2
0
2
msatish
Newly installed Universal forwarders on windows servers are forwarding logs to Splunk Cloud but newly installed forwa...
by msatish Path Finder in Getting Data In 05-16-2025
0 4
0
4
LogUx
Hi Splunkers!!,We have recently configured SSO in Splunk using Keycloak, and it's working fine — users are able to lo...
by LogUx Motivator in Getting Data In 05-16-2025
0 2
0
2
ahennewig_sva
Hi,we are currently experiencing reliability issues when using the Microsoft Teams Add-on for Splunk  (https://splunk...
by ahennewig_sva Observer in Getting Data In 05-16-2025
0 2
0
2
KeithH
Hi All,Help please.Can I get people to agree with me that the following is a bug/design flaw - as my splunk case is g...
by KeithH Communicator in Getting Data In 05-16-2025
0 6
0
6
tah7004
Hello, has anyone worked with ingest-time lookup and familiar with it?https://docs.splunk.com/Documentation/Splunk/8....
by tah7004 Path Finder in Getting Data In 05-16-2025
0 8
0
8
daniel333
All, I found myself writing this props.conf today. Say I have this: [tomcat:src:server] EXTRACT-springapp_name =...
by daniel333 Builder in Getting Data In 05-16-2025
0 5
0
5
vikas_gopal
Hello Experts , I am trying to send windows security logs to logstash(http) receiver . Below is what I have based on ...
by vikas_gopal Builder in Getting Data In 05-15-2025
0 14
0
14
sreddem
Hi Team,Greetings !!This is Srinivasa, Could you please provide Splunk with Unified Applications (CUCM) On-prem , how...
by sreddem Observer in Getting Data In 05-15-2025
0 1
0
1
antnovo
Hello, have a question regarding log ingestion from Azure. At the moment, im using REST API to onboard logs to the on...
by antnovo New Member in Getting Data In 05-15-2025
0 6
0
6
tech_g706
Hi All,Anyone who has worked with OpenText NetIQ Logs before?We are receiving the NetIQ logs via syslog, but the sour...
by tech_g706 Path Finder in Getting Data In 05-14-2025
0 4
0
4
Mobyd
Hi,     I am trying to gather data from a specific organisation unit in Active Directory and ignore everything else? ...
by Mobyd New Member in Getting Data In 05-14-2025
0 2
0
2
buzzard192
I have a field with the system's IP in it and am trying to add additional fields during ingest.  It works if the IP f...
by buzzard192 Explorer in Getting Data In 05-14-2025
0 4
0
4
GaetanVP
Hello Splunkers,I have a small question, what is the best practice (or for what reasons) should I use Syslog or TCP c...
by GaetanVP Contributor in Getting Data In 05-13-2025
0 8
0
8
sgutierrez
Hello, I am new to the Splunk interface and I have been recently given a task to configure Splunk to monitor the foll...
by sgutierrez Engager in Getting Data In 05-13-2025
1 4
1
4
Dilsheer_P
I ma trying to onboard the %SystemRoot%\System32\Winevt\Logs\Microsoft-AzureADPasswordProtection-DCAgent%4Admin.evtx ...
by Dilsheer_P Loves-to-Learn Lots in Getting Data In 05-13-2025
0 2
0
2
Niro
I have the following transforms.conf file:[pan_src_user]INGEST_EVAL=src_user_idx=json_extract(lookup("user_ip_mapping...
by Niro Explorer in Getting Data In 05-13-2025
0 10
0
10
patelmc
I need to use federated search which does not support search time lookup at this time in splunk 8.2.2.1.I came across...
by patelmc Explorer in Getting Data In 05-13-2025
0 2
0
2
Skins
I have syslog events being written to a HF locally via syslog-ng - these events are then consumed via file reader and...
by Skins Path Finder in Getting Data In 05-13-2025
0 3
0
3
dtamburin
Brand new to splunk, inherited a slightly configured system.I want to move certain cribl events to an index called vm...
by dtamburin Engager in Getting Data In 05-13-2025
0 3
0
3
KhalidAlharthi
i have used this approach to forward logs from specific index to third-party system in my case Qradar so i need to do...
by KhalidAlharthi Explorer in Getting Data In 05-12-2025
0 10
0
10
Numb78
Hi all,I'm struggling with an issue related to collecting Fortinet Fortios events through SC4S. If I use UDP protocol...
by Numb78 Explorer in Getting Data In 05-12-2025
0 3
0
3
twh1
I was trying to download the universal forwarder for windows 7 32 bit OS, but i can see only windows 8, 8.1, 10 OS. ...
by twh1 Communicator in Getting Data In 05-12-2025
0 9
0
9
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...
Top Solution Authors