Thread Info | |||||
---|---|---|---|---|---|
Hello Community
I need regex that can return extract the following fields only from event 4702:1. <EventID></EventI...
by
DanAlexander
Communicator
in
Getting Data In
12-05-2024
|
0
|
8
| |||
Hey Everyone,
i got information if Wazuh can send data to Splunk, i want reverse it.
Because i want to send dat...
by
zksvc
Communicator
in
Getting Data In
12-06-2024
|
0
|
4
| |||
I need to forward data from a heavy forwarder to two different indexer clusters. One of the clusters needs to have a ...
by
klim
Path Finder
in
Getting Data In
12-05-2024
|
0
|
3
| |||
Hi Splunkers,
Just my interest, not a serious question. Why is frozenTimePeriodInSecs about 6 years (188697600 sec...
by
sunrise
Contributor
in
Getting Data In
11-29-2013
|
0
|
5
| |||
I was following this guide on adding command line logging to my GPO. I verified that the current GPO has these settin...
by
splunktrainingu
Communicator
in
Getting Data In
09-11-2020
|
0
|
3
| |||
Hi there, I'm using this API: https://splunk.github.io/splunk-add-on-for-amazon-web-services/APIreference/
Whenever...
by
Craig1
New Member
in
Getting Data In
12-05-2024
|
0
|
3
| |||
Hello guys,
We are getting on one heavyforwarder this message in splunkd.log, we are using TCP-SSL inputs.conf :
...
by
splunkreal
Motivator
in
Getting Data In
12-05-2024
|
0
|
0
| |||
Hello Community,
I am trying to create a connection so that I can sent metric running on 8125 port UDP on Splunk En...
by
rahusri2
Path Finder
in
Getting Data In
12-04-2024
|
0
|
4
| |||
Hi All,
I have a bluecoat proxy log source for which I am using the official splunk addon. However, I noticed that ...
by
Utkc137
Explorer
in
Getting Data In
12-04-2024
|
0
|
14
| |||
I am new to Splunk but spent a log time with Unifi kit. I am on the latest version of Unifi controller with a config ...
by
boomel
New Member
in
Getting Data In
12-03-2024
|
0
|
1
| |||
How do I limit the amount of data coming over from
[monitor://path/to/file]
in my splunk forwarder inputs.conf f...
by
smallwonder
Loves-to-Learn
in
Getting Data In
12-03-2024
|
0
|
5
| |||
I’ve read the documentation on these commands, executed both in a dev environment and observed the behavior.
My int...
by
rickymckenzie10
Explorer
in
Getting Data In
12-03-2024
|
0
|
2
| |||
How to Break a multiple events into a single event based on timestamp?My logs doesn't have a date and it only has tim...
by
RAVISHANKAR
Loves-to-Learn Lots
in
Getting Data In
11-29-2024
|
0
|
5
| |||
I want to block the audit.log file from a particular instance sending logs to splunk, is the stanza sufficient to acc...
by
rickymckenzie10
Explorer
in
Getting Data In
08-22-2024
|
0
|
3
| |||
I'm trying to create an admission rule in workload management with the following syntax:
any search with "=*" in th...
by
bmcaetano
Engager
in
Getting Data In
01-22-2024
|
0
|
2
| |||
How to identify Stream_event function is called at time interval or during create/edit data input.
by
KJ10
Loves-to-Learn
in
Getting Data In
12-02-2024
|
0
|
2
| |||
Hi,
from splunk, how can i check what are the logs is being forwarded out to another SIEM?
output.conf is config...
by
SamYap
Observer
in
Getting Data In
12-02-2024
|
0
|
1
| |||
i have events that contains a specific field that sometimes contain a very long field which make the rest of the even...
by
dorHerbesman
Path Finder
in
Getting Data In
11-27-2024
|
0
|
5
| |||
Hi community,
The following mod=sed regex works as expected, but when I attempted on the system/local/props.conf o...
by
DanAlexander
Communicator
in
Getting Data In
11-30-2024
|
0
|
5
| |||
Hi Splunkers,
I have an HWF that collects the firewall logs. For cost-saving reasons, some events are filtered, not...
by
norbertt911
Communicator
in
Getting Data In
11-27-2024
|
0
|
5
| |||
Is there a reason why the auth-success is excluded from the system_actions.csv lookup file in the Splunk Add-on for p...
by
okeyalex
New Member
in
Getting Data In
11-10-2024
|
0
|
1
| |||
Dear All,
I am facing difficulty in loading all the evtx files in a folder to Splunk.
I am using free Splunk vers...
by
MMMM
Observer
in
Getting Data In
11-27-2024
|
0
|
5
| |||
I'm sure this has been asked before but can't find the answer. I'm looking to use SPLUNK to provide better metrics fr...
by
kbrisson
Loves-to-Learn
in
Getting Data In
11-27-2024
|
0
|
1
| |||
Hi Community,
Trying to build regex that can help me reduce the size of an EventCode in my case this is 4627
The ...
by
DanAlexander
Communicator
in
Getting Data In
11-27-2024
|
0
|
4
| |||
I am trying to configure Splunk to ingest only application, system and security logs from my local machine. But I can...
by
daniel99
New Member
in
Getting Data In
11-27-2024
|
0
|
2
|