Getting Data In

Getting Data In
Community Activity
Kathir
Need to Add blacklist except "*string*" is possible ?
by Kathir Loves-to-Learn Everything in Getting Data In 04-19-2021
0 3
0
3
paimonsoror
I am having a VERY strange problem with my summary indexing. I have the following search running every hour at 20 mi...
by paimonsoror Builder in Getting Data In 04-18-2021
4 16
4
16
sarnagar
How can I send splunk cold buckets to S3? We have our on-premises splunk and send Splunk data to S3 for longer storag...
by sarnagar Contributor in Getting Data In 04-16-2021
2 21
2
21
ryanadamski
Hello,I am ingesting file auditing logs to monitor changes to certain files. I am monitoring events 4663 and 4656 whi...
by ryanadamski Engager in Getting Data In 04-16-2021
0 1
0
1
thehowler
I've got a HTTP API that produces a JSON payload of metrics. The payload is formatted in a way that also works for PO...
by thehowler New Member in Getting Data In 04-16-2021
0 0
0
0
marco_massari11
Hi,I need to filter out some events from a syslog source. All the events that I need to exclude are like this:Apr 16 ...
by marco_massari11 Communicator in Getting Data In 04-16-2021
0 7
0
7
niks987
Hi All,Hope you all are doing good.I am trying to read two simple txt files containing just the numeric value . These...
by niks987 Explorer in Getting Data In 04-16-2021
0 0
0
0
konstr
I am facing a weird issue at the moment where I want to set up multiple tcp-ssl inputs and have each input using a di...
by konstr Path Finder in Getting Data In 04-16-2021
1 6
1
6
termcap
Hi All,I have set up a continuous monitor of the /var/log directory and set the host to "vps"Now when I am searching ...
by termcap Path Finder in Getting Data In 04-15-2021
0 1
0
1
wangjianiu
I set the "Restrict search time range" in the role configuration to 3 days, now for the event index, Splunk only retu...
by wangjianiu Explorer in Getting Data In 04-15-2021
0 1
0
1
aknsun
Hi,I have managed to get Process, Memory, LogicalDisk and a few other perfmon counters working. However I can't get t...
by aknsun Path Finder in Getting Data In 04-15-2021
0 0
0
0
ahmedfoda
Dears, Greetings. When I navigate to Apps > Manage Apps > Cisco eStreamer eNcore for Splunk, I can't find the "Set Up...
by ahmedfoda New Member in Getting Data In 04-15-2021
0 0
0
0
sky_143
I have the address of a data point that is being sent to Splunk. When I search for the data point in Splunk, I get th...
by sky_143 New Member in Getting Data In 04-15-2021
0 1
0
1
Kothandapanin
Here is the JSON data and looking for Props settings for splitting the event based on "Level:4" as the correlation ID...
by Kothandapanin Loves-to-Learn Lots in Getting Data In 04-15-2021
0 7
0
7
mariannedave
There are no data being index from our setup below. Does "Invalid key in stanza ..... line 36: kv_mode (value: xml)" ...
by mariannedave Explorer in Getting Data In 04-14-2021
0 0
0
0
hkasho
I am interested in configuring Heavy forwarder to send to additional destination third party like Syslog-NG using TCP...
by hkasho New Member in Getting Data In 04-14-2021
0 0
0
0
biagiodipalma
hi there,I have some machines that collect Security logs from Windows. The universal forwarder on machines have this ...
by biagiodipalma Explorer in Getting Data In 04-14-2021
0 3
0
3
milanparmar541
Hey, splunkers!According to my use case, I need the unicode/chinese character in the kvstore lookup. but seems like i...
by milanparmar541 Explorer in Getting Data In 04-13-2021
0 0
0
0
splunkfrs
Newbie question - rolled out sysmon along with UF but need to edit the sysmon config file to exclude Splunk processes...
by splunkfrs Loves-to-Learn in Getting Data In 04-13-2021
0 0
0
0
mattshwink1
So I see data coming in:04-13-2021 17:32:25.470 -0400 INFO StatusMgr - destPort=9997, eventType=connect_done, group=t...
by mattshwink1 Loves-to-Learn in Getting Data In 04-13-2021
0 0
0
0
wmuselle
Hi we are getting duplicates on log eventsEvents are :- multiline- large (to very large)- also the files can grow to ...
by wmuselle Path Finder in Getting Data In 04-13-2021
0 0
0
0
jfk87
Dear Experts, I am trying to add the data to monitor Cisco logs through Splunk, i am just able to add 1 device only, ...
by jfk87 New Member in Getting Data In 04-13-2021
0 6
0
6
justynap_ldz
Hello everyone,Could you please help me out with the following query?We have a TA-Okta_Identity_Cloud_for_Splunk inst...
by justynap_ldz Path Finder in Getting Data In 04-13-2021
0 0
0
0
StefanW
Hello,since daylight savings time is active we have a time offset for our events.For example, we use das splunk strea...
by StefanW Path Finder in Getting Data In 04-12-2021
0 0
0
0
ajromero
I'm using WMI to monitor when services are down, but noticed that the servers that don't use the Local System account...
by ajromero Path Finder in Getting Data In 04-12-2021
0 0
0
0
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...