Getting Data In

Getting Data In
Community Activity
tawm_12
Hi everyone,I'm seeking advice on the best way to send application logs from our client's Docker containers into a Sp...
by tawm_12 Engager in Getting Data In 04-02-2025
0 2
0
2
Na_Kang_Lim
As the title suggests, I am having multiple Universal Forwarders sharing the same Instance GUID due to the mistake of...
by Na_Kang_Lim Path Finder in Getting Data In 04-02-2025
0 1
0
1
bhavesh0124
I'm ingesting data into Splunk via the HTTP Event Collector (HEC), but the data is wrapped inside a "data" key instea...
by bhavesh0124 Explorer in Getting Data In 04-02-2025
0 5
0
5
jitbahan
I have installed akamai add on for splunk in our HF. https://splunkbase.splunk.com/app/4310 I followed the documentat...
by jitbahan New Member in Getting Data In 04-02-2025
0 7
0
7
zafar
Hi,Windows UF stopped sending events. I saw this event in _internal index'message from ""C:\Program Files\SplunkUnive...
by zafar Engager in Getting Data In 04-02-2025
0 3
0
3
Zoe_
HelloHas anyone encountered the situation of incomplete log transmission using UDP 514? Would changing to TCP be usef...
by Zoe_ Observer in Getting Data In 04-01-2025
0 2
0
2
ArtieZ
Hi,We recently upgraded the Heavy Forwarders (HF) of our Splunk Enterprise. After the upgrade the Universal Forwarder...
by ArtieZ Loves-to-Learn Everything in Getting Data In 03-31-2025
0 8
0
8
Kyles
I've been using dbxquery connection=my_connection procedure=my_procedure to build reports and a few that my DBAs have...
by Kyles Observer in Getting Data In 03-31-2025
0 1
0
1
Namchin_Bar
Dear Splunk Support,I am encountering an issue while configuring Splunk to filter logs based on specific ports (21, 2...
by Namchin_Bar New Member in Getting Data In 03-31-2025
0 2
0
2
Karthikeya
Hi all, I am trying to pull Akamai logs to Splunk. Hence installed this app in HF  - https://splunkbase.splunk.com/ap...
by Karthikeya Communicator in Getting Data In 03-31-2025
0 21
0
21
bedrocho
                          I want to route dataI want to split one sourcetype into two.When I click Extract New Fields...
by bedrocho Explorer in Getting Data In 03-30-2025
0 4
0
4
SplunkStudent2
I'm looking for training that would cover at when deploying a TA if it would have to go to the indexer level rather t...
by SplunkStudent2 Engager in Getting Data In 03-30-2025
0 3
0
3
Karthikeya
We are installing modular input (akamai add-on) to get akamai logs to Splunk.In our environment, we have kept modular...
by Karthikeya Communicator in Getting Data In 03-30-2025
0 8
0
8
StephenD1
I've noticed an issue with one of my syslog indexes. I have a syslog server centralizing and forwarding syslogs for 6...
by StephenD1 Path Finder in Getting Data In 03-28-2025
0 1
0
1
Na_Kang_Lim
I have this kind of log:Mar 18 02:32:19 MachineName python3[948]: DEBUG:root:... Dispatching: {'id': '<id>', 'type': ...
by Na_Kang_Lim Path Finder in Getting Data In 03-28-2025
0 8
0
8
goji
Hi,I just want to input OpenCTI feed from OpenCTI to Splunk.I followed installation instruction.https://splunkbase.sp...
by goji Path Finder in Getting Data In 03-28-2025
0 3
0
3
BRFZ
Hello,I’ve been reviewing the documentation for configuring SSL/TLS on a Splunk forwarder, but I couldn’t find the sp...
by BRFZ Communicator in Getting Data In 03-28-2025
0 9
0
9
Andre_
Hello,Can Security Essentials import security advisories from vendors like Broadcom or Microsoft?I would like to comp...
by Andre_ Path Finder in Getting Data In 03-27-2025
0 2
0
2
KJ10
Hi Team,How to combine multiple data input into one, basically I am having 5 different data inputs where I am taking ...
by KJ10 Engager in Getting Data In 03-27-2025
0 3
0
3
uagraw01
Dear Splunkers!!I am facing an issue with Splunk file monitoring configuration. When I define the complete absolute p...
by uagraw01 Motivator in Getting Data In 03-27-2025
0 8
0
8
dolj
Hi Community,I have a JSON data source that I am trying to get into Splunk via a heavy Forwarder using a custom built...
by dolj Explorer in Getting Data In 03-27-2025
0 6
0
6
cbiraris
Hi team,i have a index with 4 sourcetype.  index has searchable retention of 4 months.is there any way we can keep sa...
by cbiraris Path Finder in Getting Data In 03-27-2025
0 5
0
5
mkhasan
We had a problem with our Microsoft Azure plugin since July. The field appliedConditionalAccessPolicies: [ [ - ] ] mi...
by mkhasan New Member in Getting Data In 03-26-2025
0 1
0
1
Avantika
I have below configurations in transforms and props config files to change the source name of my events from upd:9514...
by Avantika Explorer in Getting Data In 03-25-2025
0 9
0
9
kermitshort
I'm setting up a Splunk Indexer (Splunk Enterprise 6.4.1) on CentOS 6.8 64-bit. I do have the Splunk Add-on for Micr...
by kermitshort Explorer in Getting Data In 03-25-2025
0 14
0
14
Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors