Getting Data In

Getting Data In
Community Activity
sabollam
Hello All,I have log file which has the following content in json format, I would like to parse the timestamp and con...
by sabollam Loves-to-Learn Lots in Getting Data In 04-17-2025
0 11
0
11
stemerdink
As we have recently enabled various audit settings on our domain, we now have 4662 events being generated on the DCs....
by stemerdink Engager in Getting Data In 04-17-2025
0 3
0
3
manideepa
Hello Experts,In Splunk ITSI, we’re able to see the alerts in the Alerts table, but those alerts are not being reflec...
by manideepa Engager in Getting Data In 04-16-2025
0 1
0
1
Abass42
So the title is pretty self explanatory. I have been approached and requested to trim logs. I had initially installed...
by Abass42 Communicator in Getting Data In 04-16-2025
0 5
0
5
anandhalagaras1
Based on the article provided below we have updated our Atlassian settings to pull the Bitbucket logs into our Audit ...
by anandhalagaras1 Contributor in Getting Data In 04-16-2025
0 4
0
4
blanky
We are collecting the sourtype of the data we are currently receiving by changing it as follows.[A_syslog]TRANSFORMS-...
by blanky Explorer in Getting Data In 04-16-2025
0 2
0
2
Karthikeya
We have a architecture of 3 site multi cluster which contains 6 indexers (2 in each site), 3 search heads (one in eac...
by Karthikeya Communicator in Getting Data In 04-16-2025
0 16
0
16
wni
Hello from Splunk Data Manager Team,We are excited to announce the preview of Data Manager for Splunk Cloud. Before y...
by wni Splunk Employee Splunk Employee in Getting Data In 04-16-2025
3 22
3
22
arusishere
Dear Splunk Community,I need some advice on how to get DB Connect configured. I'm hitting a brick wall trying to get ...
by arusishere New Member in Getting Data In 04-15-2025
0 4
0
4
cmutt78_2
Upon installing the Akamai SIEM I am not seeing the data input option for "Akamai​ Security Incident Event Manager AP...
by cmutt78_2 Explorer in Getting Data In 04-15-2025
0 7
0
7
jamie1
Hi There,I have noticed that the cloud monitoring console is reporting a critical bucket. I only have one and have at...
by jamie1 Communicator in Getting Data In 04-15-2025
0 3
0
3
blanky
We are collecting various data from security equipment.The data is being stored in index=sec_A and received as sourty...
by blanky Explorer in Getting Data In 04-15-2025
0 3
0
3
sideview
I'm trying to piece things together from the restmap.conf docs, to get a working custom endpoint that I can use. Not...
by SplunkTrust SplunkTrust in Getting Data In 04-14-2025
3 4
3
4
tech_g706
Hi,I have a question on Netskope onboarding to Splunk. I installed to TA-NetSkopeAppForSplunk (4.1.0) on Splunk cloud...
by tech_g706 Path Finder in Getting Data In 04-14-2025
0 2
0
2
okana
Expert advice needed.I was able to ingest cloudwatch logs for ecs and lambda with data managerNow i need to add tags ...
by okana Loves-to-Learn Lots in Getting Data In 04-14-2025
0 2
0
2
splunklearner
How can we pull Azure event hub logs to Splunk? I check that we cannot use HEC configuration for pulling the data. Wh...
by splunklearner Communicator in Getting Data In 04-11-2025
0 6
0
6
gerrysr6
I have written and tested some rules using "Ingest Actions". I used the "Sample" indexed data and everything seems fi...
by gerrysr6 Explorer in Getting Data In 04-11-2025
0 5
0
5
danielbb
I created a KV Store lookup using the "Splunk App for Lookup File Editing" app, however when I look at Settings>Looku...
by danielbb Motivator in Getting Data In 04-11-2025
0 4
0
4
b17gunnr
Hello folks,My organization is struggling with ingesting the Cisco Firepower audit (sys)logs into Splunk, we've been ...
by b17gunnr Path Finder in Getting Data In 04-11-2025
0 3
0
3
samuel-devops
 Commands used to run docker image: docker run -d -p 9997:9997 -p 8080:8080 -p 8089:8089 -e "SPLUNK_START_ARGS=--acce...
by samuel-devops Explorer in Getting Data In 04-10-2025
1 15
1
15
jni
Hi,We're setting up a Splunk enterprise instance in an air-gapped environment. In addition to this, the server is sit...
by jni Explorer in Getting Data In 04-10-2025
0 7
0
7
man03359
Hi,I am a splunk admin and we are re-assigning the orphaned knowledge object to my name as a temporary solution. I ne...
by man03359 Communicator in Getting Data In 04-10-2025
0 1
0
1
splunklearner
AWS logs to SplunkWe need to onboard AWS cloud watch logs (from Kinesis) to our Splunk. We have all our Splunk instan...
by splunklearner Communicator in Getting Data In 04-09-2025
0 10
0
10
TheJagoff
I have multiline events where it is required to capture the error messages.The events are separated by "FAILED".I nee...
by TheJagoff Communicator in Getting Data In 04-09-2025
0 5
0
5
Karthikeya
we got a requirement to on-board new platform logs to Splunk. They will have 1.8 TB/day data to be ingested. As of no...
by Karthikeya Communicator in Getting Data In 04-08-2025
0 18
0
18
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...
Top Solution Authors