Getting Data In

Getting Data In
Community Activity
titoluna07
I have this add-on "TA Microsoft Windows Defender" installed in our UFs using a deployment server, all configuration ...
by titoluna07 Explorer in Getting Data In 09-23-2020
1 0
1
0
Blackmagician
I am after some help to debug why Splunk is not monitoring my external .evtx files.Currently have the following: %Spl...
by Blackmagician Engager in Getting Data In 09-23-2020
1 1
1
1
krvamsireddy
We upgraded the McAfee ePO from 5.9 to 5.10 after that splunk integration was broken, so i checked some articles and ...
by krvamsireddy Explorer in Getting Data In 09-23-2020
0 0
0
0
sneha
Hi Team, I am trying to onboard Reports data to splunk available under "Airwatch Workspace one UEM">Monitor>Reports &...
by sneha New Member in Getting Data In 09-23-2020
0 0
0
0
datamine
hi All,IN the AWS inputs logs we are getting timestamps behind 2 hours and we need to adjust it to UTC + 02:00 . I ha...
by datamine Loves-to-Learn Lots in Getting Data In 09-23-2020
0 1
0
1
rajiv_r
I have a splunk trial version and i am trying pushing aws waf logs through HEC- I have enabled the token perfectly an...
by rajiv_r Explorer in Getting Data In 09-23-2020
0 1
0
1
andrewtrobec
Hello,I would like to know how forwarders handle rolling logs when their target indexers become unavailable.  Here is...
by andrewtrobec Motivator in Getting Data In 09-22-2020
0 2
0
2
trevor_dunstan8
Hey all, Long story short, I have a Windows IIS FTP server on a Heavy forwarder that receives logs from Cisco proxy s...
by trevor_dunstan8 Explorer in Getting Data In 09-22-2020
1 0
1
0
7aurelius
Hi,Is there a way to remove or quarantine multiple search peers (indexers) at the same time? It's not practical enoug...
by 7aurelius Loves-to-Learn in Getting Data In 09-22-2020
0 3
0
3
sahabhi606
Dear Splunkers, Splunk server certificates on servers with splunk forwarder is expiring. is there a way to upgrade th...
by sahabhi606 Path Finder in Getting Data In 09-22-2020
0 0
0
0
spl_unker
Hello Splunkers,We have all the log collection at s3 .  What would be best option to send logs from s3 to Splunk .I k...
by spl_unker Explorer in Getting Data In 09-22-2020
0 0
0
0
splunkcol
I open a new thread because in the previous one I was reviewing several errors at the same timefor this specific erro...
by splunkcol Builder in Getting Data In 09-22-2020
0 1
0
1
chair56
Is there any chunk size applied while reading the data on the connections? chunk size like 2kb,4kb,8kb ? is there a w...
by chair56 New Member in Getting Data In 09-21-2020
0 1
0
1
iamperson347
Hi All,I've followed the instructions here (https://docs.splunk.com/Documentation/AddOns/latest/MSIIS/About) to inges...
by iamperson347 Explorer in Getting Data In 09-21-2020
0 3
0
3
diptij
Has anybody installed Sophos Anti-Virus for Linux on the same machines as their Splunk Head and Splunk Indexer?  If s...
by diptij Path Finder in Getting Data In 09-21-2020
0 1
0
1
rgadepal
Hi All, I am looking to configure a sox app on splunk, so wanted to know if it is possible  to restrict a user/s to o...
by rgadepal New Member in Getting Data In 09-21-2020
0 1
0
1
gauravmsharma
I am dynamically extracting a sourctype using props.conf and tranform.conf file. But the extraction is not working as...
by gauravmsharma Path Finder in Getting Data In 09-21-2020
1 5
1
5
potnuru
Requirement is to send data from Splunk to PTA tool using Scheduled Search on Search Head.The Data should be filtered...
by potnuru Path Finder in Getting Data In 09-21-2020
0 3
0
3
VatsalJagani
I'm reading a file that is being overridden by a PowerShell script. (no append in the file)The PowerShell script is u...
by SplunkTrust SplunkTrust in Getting Data In 09-21-2020
1 2
1
2
adzeh
Afternoon all, I have an XML dataset that I am struggling to extract fields from. What I need is for the <key> value ...
by adzeh Engager in Getting Data In 09-21-2020
0 5
0
5
las
Hi. I have just been presented with a very curious timestamp format.  18-08-2020 15:41:00,07 No running service ins...
by las Contributor in Getting Data In 09-21-2020
0 2
0
2
cboillot
In the DMC, I am seeing errors like below when looking at Index Detail. [<SplunkServerName>] REST Processor: Failed ...
by cboillot Contributor in Getting Data In 09-21-2020
0 7
0
7
ari-001
Hello, Im a splunk newbie, we dont have FMC module. How do I send logs to Splunk without using FMC ? I only have acce...
by ari-001 Explorer in Getting Data In 09-20-2020
1 2
1
2
ankithreddy777
May I know how exactly LINE_BREAKER_LOOKBEHIND works? I am little bit confused by the explanation given in Splunk doc...
by ankithreddy777 Contributor in Getting Data In 09-18-2020
1 4
1
4
ips_mandar
HiI am trying to extract timestamp including nanoseconds but I am able to extract only 7 digits of nanoseconds though...
by ips_mandar Builder in Getting Data In 09-18-2020
0 1
0
1
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...