Getting Data In

Getting Data In
Community Activity
althomas
Hi all, Currently I'm using the Splunk Logging for Java libary to send HEC messages to Splunk via logback. Currently...
by althomas Communicator in Getting Data In 07-23-2020
1 5
1
5
alexspunkshell
Hi,I am using UF for syslog. In inputs.conf made index=cisco and sourcetype=syslog:ios and able to receive logs in co...
by alexspunkshell Contributor in Getting Data In 07-23-2020
0 1
0
1
rayar
Hihow I can get a list of all users that run savedsearch?
by rayar Contributor in Getting Data In 07-23-2020
0 2
0
2
moogmusic
I'm trying to send some busy logs through a Heavy Forwarder into our Splunk Cloud so we can do some aggregation to re...
by moogmusic Path Finder in Getting Data In 07-23-2020
0 0
0
0
sdkp03
I have Splunk set up in 2 different environments. Splunk in environment A is accessible to all users. Splunk in envir...
by sdkp03 Communicator in Getting Data In 07-22-2020
0 1
0
1
KayBeesKnees83
Greetings!Just wanted to know the steps for adding an input to an UF using the CLI.Thank you in advance. 
by KayBeesKnees83 Path Finder in Getting Data In 07-22-2020
0 1
0
1
leticiamartello
I have a watched file on a Universal Forwarder (Windows) and the file is send to the Heavy Forwarder (linux), but som...
by leticiamartello New Member in Getting Data In 07-22-2020
0 2
0
2
nuaraujo
Hello all, I need to sum 1 day(86400 seconds) to my _time, if the event(_raw) includes the string "SB". This needs t...
by nuaraujo Path Finder in Getting Data In 07-22-2020
0 12
0
12
antoniomsilva
What is the best practice for collecting events in which the user performs a query against the cloudera / hadoop ecos...
by antoniomsilva New Member in Getting Data In 07-21-2020
0 0
0
0
brandy81
Hi,What is the role of HEADER_MODE in props.conf? I am seeing the documents, but I don't understant.https://docs.splu...
by brandy81 Path Finder in Getting Data In 07-21-2020
0 4
0
4
ejmin
Hi Splunk Experts I have this kind of problem which confuses me. The file being ingested generates another file which...
by ejmin Path Finder in Getting Data In 07-21-2020
0 2
0
2
Glasses
Its been awhile since I setup an props/transforms override, but I never had so much trouble.I have 20 Foo-appliances ...
by Glasses Builder in Getting Data In 07-21-2020
0 8
0
8
Vidi
I tried this but seems this is not working.I want to convert BST to America /NY time please.| eval BST=strftime(Trans...
by Vidi Engager in Getting Data In 07-21-2020
0 3
0
3
grywiner51
The .csv file that I am using as input has a column name that begins with a percent sign ("% Complete").  I just noti...
by grywiner51 Explorer in Getting Data In 07-20-2020
0 2
0
2
tkw03
we have  monitors on 2 Windows file paths:[monitor://C:\Data\Data\Disk\SplunkLoad\IsilonCaptures\i*.txt]index = stora...
by tkw03 Communicator in Getting Data In 07-20-2020
0 0
0
0
Olivier_T
Hello,I have many forwarders sending logs to a cluster of indexers, and for some logs I need to send it not cooked.Th...
by Olivier_T Explorer in Getting Data In 07-20-2020
0 7
0
7
islam
Hi, we are asked to increase our retention period of splunk logs to 1 year. we need to put our data to be searchable ...
by islam Explorer in Getting Data In 07-20-2020
0 5
0
5
lehoang47tin
Hi, I am trying to collect NetFlow data from Cisco router via Splunk_TA_Stream. I config streamfwd.conf according to ...
by lehoang47tin Engager in Getting Data In 07-20-2020
0 0
0
0
jg91
Hello, we want to filter some fields of receiving events before indexing for the license saving, for example, in a fi...
by jg91 Path Finder in Getting Data In 07-19-2020
0 3
0
3
joshuapetitt
Hi all, I have a situation where there are servers from which we wish to get logs into Splunk. However, we cannot use...
by joshuapetitt Path Finder in Getting Data In 07-19-2020
0 2
0
2
loginsoft
Hi-We are indexing JSON data into Splunk. We push the data once every 24 hours. The Rest API will not give "Delta:", ...
by loginsoft Loves-to-Learn Lots in Getting Data In 07-19-2020
0 2
0
2
pavanprem009
Splunk is getting duplicate events from Azure billing API,  We are using inbuild azure connector to onboard the data....
by pavanprem009 New Member in Getting Data In 07-19-2020
0 0
0
0
uagraw01
My logs are that kind :<July 13, 2020 10:55:02,572 PM CDT>So i used TIME_FORMAT=%b %d, %Y %H:%M:%S, %3N%p%zBut it is ...
by uagraw01 Motivator in Getting Data In 07-18-2020
0 16
0
16
rameshlpatel
Hi, In splunk UI, I am seeing only top 10 source and sourcetype list. But I want to see all of them. Please suggest...
by rameshlpatel Communicator in Getting Data In 07-18-2020
6 17
6
17
asimasplunk
We are using ingest pattern as API at Heavy forwarder. props.conf:- [kenna:applications] INDEXED_EXTRACTIONS = json T...
by asimasplunk Explorer in Getting Data In 07-18-2020
0 6
0
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...