Getting Data In

Getting Data In
Community Activity
stwong
Hi all, We set sourcetype in inputs.conf on universal forwarder, e.g. [monitor:///Firewall/*/*_pa_firewall.log] ig...
by stwong Communicator in Getting Data In 05-14-2020
0 2
0
2
wwhite12
I have some json data events that has multiple "date" fields. The date field I am looking to use as my timestamp come...
by wwhite12 Path Finder in Getting Data In 05-14-2020
0 2
0
2
user789
I have set splunk to ingest the /var/log directory. On this particular host, I go to filter by "source", and only se...
by user789 New Member in Getting Data In 05-14-2020
0 6
0
6
ppanchal
I have a heavy forwarder currently sending data to Splunk Cloud. Can I use the same heavy forwarder to stop data sen...
by ppanchal Path Finder in Getting Data In 05-14-2020
0 1
0
1
s0mar
I am trying to filter out noise before it is sent to the indexer. We were using Windows Event Forwarding previously,...
by s0mar Explorer in Getting Data In 05-14-2020
0 1
0
1
schua
Hi, I have an Apache instance with Splunk Forwarder installed that sends logs to Splunk Cloud directly (no heavy for...
by schua New Member in Getting Data In 05-14-2020
0 1
0
1
wwhite12
I have json files that have multiple events per file. However when I ingest the data, Splunk parses some of the times...
by wwhite12 Path Finder in Getting Data In 05-14-2020
0 5
0
5
skirven
Hi! We are on Splunk 7.2.0, and I am trying to automate setting up a Saved Search using an Ansible Playbook that wou...
by skirven Communicator in Getting Data In 05-14-2020
0 4
0
4
xinlux01rhi
I have a JSON string as an event in Splunk below: {"Item1":{"Max":100,"Remaining":80},"Item2":{"Max":409,"Remaining"...
by xinlux01rhi Explorer in Getting Data In 05-13-2020
0 4
0
4
putnamblake
Hi all, I have a general question on saving some space and grouping hosts in serverclass.conf. I have reviewed This ...
by putnamblake Path Finder in Getting Data In 05-13-2020
0 4
0
4
mlevsh
Hi, On server with Splunk Universal Forwarder installed we are monitoring cvs log with a header and lines in the fo...
by mlevsh Builder in Getting Data In 05-13-2020
0 0
0
0
kevincorder
When running a search for syslogs within 7 days, Splunk is retuning some logs that are months old. Timestamp is corre...
by kevincorder New Member in Getting Data In 05-13-2020
0 4
0
4
sanjax90
How can we use spath for below JSON to evaluate if for ConcurrentAsyncGetReportInstances , Remaining/Max*100 is >= 70...
by sanjax90 New Member in Getting Data In 05-13-2020
0 5
0
5
sdkp03
Have tried to setup HTTPEventCollector via cli using splunk documentation link: https://docs.splunk.com/Documentation...
by sdkp03 Communicator in Getting Data In 05-12-2020
0 8
0
8
seomaniv
I have a dashboard that takes 3 inputs. (TimePicker, Associate, and Activity). All items (inputs and dash panels) up...
by seomaniv Explorer in Getting Data In 05-12-2020
0 2
0
2
mb1226
I have an application feeding to Splunk for the better part of a couple years now. Last December we change formats...
by mb1226 Explorer in Getting Data In 05-12-2020
0 2
0
2
ruman
The field value is ["","apples","oranges"] | spath input=foo creates a multi-value field named '{}'. which is a litt...
by ruman Splunk Employee Splunk Employee in Getting Data In 05-12-2020
3 9
3
9
ikoniasavina
I have search querrie created from json file. Problem is values that i have appear in one row, instead of 3 rows(in j...
by ikoniasavina Explorer in Getting Data In 05-12-2020
0 11
0
11
ch1221
Looking for some assistance extracting all of the nested json values like the "results", "tags" and "iocs" in the scr...
by ch1221 Path Finder in Getting Data In 05-12-2020
0 11
0
11
mysicksi
Hi everyone, Can someone please help with a search I'm trying to create. My end goal is to capture which user accoun...
by mysicksi Path Finder in Getting Data In 05-12-2020
0 2
0
2
jaimelopez
Hello, I would like to extract data from inside a parenthesis to create a new field This command for a search works w...
by jaimelopez Explorer in Getting Data In 05-12-2020
0 11
0
11
santhoshvelling
Hi Experts, I have a even like below generated from my application. {<!-- --> "index": "exp_prod", "host": "myhost...
by santhoshvelling New Member in Getting Data In 05-12-2020
0 4
0
4
abhi04
Hi, I want to confisure Splunk HEC on dedicated splunk server. Please let me know the server hardware and software ...
by abhi04 Communicator in Getting Data In 05-12-2020
0 4
0
4
cmahan
I am trying to find the format for a perfmon input to collect the following from a universalforwarder but am not sure...
by cmahan Path Finder in Getting Data In 05-12-2020
0 5
0
5
awilcox_splunk
What are the best configuration settings for using pgBadger to analyze Splunk Phantom's PostgreSQL logs?
by awilcox_splunk Splunk Employee Splunk Employee in Getting Data In 05-11-2020
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...
Top Solution Authors