Getting Data In

Getting Data In
Community Activity
dhughesanz
I have the below config in tags.conf: [source=/some/directory/logs/foo-bar/error.log] sometag = enabled And this wo...
by dhughesanz New Member in Getting Data In 01-10-2020
0 1
0
1
erlindemberg
How do I configure HOT / WARM, COULD, and FROZEN in Splunk Enterpise? I need to configure Splunk Data Retention and ...
by erlindemberg Explorer in Getting Data In 01-10-2020
0 2
0
2
jerinvarghese
Hi All, I have a query to display some BGP neighbour UP or DOWN. Output looks like nodelabel Status PEER_IP Ti...
by jerinvarghese Communicator in Getting Data In 01-10-2020
0 5
0
5
lifekis
It was working fine until 1 month ago. There was no Splunk forwarder and network configuration change. No packets fro...
by lifekis Explorer in Getting Data In 01-09-2020
0 5
0
5
kirti_gupta12
I want to populate the list of hosts in the multiselect input option in Splunk. index=someIndexName * host!="notThis...
by kirti_gupta12 Path Finder in Getting Data In 01-09-2020
0 1
0
1
mccartneyc
Hi everyone, I have about 20 windows servers and 30 linux servers, all with universal forwarders installed and config...
by mccartneyc Path Finder in Getting Data In 01-09-2020
0 1
0
1
mccartneyc
Hi guys, here is the current setup I have. UF uses data cloning to send to both an indexer cluster and an intermedia...
by mccartneyc Path Finder in Getting Data In 01-09-2020
0 3
0
3
vnguyen46
Hi, I have a new Splunk enterprise system up and running, with HFs and Indexers. For logs from network devices like F...
by vnguyen46 Contributor in Getting Data In 01-09-2020
0 1
0
1
myoung54
Hey all, So I'm kind of scratching my head on this, and any kind of guidance would be extremely helpful! Alright, s...
by myoung54 Explorer in Getting Data In 01-09-2020
0 2
0
2
dsbruce
I am trying to pull windows_TA perfmon data to a metric index to give our users sample data so they can create metric...
by dsbruce Explorer in Getting Data In 01-09-2020
0 0
0
0
itsmevic
What is the best method for gauging the amount of data a log source feeds in? for example, let the system send data ...
by itsmevic Communicator in Getting Data In 01-09-2020
0 1
0
1
simonselvin2019
how can I get Hostnames anits respective IP address through a query.For e.g (index=winlog | Stats count by host) only...
by simonselvin2019 Explorer in Getting Data In 01-09-2020
0 3
0
3
davidbann
I'm adding a new input (UNC directory) and due to previous lessons learned, I took from best practice and sent events...
by davidbann Explorer in Getting Data In 01-09-2020
0 1
0
1
dglass0215
Hello, i am trying to understand the documentation surrounding SHOULD_LINEMERGE. It says the default is SHOULD_LIN...
by dglass0215 Path Finder in Getting Data In 01-09-2020
0 2
0
2
mbasharat
Hi, I have a dashboard. It has 3 text inputs. Search by IP Text Input 1 Search by NETBIOS Text Input 2 Search by...
by mbasharat Builder in Getting Data In 01-09-2020
0 5
0
5
Deprasad
Log looks like this. {...\"Key_name\":\"Value\",....}, {...\"Key_name\":\"Value\",....}, {...\"Key_name\":\"Value\",...
by Deprasad Path Finder in Getting Data In 01-09-2020
0 9
0
9
lawrence_magpoc
Some of the logs ingested into our Splunk environment has missing line. I was told that this could be the result of a...
by lawrence_magpoc Path Finder in Getting Data In 01-08-2020
0 2
0
2
essibong1
I'm trying to know why I can't feed data in splunk. I'm trying to get data from windows servers to splunk, I've creat...
by essibong1 New Member in Getting Data In 01-08-2020
0 2
0
2
MTravisVolker
We are attempting to add Microsoft RAS Total counters from PerfMon to the Splunk UF collector. We updated the local/i...
by MTravisVolker Explorer in Getting Data In 01-08-2020
2 1
2
1
twinspop
In an effort to get our inventory of inputs under control, I'm trying to get all servers to have one place for logs. ...
by twinspop Influencer in Getting Data In 01-08-2020
1 7
1
7
rileyken2
I have indexed my Azure AD audit and sign-in logs: { [-] Level: 4 callerIpAddress: xxx.xxx.xxx.xxx category...
by rileyken2 Path Finder in Getting Data In 01-08-2020
0 0
0
0
mikefg
I'm working moving a retired index to frozen (indexer cluster). I've set the maxWarmDBCount = 0 for the index and all...
by mikefg Communicator in Getting Data In 01-08-2020
0 0
0
0
tkerr1357
Hello all, I am fairly new to Splunk and am working on gathering data for our operations team. They are asking me to...
by tkerr1357 Path Finder in Getting Data In 01-08-2020
0 2
0
2
becksyboy
Hi, I'm fairly new to Splunk and currently undergoing some training. Within my home lab I have a Splunk instance ins...
by becksyboy Contributor in Getting Data In 01-08-2020
2 26
2
26
Anirban92Chakra
Hello Guys, I need you help to figure out how to put multiple HF or indexer name in collectd.conf for matrices data...
by Anirban92Chakra New Member in Getting Data In 01-08-2020
0 0
0
0
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors