Getting Data In

Getting Data In
Community Activity
bcarr12
I am using the transaction command in Splunk to group the events of an identical log file across two hosts. Essentia...
by bcarr12 Path Finder in Getting Data In 01-13-2020
0 1
0
1
juls0125
Hello Friends! I was trying to send an input Script to all my AIX servers ( i have aprox 20) but the script only get...
by juls0125 New Member in Getting Data In 01-13-2020
0 0
0
0
ankitgupta15
I want to get value from one multivalued field which are not present in other multivaliued field from same index and ...
by ankitgupta15 Engager in Getting Data In 01-13-2020
0 3
0
3
Stokers_23
I would like to understand if the following requirement can be made to work.. We are ingesting AWS Cloudtrail events...
by Stokers_23 Explorer in Getting Data In 01-13-2020
0 0
0
0
splunkreal
Hello, is it possible to filter events based on sourcetype + (host OR sourcetype) with props.conf/transforms.conf on...
by splunkreal Influencer in Getting Data In 01-13-2020
0 4
0
4
bigfatyeastroll
I've got several data indexes (only one server) already that are separated by forwarders or listener ports. However, ...
by bigfatyeastroll Path Finder in Getting Data In 01-13-2020
0 3
0
3
aagehh
Hi I get al lot of the following messages on my IX: TcpInputProc - Encountered S2S Exception=Invalid _meta atom: for...
by aagehh New Member in Getting Data In 01-13-2020
0 4
0
4
Amirahussein
please need your support as SPLUNK didn't parse all files from same path, i.e for example in my inputs.conf there are...
by Amirahussein Path Finder in Getting Data In 01-13-2020
0 1
0
1
dk30390
I am trying to do custom encryption and decryption of data on the universal forwarders. I am trying to configure the ...
by dk30390 New Member in Getting Data In 01-13-2020
0 0
0
0
chimbudp
What is command that i need to use to export a splunk app into .spl format ?
by chimbudp Contributor in Getting Data In 01-13-2020
2 5
2
5
shugup2923
I am trying to read csv from one of my universal forwareder, below is my inputs file [monitor://D:\DUMP\Updated_Dump...
by shugup2923 Path Finder in Getting Data In 01-12-2020
0 4
0
4
jamesvz84
I am using the splunk for unix app and the KV_MODE = multi entry in props.conf is not working. For example, I am stil...
by jamesvz84 Communicator in Getting Data In 01-12-2020
1 2
1
2
aojie654
Hi, Splunkers: I have a question about retention policy that I had configured my index linux_log of frozenTimePeriod...
by aojie654 Path Finder in Getting Data In 01-12-2020
0 2
0
2
aojie654
Hi, Splunkers: I have a question about retention policy that I had configured my index linux_log of frozenTimePeriod...
by aojie654 Path Finder in Getting Data In 01-12-2020
0 1
0
1
D2SI
Hello there, For a particular sourcetype there are events with a timestamp and events without timestamp. As Splunk ...
by D2SI Communicator in Getting Data In 01-11-2020
0 9
0
9
mlevsh
Lets say we have Json data in the following format ( using 2 events as an example) Event 1) Time Event 5/19/19 2...
by mlevsh Builder in Getting Data In 01-10-2020
0 4
0
4
n_young
Source JSON Structure: { "working": { "https://site.number.one": [ { "metric": "...
by n_young New Member in Getting Data In 01-10-2020
0 6
0
6
surekhasplunk
Hi, I have a json output which is getting indexed correctly. And i am collectng ip from remotemanagement{}.ip . But ...
by surekhasplunk Communicator in Getting Data In 01-10-2020
0 11
0
11
hughkelley
I have a KV collection that uses a CIDR-style network address as the key value. This means that delete operations ...
by hughkelley Path Finder in Getting Data In 01-10-2020
0 6
0
6
swamysanjanaput
Hello, We have an issue monitoring os_metrics logs where the log entries are generated from a Windows command wmic a...
by swamysanjanaput Explorer in Getting Data In 01-10-2020
0 4
0
4
juls0125
Hello Splunkers! I have a question, i have installed a universal forwarder on a AIX server, but all the logs arrives...
by juls0125 New Member in Getting Data In 01-10-2020
0 3
0
3
dhughesanz
I have the below config in tags.conf: [source=/some/directory/logs/foo-bar/error.log] sometag = enabled And this wo...
by dhughesanz New Member in Getting Data In 01-10-2020
0 1
0
1
erlindemberg
How do I configure HOT / WARM, COULD, and FROZEN in Splunk Enterpise? I need to configure Splunk Data Retention and ...
by erlindemberg Explorer in Getting Data In 01-10-2020
0 2
0
2
jerinvarghese
Hi All, I have a query to display some BGP neighbour UP or DOWN. Output looks like nodelabel Status PEER_IP Ti...
by jerinvarghese Communicator in Getting Data In 01-10-2020
0 5
0
5
lifekis
It was working fine until 1 month ago. There was no Splunk forwarder and network configuration change. No packets fro...
by lifekis Explorer in Getting Data In 01-09-2020
0 5
0
5
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors