Getting Data In

Getting Data In
Community Activity
swamysanjanaput
Hi Splunkers, I am trying to ingest os_metrics logs from one of our prod server to splunk. In QA and dev instance, e...
by swamysanjanaput Explorer in Getting Data In 10-25-2019
0 4
0
4
abdulhasnath
Hi, quite new to Splunk. I have had a look at the various documentation and have managed to come this far (see below)...
by abdulhasnath New Member in Getting Data In 10-24-2019
0 4
0
4
geoffmoraes
I want to run a search where if AuthenticationMethod!=x509_PKI even once within 6 hours, it should not show the host ...
by geoffmoraes Path Finder in Getting Data In 10-24-2019
1 6
1
6
Bentash
anyone knows why stash sourcetype for a particular app(demisto in this case) going to index=main? i believe these are...
by Bentash Explorer in Getting Data In 10-24-2019
0 2
0
2
akg2019
Hi, I have a VDI desktop environment with 100's of thin clients. Also i have a Splunk Enterprise in place that monit...
by akg2019 Explorer in Getting Data In 10-24-2019
1 1
1
1
julienoud
hello, I want to change my source names in shorter ones. At first I had something that worked very well. transforms....
by julienoud New Member in Getting Data In 10-24-2019
0 1
0
1
thinman
I have a file a like to upload to splunk with the following data:   72162397   SANTA CRUZ   00   33527710 01/08/201...
by thinman Explorer in Getting Data In 10-24-2019
1 8
1
8
rohankin
Hi, I am new to Splunk and am stuck at the this problem. To elaborate: I have attached example of datasets and the ...
by rohankin New Member in Getting Data In 10-24-2019
0 8
0
8
muizash
I want to know where is the location of launch.conf in our whole environment because i have to edit the proxy server ...
by muizash Path Finder in Getting Data In 10-24-2019
0 3
0
3
clintonburnett
I am looking to integrate Avanan a phishing solution and send its security logs that are in JSON format to an on prem...
by clintonburnett Explorer in Getting Data In 10-23-2019
0 9
0
9
shoof
Hello, We have an integration test which verifies expected values after deploying a new splunk instance. This test ...
by shoof New Member in Getting Data In 10-23-2019
0 1
0
1
Mkaz
I checked through the answers and cannot find anything that matches or will work... I am asking how to rename a tabl...
by Mkaz New Member in Getting Data In 10-23-2019
0 4
0
4
tan_junyuan
For some reason, 1 liner entries are send to my splunk, after incapsula logs shifted to LEEF format. Initially, we we...
by tan_junyuan Engager in Getting Data In 10-23-2019
0 4
0
4
mgallacher
Before you ask, I have found at least 10 questions similar to this as well as two identical questions, both of which ...
by mgallacher Engager in Getting Data In 10-22-2019
2 2
2
2
lmaclean
Hi, Have an issue with a Splunk deployment on Windows (Server '08 Datacenter R2) with the end-user assets being Wind...
by lmaclean Path Finder in Getting Data In 10-22-2019
0 5
0
5
graju89
Hi, I am new to splunk. Need some help in log filtering. I have below example log: p 12 02:04:55 xxx,[DEFAULT_LOG] 2...
by graju89 Path Finder in Getting Data In 10-22-2019
0 2
0
2
matthew_foos
Splunkers, To meet a regulatory requirement, I need to alert on if a syslog device does NOT send data to the Indexer...
by matthew_foos Path Finder in Getting Data In 10-22-2019
0 4
0
4
kranthimutyala
Hi Guys, I have the below sample data , i want to mask the string after Basic and tried below transforms.conf and s...
by kranthimutyala Path Finder in Getting Data In 10-22-2019
0 2
0
2
jefthompson
Hello Is Splunk capable of clustering indexers and search heads that are in different Azure regions
by jefthompson New Member in Getting Data In 10-22-2019
0 1
0
1
CsungyiPepi19
Can I filter logs coming from forwarders with config files under \etc\system or logs can be filtered just from heavy ...
by CsungyiPepi19 New Member in Getting Data In 10-22-2019
0 3
0
3
o_calmels
Hi splunkers, I need to enrich the Checkpoint Firewall logs with the username in my corporate VPN logs. On a first ...
by o_calmels Communicator in Getting Data In 10-22-2019
0 2
0
2
sloshburch
Two indexes are failing bundle validation checks on my cluster master with this error message: [Critical] App='syst...
by sloshburch Ultra Champion in Getting Data In 10-21-2019
1 1
1
1
Lowell
I just recently started using Windows 2008 and when I got splunk setup and forwarding thge Windows event logs and I n...
by Lowell Super Champion in Getting Data In 10-21-2019
6 14
6
14
adalbor
Hey All, We have been experiencing issues with latency concerning Windows events being processed/indexed in Splunk. A...
by adalbor Builder in Getting Data In 10-21-2019
0 0
0
0
derekho55
As with many folks, my IIS logs are setup to run with GMT timestamps. I have setup "TZ=GMT" on the sourcetype setup f...
by derekho55 Explorer in Getting Data In 10-21-2019
0 0
0
0
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors