Getting Data In

Getting Data In
Community Activity
mzeb
I have an event that has a syslog preamble with a JSON body. They take this shape: <190>0 2019-08-27T17:51:22.87657...
by mzeb New Member in Getting Data In 08-27-2019
0 1
0
1
jms112080
I'm using the lastest version of the app and Splunk 7.0.1 and I've tried every suggestion I can find on the Splunk we...
by jms112080 New Member in Getting Data In 08-27-2019
0 3
0
3
omuelle1
Hi, I am working in a shared environment with several Heavy Forwarders that sent data to Splunk Cloud Indexers and a...
by omuelle1 Communicator in Getting Data In 08-27-2019
0 1
0
1
jarrebola
Hi I have this data indexed, as you can see there is only one monitored_element_id. {"monitored_jobs":[{"monitored_e...
by jarrebola Explorer in Getting Data In 08-27-2019
0 2
0
2
abhijit_mhatre
The configuration I have written to ingest MSExchange management data isn’t ingesting all the information contained i...
by abhijit_mhatre Path Finder in Getting Data In 08-27-2019
0 4
0
4
brutecat
Hi, I am doing some experimentation wirh regards JSON events. I have two events loaded: {<!-- --> "event": ...
by brutecat Path Finder in Getting Data In 08-27-2019
0 4
0
4
net1993
Hello I found this attribute in mysql app in props.conf: PREAMBLE_REGEX &#61; #\sTime:\s\d&#43;\s&#43;\d{1,2}:\d{2}:\d{2} test ...
by net1993 Path Finder in Getting Data In 08-26-2019
0 12
0
12
nick405060
Hi guys I want to forward some of my data from my indexer to one port on our Rapid7 InsightIDR server, and some of m...
by nick405060 Motivator in Getting Data In 08-26-2019
0 0
0
0
shocko
I'm using Splunk 6.1.4 (soon to be 7.x). I've processed some windows event log data and as per normal Spunk processin...
by shocko Contributor in Getting Data In 08-26-2019
0 12
0
12
lufermalgo
Hi community, I need your help to resolve a question. Is it possible to obfuscate / mask data that is sent via HEC? ...
by lufermalgo Path Finder in Getting Data In 08-26-2019
0 5
0
5
shivanandbm
i see duplicate data getting indexed.its impacting license. can you please suggest how i can fix this.below is the mo...
by shivanandbm Explorer in Getting Data In 08-26-2019
0 2
0
2
wilcompl1334
We have encountered an odd process, named 'streamfwd.exe.delete_me', running on a test instance that we are piloting ...
by wilcompl1334 Explorer in Getting Data In 08-26-2019
0 0
0
0
dglass0215
Hello, I have my props/transforms setup so that it routes data to specific indexes (For the most part) based on hos...
by dglass0215 Path Finder in Getting Data In 08-26-2019
0 3
0
3
sendijsd
Greetings, In my environment, I have set up an Universal Forwarder that is monitoring a single server .log file, whi...
by sendijsd Engager in Getting Data In 08-26-2019
0 2
0
2
bkeif
Hi everyone, I have Splunk_TA_aws and Splunk_TA_aws_knowledgeonly deployed to a distributed splunk environment from ...
by bkeif Path Finder in Getting Data In 08-26-2019
0 8
0
8
anantdeshpande
Hi team, I am not able to index below JSON data in Splunk 6.2 with below props.conf attributes. Its breaking at ever...
by anantdeshpande Path Finder in Getting Data In 08-26-2019
0 4
0
4
msmita
Hi All, Wanted to know ,is there any checkpoint stored to allow splunk forwarder to skip events already sent earlier...
by msmita New Member in Getting Data In 08-26-2019
0 3
0
3
aalhabbash1
Hi Splunker; The syslog server store any logs coming to it by syslog on files as .log file then Splunk read this lo...
by aalhabbash1 Path Finder in Getting Data In 08-26-2019
0 8
0
8
jip31
hello I want to create a new sourcetype from the csv file below https://www.cjoint.com/c/IHvhvr2JHYh I dont want to ...
by jip31 Motivator in Getting Data In 08-26-2019
0 2
0
2
rleviseur
When configuring ingest-time log to metrics conversions via props.conf and transforms.conf, does Splunk still index t...
by rleviseur Explorer in Getting Data In 08-25-2019
0 1
0
1
akshatj2
HI All, I have created an inputs stanza for syslog input and created a manual host override using transforms. I trie...
by akshatj2 Path Finder in Getting Data In 08-25-2019
0 3
0
3
DavidHourani
Hi guys, Is it possible to run Splunk using a micro services architecture ? I heard that it was going to be suppor...
by DavidHourani Super Champion in Getting Data In 08-24-2019
0 9
0
9
shivanandbm
can we block forwarder from sending data using serverclass.conf in deployer. we have option to blacklist the host in ...
by shivanandbm Explorer in Getting Data In 08-23-2019
0 1
0
1
pprice21
I'm relatively new to splunk, and am working to do some auditing of sensitive groups within our active directory. I...
by pprice21 New Member in Getting Data In 08-23-2019
0 0
0
0
wgawhh5hbnht
I'm attempting to find events when EventCodes occur in 1, 3, 13, then 4689. (Detection of psexec via windows logs). H...
by wgawhh5hbnht Communicator in Getting Data In 08-23-2019
0 3
0
3
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...