Getting Data In

Getting Data In
Community Activity
Splunk_rocks
when i run below search its extracting data from AWS bucket so how ican convert this to search time in splunk cloud a...
by Splunk_rocks Path Finder in Getting Data In 09-01-2019
0 2
0
2
tsheets13
We have Universal Forwarder on our windows servers varying in version from 6.2.3 to 7.1.3. Our Splunk Enterprise ver...
by tsheets13 Communicator in Getting Data In 09-01-2019
0 8
0
8
pavanae
The following is transforms.conf in my search head [a_b] SOURCE_KEY = _meta REGEX = (logtype::A.*(id::(123|456)|(id:...
by pavanae Builder in Getting Data In 09-01-2019
0 4
0
4
cedmunds
I have logs going from the Universal Forwarder but are going to the Unknown Folder instead of uploading to the Cloud....
by cedmunds New Member in Getting Data In 09-01-2019
0 3
0
3
maxd
I have a script that pulls the data at the bottom into a file and then splunk pull the files from the corresponding d...
by maxd Engager in Getting Data In 09-01-2019
0 5
0
5
givehchin
hello, I want to track all active session(RDP) in the network and see who login which server, what is the source IP a...
by givehchin Path Finder in Getting Data In 09-01-2019
0 7
0
7
PavelP
to make the configuration more readable I use "\" to break long lines, which works fine: EVAL-user = case ( FOO="Act...
by PavelP Motivator in Getting Data In 08-31-2019
0 3
0
3
joemaz95
There are 2 endpoints that seem to return extractions which are data/transforms/extractions and data/props/extraction...
by joemaz95 Path Finder in Getting Data In 08-30-2019
0 10
0
10
_smp_
I'm having some difficulty forcing Splunk to ignore events which start with a '#' character. The file is compressed, ...
by _smp_ Builder in Getting Data In 08-30-2019
0 21
0
21
splunkjas1
For several UF's, I've noticed that the metrics.log 'per_sourcetype_thruput' entries have stopped completely, for day...
by splunkjas1 Path Finder in Getting Data In 08-30-2019
0 1
0
1
aalaa
Hello , Please i need to filter data on the heavy forwrader to eliminate some logs , Exemple : i need to ingnore ...
by aalaa Path Finder in Getting Data In 08-30-2019
0 2
0
2
gopiven
Hi Experts Actually I am searching on one index, where Userid is with multiple fields like user,userids,useridvalue,...
by gopiven Explorer in Getting Data In 08-30-2019
0 2
0
2
saiynv
Hi, I am trying to extract a JSON log file at index time. The log structure has a nested key(key,value) pairs. Like f...
by saiynv New Member in Getting Data In 08-30-2019
0 5
0
5
nareshinsvu
Below is my use-case (Heavy Forwarders -> Indexers). Need expert assessment. 1) I have very huge log files. 2) So, I...
by nareshinsvu Builder in Getting Data In 08-29-2019
0 8
0
8
nick405060
I would like to be able to forward logs and then delete them using a UF. How can I do this? For the sake of the Splu...
by nick405060 Motivator in Getting Data In 08-29-2019
0 2
0
2
thirusama
JSON fields are extracted twice. On Universal forwarder (7.0.3) the settings props.conf are like this [my_sourcetyp...
by thirusama Path Finder in Getting Data In 08-29-2019
0 12
0
12
donaldson8
We're running a Splunk indexer behind an Nginx proxy in order to apply HSTS headers. However, we recently noticed tha...
by donaldson8 New Member in Getting Data In 08-29-2019
0 0
0
0
siva_cg
Hi All, We have a Splunk environment running on 6.2.2. We configured a TCP input to receive logs directly from netwo...
by siva_cg Path Finder in Getting Data In 08-29-2019
0 9
0
9
test_qweqwe
Hello all. I'm now working out how to detect tor traffic. How better me do this? Maybe some articles, guides, some tr...
by test_qweqwe Builder in Getting Data In 08-29-2019
0 6
0
6
flyingpiglet
Hi, There is a task to index csv structured files where the structure depends on one or several fields. For example i...
by flyingpiglet Engager in Getting Data In 08-29-2019
0 0
0
0
psychogyiokosta
Hello. I am new with Splunk, I have the following question/issue: My goal is to parse a raw log file with Splunk an...
by psychogyiokosta New Member in Getting Data In 08-29-2019
0 6
0
6
kbakeragx
New to Splunk, I am trying to get logs forwarded from a 2003 server that we have, but having no luck. I installed a ...
by kbakeragx New Member in Getting Data In 08-28-2019
0 5
0
5
rdevudra
The logs are forwarding to from our server to the Splunk server. But the logs are not readable format. (Attached scr...
by rdevudra New Member in Getting Data In 08-28-2019
0 3
0
3
markhvesta
I am trying to anonymize customer credit card data in splunk logs but when more than one card appears in the same eve...
by markhvesta Path Finder in Getting Data In 08-28-2019
0 2
0
2
asofo
Trying to reduce some of the noise caused by NTLM failures by adding the following to our Windows Event Log stanza fo...
by asofo Path Finder in Getting Data In 08-28-2019
0 7
0
7
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors