Getting Data In

Getting Data In
Community Activity
bobcatluke
Hi all, I created a job in Rundeck that lets you select a Splunk app and a time period, then enables/disables the app...
by bobcatluke Explorer in Getting Data In 07-19-2019
0 1
0
1
woodcock
In $SPLUNK_HOME/etc/system/default/ we find this troublesome configuration in transforms.conf: [syslog-host] DEST_KE...
by Esteemed Legend in Getting Data In 07-19-2019
0 2
0
2
wfmseanm
Is there a way to modify a .conf file or a setting on an individual endpoint to only send data to a single heavy forw...
by wfmseanm New Member in Getting Data In 07-19-2019
0 1
0
1
nls7010
I set up a new index for one of my groups. In it they want to store their servers wineventlogs. I am unable to succe...
by nls7010 Path Finder in Getting Data In 07-19-2019
0 13
0
13
ankithreddy777
I have a situation where I have to parse the data, especially timestamp extraction based on the keyword in the messag...
by ankithreddy777 Contributor in Getting Data In 07-19-2019
0 6
0
6
koshyk
Hi I'm having issues while running script command within the search. I've tried running something like .. | saveds...
by koshyk Super Champion in Getting Data In 07-19-2019
1 7
1
7
aohls
I have read through the documentation and still feel that I am missing something with creating an index summary. I wa...
by aohls Contributor in Getting Data In 07-19-2019
0 6
0
6
satyaallaparthi
Hello, I have my own Splunk where I installed SPLUNK ES and I just got the Search head access from somebody's SPLU...
by satyaallaparthi Communicator in Getting Data In 07-19-2019
0 9
0
9
dglass0215
Hello, I am trying to implement setting a specific index based on part of the hostname. For ALL of my data that I ...
by dglass0215 Path Finder in Getting Data In 07-19-2019
0 6
0
6
ips_mandar
I want to know if below things are possible in splunk and if YES then How it can be achieved- 1. Below is sample even...
by ips_mandar Builder in Getting Data In 07-19-2019
0 5
0
5
Sujithkumarkb
I am trying to break the event based on the realm in the below example. My sourcetype "Iam_logs" is defined globally ...
by Sujithkumarkb Observer in Getting Data In 07-19-2019
0 1
0
1
riqbal47010
I want to configure HTTP Event collector on one of the Heavy forwarder. initially i create the app with named splunk...
by riqbal47010 Path Finder in Getting Data In 07-19-2019
0 3
0
3
lalbsah
I see below error while running installation script of Splunk Forwarder Add-on for WAS. $ python was_log_inputs.py ...
by lalbsah Engager in Getting Data In 07-18-2019
0 3
0
3
Sujithkumarkb
Each Realm entry should be an event, JSON is the source. Event1: {"realm":"/humapp","transactionId":"d9d6ba4e-c3bb...
by Sujithkumarkb Observer in Getting Data In 07-18-2019
0 5
0
5
hartfoml
I have file names like this "Patch-Data_2-1-2012.csv" How do I use the date in the file name for the datestamp for ...
by hartfoml Motivator in Getting Data In 07-18-2019
2 5
2
5
vsrigane
Hello, I am trying to configure Splunk Website Monitoring app to probe new application URLS. It was working fine, un...
by vsrigane Explorer in Getting Data In 07-18-2019
0 0
0
0
MikeVenable
I have a cluster environment, 3 indexers and one Master indexer/DMC/LM, a deployment server, syslog-ng Heavy Forwarde...
by MikeVenable Path Finder in Getting Data In 07-18-2019
0 2
0
2
vstariradev
We're trying to index json formatted logs from kubernetes pods by removing the json formatting and making the logs ap...
by vstariradev Explorer in Getting Data In 07-18-2019
0 0
0
0
dsuddu
Seeing lots of "Brute Force Access Behavior Detected" notable events coming from Microsoft domain controllers. The c...
by dsuddu Engager in Getting Data In 07-18-2019
6 4
6
4
plumainwfs
Not sure why the hostname for the monitor stanza below is not being parsed out... directory is as follows: /mnt/log...
by plumainwfs New Member in Getting Data In 07-18-2019
0 2
0
2
omri_p
I have installed the Splunk Add-on for Microsoft Windows App on the latest 6.0 Version on Splunk Enterprise 7.3 i am...
by omri_p Engager in Getting Data In 07-18-2019
0 0
0
0
3vi
Hello, I have a raw like this: .success [{"importo":2,"tipologiaOperazione":"AAA"},{"importo":1.82,"tipologiaOperazi...
by 3vi Engager in Getting Data In 07-18-2019
0 2
0
2
saramamurthy_sp
I have a setup, where I have one production indexer and another one is development indexer. I want all the data to be...
by saramamurthy_sp Splunk Employee Splunk Employee in Getting Data In 07-18-2019
0 2
0
2
alanzchan
I'm trying to minimize the amount of data from Kubernetes JSON events that are being indexed into my Splunk instance....
by alanzchan Path Finder in Getting Data In 07-17-2019
0 21
0
21
kevinbullock
How can I run a powershell script on a Universal Forwarder on-demand instead of scheduling it in the inputs.conf and ...
by kevinbullock New Member in Getting Data In 07-17-2019
0 0
0
0
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...