Getting Data In

Getting Data In
Community Activity
rg0nzalez
Is it possible to ingest data related specifically from Microsoft Defender Safe Links?  We have tried both Microsoft ...
by rg0nzalez New Member in Getting Data In 09-10-2024
0 1
0
1
brent_weaver
I am working to decommission some indexers from my cluster. I am using splunk offline --enforce-counts and letting th...
by brent_weaver Builder in Getting Data In 09-10-2024
0 2
0
2
Iana_R
Hello guys,I am quite new on the topic so I really need tyour help ^_^.I am ingesting Zscaler logs in a Splunk Cloud ...
by Iana_R Loves-to-Learn Lots in Getting Data In 09-10-2024
0 1
0
1
jesperbassoe
Hi folks..I have an issue where I can't get an event to break right.The event looks like this  **********************...
by jesperbassoe Explorer in Getting Data In 09-09-2024
0 4
0
4
arunkuriakose
 I have logs indexed like this. How to break entries based on each lines . i need each line as a seperate entry. I tr...
by arunkuriakose Explorer in Getting Data In 09-09-2024
0 7
0
7
yallami
Hello, i am trying to intergrate the Splunk Ui Toolkit into my  own Splunk instace that is running on localhost.I am ...
by yallami Explorer in Getting Data In 09-09-2024
0 3
0
3
Redwood
Hi all, I am a bit of a newbie here, and am trying to setup HEC on splink cloud, however the URL I have created follo...
by Redwood Loves-to-Learn Lots in Getting Data In 09-08-2024
0 2
0
2
vpsmax
Hello.Trying to test a sourcetype using "oneshot".  Although we were able to add raw data using "oneshot" the first t...
by vpsmax Path Finder in Getting Data In 09-07-2024
0 3
0
3
markconlin
I am attempting to test a SEDCMD for event manipulation and it does not appear this is possible via oneshot? When I t...
by markconlin Path Finder in Getting Data In 09-07-2024
0 2
0
2
NullZero
I'm using a distributed Splunk Enterprise environment with over 15 peers at the Indexer Tier.  I have some JSON data ...
by NullZero Path Finder in Getting Data In 09-07-2024
0 4
0
4
sagar_shubham23
Hi Folks, I am trying to backlist the gz files in input.conf. But somehow the blacklist doesn't work properly. Files ...
by sagar_shubham23 Explorer in Getting Data In 09-06-2024
0 3
0
3
jm_tesla
Suppose I have `/var/log/nginx/access.log` and then a dozen files in the same directory named like `access.log-<date>...
by jm_tesla Engager in Getting Data In 09-05-2024
0 5
0
5
ryanf
Hi everyone,I’m currently sending vCenter logs via syslog to Splunk and have ensured that the syslog configuration an...
by ryanf Engager in Getting Data In 09-05-2024
0 1
0
1
Ricco19
Hi, The Splunk Heavy Forwarders and Deployment Servers were running under Splunk user. Unfortunately, during the upgr...
by Ricco19 Loves-to-Learn in Getting Data In 09-05-2024
0 1
0
1
rweales
We have been using Splunk on a Windows server without issue.  It ingested logs from Vmware hosts, networking hardware...
by rweales Explorer in Getting Data In 09-04-2024
0 9
0
9
solman07
Hello all, implementing some routing at the moment in order to forward a subset of data to a third party syslog syste...
by solman07 New Member in Getting Data In 09-04-2024
0 1
0
1
discenzadoe
We are working with several remote datasets that are combined to give our end user a specific result.  Federated Sear...
by discenzadoe Explorer in Getting Data In 09-04-2024
0 3
0
3
adrifesa95
Hello, We are ingesting Checkpoint logs through an Edge Processor to our SCP. We have deployed Splunk Add-on for Chec...
by adrifesa95 Engager in Getting Data In 09-04-2024
0 2
0
2
kig121
Hi,I have a splunk search which give back the testcase_id's.I need a button which call a rest API request.Rest API in...
by kig121 Loves-to-Learn Lots in Getting Data In 09-03-2024
0 5
0
5
markhvesta
I am trying to route metric type events to a null queue to avoid indexing them but they are still coming through.  An...
by markhvesta Path Finder in Getting Data In 09-03-2024
0 6
0
6
KhalidAlharthi
I have events from Trellix Hx appliance and i need to adjust _time of the log events because it coming as 9/3/20 and ...
by KhalidAlharthi Explorer in Getting Data In 09-03-2024
0 2
0
2
DanAlexander
Hello, community, I need help reducing Events containing 4688 and ParentProcessName=*splunkd.exe There is an excerpt ...
by DanAlexander Communicator in Getting Data In 08-30-2024
0 2
0
2
Dyrock
Hello,This is my first experience with Splunk as I am setting up a lab.in VirtualBox I have:VM1: Act as server: Ubunt...
by Dyrock Engager in Getting Data In 08-29-2024
0 1
0
1
UnsuperviseLeon
Hello! I am trying to collect 3 additional Windows Event logs and I have added them in the inputs.conf, for example [...
by UnsuperviseLeon Loves-to-Learn in Getting Data In 08-29-2024
0 5
0
5
gchappel
BackgroundI have a very legacy application with bad/inconsistent log formatting, and I want to be able to somehow col...
by gchappel Observer in Getting Data In 08-29-2024
0 2
0
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...
Top Solution Authors