Getting Data In

Getting Data In
Community Activity
QuintonS
my input.conf below, need to have a recursive path for subfolders and all files. But the below is not working, am I ...
by QuintonS Path Finder in Getting Data In 03-05-2019
1 4
1
4
mchang_splunk
I have a search-time extracted field defined in props.conf: [foo] EXTRACT-fields = msg=\".{20}(?<newfield>.{6}) ...
by mchang_splunk Splunk Employee Splunk Employee in Getting Data In 03-05-2019
0 1
0
1
soumyacharya91
I am trying to fetch the logs from a REST url. But when ever the url getting hit all the data is fetched from the url...
by soumyacharya91 Path Finder in Getting Data In 03-05-2019
1 2
1
2
kmower
I am still trying to work out sourcetype=iis . I am aware of the Add-On for IIS and have installed it, but I want to...
by kmower Communicator in Getting Data In 03-05-2019
0 3
0
3
swagner1965
We want to watch the /local .conf files on our forwarders and alert if changes are made. Is this as simple as settin...
by swagner1965 Path Finder in Getting Data In 03-05-2019
0 2
0
2
pattokt
Goal Query for a list of all users across a search head cluster Problem Not all users are returned by the query belo...
by pattokt Explorer in Getting Data In 03-05-2019
0 2
0
2
test4u
I have files with a time field that is of a previous date . I want to ingest these files in Splunk, but the indexed t...
by test4u Path Finder in Getting Data In 03-05-2019
0 2
0
2
AndersNierhoff
Hi Splunk community, I am facing some issue in using the Splunk modular input. The modular input is built around e...
by AndersNierhoff New Member in Getting Data In 03-05-2019
0 7
0
7
adriannicolicea
Hi, I am receiving the following error message in my inbox : Unable to initialize modular input "jmx" defined inside...
by adriannicolicea New Member in Getting Data In 03-04-2019
0 1
0
1
oversight
I am looking for assistance with unwanted fields extracted automatically. I am using a custom sourcetype that I adde...
by oversight Explorer in Getting Data In 03-04-2019
1 8
1
8
molinarf
I have been trying to get the Cisco eStreamer eNcore app to work and since rebuilding the FMC host, and using a routa...
by molinarf Communicator in Getting Data In 03-04-2019
0 10
0
10
pgelnar_usy
I am creating indexes, inputs and roles based on k8s namespace. I was granting user role capabilities, but now, I nee...
by pgelnar_usy Engager in Getting Data In 03-04-2019
0 2
0
2
nls7010
I want to NOT ingest the events that have INFO or WARN in them. Can I use the following in the Props.conf without an...
by nls7010 Path Finder in Getting Data In 03-04-2019
0 2
0
2
rip_leroi
I'm brand new to Splunk and I'm having difficulty getting a query to return the results I'm looking for. I've checke...
by rip_leroi Explorer in Getting Data In 03-04-2019
0 6
0
6
lhanich1
I have a heavy forwarder that is capturing incoming logs from thousands of Linux hosts. The hosts are sending their O...
by lhanich1 Path Finder in Getting Data In 03-04-2019
0 12
0
12
jchapell
I have a search that I am working on and running into problems. Currently, I have a CSV generated that contains al...
by jchapell Explorer in Getting Data In 03-04-2019
0 3
0
3
puneethgowda
Hi , We have noticed an issue in my Splunk environment: Issue: Data is getting duplicated twice in indexers. If i ...
by puneethgowda Communicator in Getting Data In 03-04-2019
0 9
0
9
Mayanakhan
Hi All, In our environment, Already our team installed the "Cisco UCS Add-On" and data is getting into splunk. Now...
by Mayanakhan Explorer in Getting Data In 03-04-2019
0 0
0
0
JWBailey
Good morning, I noticed recently that some of my events in splunk are no longer displaying account names and group n...
by JWBailey Communicator in Getting Data In 03-04-2019
0 2
0
2
funlearning321
Hello, I am new to splunk and learning it . I am trying the parse the events with specific keyword will dropping the...
by funlearning321 New Member in Getting Data In 03-04-2019
0 4
0
4
jvmerilla
Hello. I have an email alert that sends the results in a csv file attached to the email. The search result of this a...
by jvmerilla Path Finder in Getting Data In 03-03-2019
0 2
0
2
saurabh009
Hi, We have a requirement where we need to deploy an app having a script in it but interval of execution of script sh...
by saurabh009 Path Finder in Getting Data In 03-03-2019
1 6
1
6
horizonsecurity
I'm using *NIX app 4.6, and for auditd logs I have a duplication problem of events. I also checked the raw logs and t...
by horizonsecurity Explorer in Getting Data In 03-03-2019
0 8
0
8
RichaSingh
I have application data being collected on following shared folders over network : \qlikviewt1\east\torage\ \qlikv...
by RichaSingh Path Finder in Getting Data In 03-03-2019
0 4
0
4
yutaka1005
I want to configure routing that sends specific logs(syslog_test) to only 514 and other logs to 9997, so I edited pro...
by yutaka1005 Builder in Getting Data In 03-03-2019
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...
Top Solution Authors