Getting Data In

Getting Data In
Community Activity
johannterc
We have two Active Directory forests in our enterprise with Universal Forwarders installed on all of our domain contr...
by johannterc New Member in Getting Data In 01-03-2019
0 3
0
3
jskopis5668
I defined a scripted input: [script://$SPLUNK_HOME/etc/apps/ccbn/bin/get_domain_by_date] disabled = true host = dbse...
by jskopis5668 Explorer in Getting Data In 01-03-2019
3 4
3
4
sboogaar
We are working with the following JSON generated by a dcos/marathon api: When I run: index=dcos sourcetype="dcos:...
by sboogaar Path Finder in Getting Data In 01-03-2019
0 9
0
9
jincy_18
Hi All, We are working on a clustered environment where splunk is fetching logs from various servers. In the source ...
by jincy_18 Path Finder in Getting Data In 01-02-2019
0 1
0
1
rung8
Hi everyone, As the title suggests I was wondering if I can filter the logs that go into Splunk to avoid the daily v...
by rung8 New Member in Getting Data In 01-02-2019
0 3
0
3
muizash
What could be the possible reason that Windows security logs are not coming from the forwarders? How do I troublesho...
by muizash Path Finder in Getting Data In 01-02-2019
0 1
0
1
WXY
I want to extract the year, month and day from the file name. The file name format is: aa_1_20180701.csv OR aa_2_2018...
by WXY Path Finder in Getting Data In 01-02-2019
0 5
0
5
raj_mpl
I have a problem here. My shell script is not giving the complete output in the Splunk search head . What is the comm...
by raj_mpl Path Finder in Getting Data In 01-02-2019
0 2
0
2
coltwanger
When a server is decommissioned in our environment, it's brought offline, severing the communication with Splunk. The...
by coltwanger Contributor in Getting Data In 01-02-2019
0 3
0
3
kadamshridhar01
I want to know using postman how can find the result of below query sourcetype="httpevent" 69272d19-53a9-4539-b149-9...
by kadamshridhar01 New Member in Getting Data In 01-01-2019
0 3
0
3
skoelpin
I have a forwarder on 3 different servers which grabs all the data coming from those servers. There is 1 specific sou...
by SplunkTrust SplunkTrust in Getting Data In 12-30-2018
0 8
0
8
claudio_manig
Hello Ninjas, Does anybody have an idea of how to properly define a volume of 5TB of total storage in indexes.conf? ...
by claudio_manig Communicator in Getting Data In 12-28-2018
0 1
0
1
ssankeneni
Do SplunkForwarder forward the metrics.log to the Splunk indexer automatically? I can see the splunkd.log files but n...
by ssankeneni Communicator in Getting Data In 12-28-2018
0 4
0
4
aab5272
In standalone environment why my splunk enterprise don't have "source=*metrics.logs " at certain hours.
by aab5272 Engager in Getting Data In 12-28-2018
0 2
0
2
vaibhavagg2006
Hi Experts I am trying to disable an alert using below rest API example provided in the documentation. It returns bac...
by vaibhavagg2006 Communicator in Getting Data In 12-28-2018
0 19
0
19
neerajshah81
Hi All, I have a single instance Splunk 7.1.2 on Windows platform. I am getting lot of events related to Perfmon...
by neerajshah81 Path Finder in Getting Data In 12-28-2018
0 20
0
20
efaundez
Good Morning, We have the following concern. We currently have several universal forwarders sending information to t...
by efaundez Path Finder in Getting Data In 12-28-2018
0 1
0
1
jpena323
Hi guys, I am having a really hard time figuring out how to get the sedcmd to work in props.conf. I'd appreciate any...
by jpena323 Explorer in Getting Data In 12-28-2018
2 5
2
5
crsupportddc
Is there any way to get only critical and error logs from Windows? I mean, Windows generates logs using different le...
by crsupportddc Explorer in Getting Data In 12-28-2018
0 3
0
3
salpaysog
I have two csv files of email adresses that I want to compare by listing email adresses only available in one (and re...
by salpaysog Explorer in Getting Data In 12-28-2018
0 2
0
2
justodaniel
I hava a log on a Windows server like this: D:\SplunkTest\confidencial.log and on this log, I have data like this: n...
by justodaniel Path Finder in Getting Data In 12-27-2018
1 15
1
15
derekf
Our use case is: we have an organization that would sign in to only use the REST API with a web app we have built. ...
by derekf Explorer in Getting Data In 12-27-2018
0 3
0
3
TiagoTLD1
Hello, I am facing this behaviour: when searching for thin index, I see events of sourcetype=broker, like shown in t...
by TiagoTLD1 Communicator in Getting Data In 12-26-2018
0 6
0
6
mwk
I've been trying things to figure this out for a few months now off and on. I get close but . . . and since my log o...
by mwk Explorer in Getting Data In 12-26-2018
0 4
0
4
kaumiladani
I have a macro.conf file containing a macro with definition: definition = index="SOME_INDEX" AND sourcetype="SOME_SOU...
by kaumiladani New Member in Getting Data In 12-25-2018
0 0
0
0
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...
Top Solution Authors