Getting Data In

Getting Data In
Community Activity
AndreaSimon
We are trying to ingest Peregrine logs for Asset Manager and we can open the log file up on the windows server and it...
by AndreaSimon New Member in Getting Data In 11-21-2018
0 0
0
0
scottrunyon
i have multiple applications that place login information (Logon Date/Time, Logoff Date/Time, userid, etc.) into exis...
by scottrunyon Contributor in Getting Data In 11-21-2018
0 10
0
10
pbsuju
I have below entries from my logs and I want to remove ' from the beginning and end of the field value. valid_from='...
by pbsuju Explorer in Getting Data In 11-21-2018
0 1
0
1
Branden
Hi. I have an JSON event that has nested arrays of objects within it. In the Search app, it "prettifies" the top le...
by Branden Builder in Getting Data In 11-20-2018
0 4
0
4
ankithnageshshe
Hello Splunkers, Lately, we have been facing issues in on-boarding data due to the “Could not send…..parsing queue f...
by ankithnageshshe Path Finder in Getting Data In 11-20-2018
0 2
0
2
wissenaire17
I need to count the number of particular events in a transaction. Here, I NEED to count the number of tickets that ha...
by wissenaire17 New Member in Getting Data In 11-20-2018
0 3
0
3
a212830
Hi, I want to remove some legacy indexers from my cluster. I did the ./splunk offline --enforce-counts command, and...
by a212830 Champion in Getting Data In 11-20-2018
0 2
0
2
barney00
I have a main query which shows the destination IP of the computer and there are some destination IPs that I need to ...
by barney00 New Member in Getting Data In 11-20-2018
0 1
0
1
stevegadd
I have the following coming in via an XML file. Most of the attributes parse just fine using the default parser, but...
by stevegadd Explorer in Getting Data In 11-20-2018
1 0
1
0
jmads
I use Splunk on Windows. I have several heavy forwarders that forward Windows event logs to my indexer cluster into ...
by jmads Explorer in Getting Data In 11-20-2018
0 3
0
3
TitanAE
I currently have a universal forwarder and an indexer. The universal forwarder reads a number of CSV files. And the...
by TitanAE New Member in Getting Data In 11-19-2018
0 4
0
4
daniel333
All, How can I delete specific metrics? We have a GDPR concern that is preventing our metrics use cases. They are w...
by daniel333 Builder in Getting Data In 11-19-2018
0 0
0
0
rbal_splunk
I'm seeing the below errors when searching on a few different types of indexes: 7 errors occurred while the search w...
by rbal_splunk Splunk Employee Splunk Employee in Getting Data In 11-19-2018
0 1
0
1
chrismallow
I'm running a Bro sensor with some (obviously) very high-volume log files that I'm monitoring with the Universal Forw...
by chrismallow Engager in Getting Data In 11-19-2018
0 6
0
6
mlevsh
I need to read RoleStatus.csv file , that's being rolled over every day. The first line of file is always empty. L...
by mlevsh Builder in Getting Data In 11-19-2018
0 4
0
4
rakeshksingh
Hi All, I am looking for a field extraction at that time at indexing for JSON file format. {"field1": "a=\"1", b=\...
by rakeshksingh New Member in Getting Data In 11-19-2018
0 2
0
2
matstap
I ran this query: | makeresults | eval creationdate = "2018-11-15 20:00:00.000000000" | eval epoch=relative_time(no...
by matstap Communicator in Getting Data In 11-19-2018
0 4
0
4
mpasha
Good day, I am trying to monitor our User Account logon activity through Splunk. As you might know, Active directory...
by mpasha Path Finder in Getting Data In 11-19-2018
0 3
0
3
tgadbois
We have a 3-site cluster with one site being primary, the other two being for HA/DR. So all primary data goes to site...
by tgadbois New Member in Getting Data In 11-19-2018
0 2
0
2
damucka
Hello, I would need a confirmation of my CLONE_SOURCETYPE configuration. I have the following requirements: sourcet...
by damucka Builder in Getting Data In 11-19-2018
0 0
0
0
harishalipaka
HI All, I upgraded splunk 6.5 to splunk 7.1.1 version in linux.we are good with xml dashboards only.For html dashboar...
by harishalipaka Motivator in Getting Data In 11-18-2018
1 0
1
0
ajdyer2000
Hi, Right after the initial install of the Splunk Windows Forwarder the Splunk-Winevtlog.exe process consistently ru...
by ajdyer2000 Path Finder in Getting Data In 11-18-2018
0 1
0
1
mohan401
Hi All, I am using rsyslog and logstash agent to forward data to splunk. I am able to send data through tcp from rs...
by mohan401 Engager in Getting Data In 11-18-2018
0 0
0
0
brent_weaver
Good morning all, I am reading docs on how to create sourcetypes for metrics but none go into how to just use fields ...
by brent_weaver Builder in Getting Data In 11-18-2018
1 3
1
3
dloszewski
Hello, I'm having a hard time understanding why I'm receiving the values that I am for _time and _indextime. All ev...
by dloszewski New Member in Getting Data In 11-17-2018
0 1
0
1
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors