Getting Data In

Getting Data In
Community Activity
NatSec
Good day,I have installed Splunk ES v9.2.1 on a Linux server (CentOS 7.9). On Splunk ES server, I have installed Splu...
by NatSec Explorer in Getting Data In 07-31-2024
0 1
0
1
danielbb
When ingesting Microsoft Azure data, we see different time formats for different Azure categories, and I wonder how t...
by danielbb Motivator in Getting Data In 07-31-2024
0 1
0
1
yanjingz
The GWS is running for the whole company.Is it possible to only input a part of users' logs into Splunk, using add-on...
by yanjingz Splunk Employee Splunk Employee in Getting Data In 07-31-2024
0 1
0
1
im_bharath
Hello All, Currently a certain application is sending the data to splunk via syslog method(rsyslog) using TCP, so no...
by im_bharath Path Finder in Getting Data In 07-31-2024
0 3
0
3
sarlacc
I'm running Splunk Enterprise 9.1.1.  It is a relatively fresh installation (done this year).  Splunk forwarders are ...
by sarlacc Explorer in Getting Data In 07-30-2024
0 6
0
6
NanSplk01
I am trying to create a sourcetype for a new client:Note StartDate=xxxx is where the log begins.  However the StartTi...
by NanSplk01 Communicator in Getting Data In 07-30-2024
0 5
0
5
yohhpark
using UF to send json file and below are the props.conf.[test_json]pulldown_type = trueLINE_BREAKER = ([\r\n]+)INDEXE...
by yohhpark Path Finder in Getting Data In 07-30-2024
0 21
0
21
m130carbine
I am wanting to go into the Splunk Web and monitor the USBSTOR in Windows 10.  I am selecting the "New Registry Monit...
by m130carbine Loves-to-Learn Lots in Getting Data In 07-30-2024
0 1
0
1
tuts
Hello everyone, I want the Kerio Control technical guide that provides details on how to set up and configure a Syslo...
by tuts Path Finder in Getting Data In 07-30-2024
1 2
1
2
chandrasekhar46
i have json data but all the data getting in single event not parsing properly each event here is adding the event da...
by chandrasekhar46 Loves-to-Learn Everything in Getting Data In 07-30-2024
0 6
0
6
sarvesh_11
Hello,I am currently using Splunk UF 7.2 on a Windows Server, and my UF is configured on D Drive.I am getting below e...
by sarvesh_11 Communicator in Getting Data In 07-29-2024
0 3
0
3
sarit_s6
HelloI have one big index with lots of files which I want to reroute logs from there to different indexesThe reroute ...
by sarit_s6 Engager in Getting Data In 07-29-2024
0 12
0
12
benmstl
Hello Splunk communityin a nutshell my problem is i have set up splunk and a forwarder on a server, added input and o...
by benmstl New Member in Getting Data In 07-27-2024
0 2
0
2
splunkreal
Hello, we receive data using _TCP_ROUTING from forwarders from another team using another Splunk cluster.We don't use...
by splunkreal Influencer in Getting Data In 07-26-2024
0 2
0
2
Silah
Hey allI am taking input over TCP by having this in my inputs.conf [tcp://1.2.3.4:123] connection_host = ip index = i...
by Silah Path Finder in Getting Data In 07-26-2024
0 4
0
4
pavithra
Hi All,Data is not getting indexed after adding the conf
by pavithra Explorer in Getting Data In 07-25-2024
0 3
0
3
oreoshake
I have log files with color codes and control characters that we'd like to strip because they clutter the search resu...
by oreoshake Communicator in Getting Data In 07-25-2024
1 9
1
9
DoubleAka
How can I cut some parts of my message prior to index time?I tried to use both SEDCMD and transform on raw messages b...
by DoubleAka Observer in Getting Data In 07-25-2024
0 4
0
4
Gil
Hi, in our organization we use wef to monitor windows. we configure an inputs.conf for monitoring from the Event view...
by Gil Explorer in Getting Data In 07-25-2024
0 8
0
8
msalghamdi
Hello Splunkersi have clustered splunk 9.2.1 on prem, i have pushed an app from the CM to search head cluster and try...
by msalghamdi Path Finder in Getting Data In 07-24-2024
0 2
0
2
c86
HelloI am building an app using the Splunk Add-on builder. Can I use the helper.new_event method in order to send a m...
by c86 Loves-to-Learn in Getting Data In 07-24-2024
0 0
0
0
splunkreal
Subject moved to https://community.splunk.com/t5/All-Apps-and-Add-ons/Solution-Splunk-Enterprise-Security-ES-incident...
by splunkreal Influencer in Getting Data In 07-23-2024
0 1
0
1
jcorcorans
linux logs only showing epoch time - how to convert epoch time upon ingestion in props/trans ?is there a way or a con...
by jcorcorans Explorer in Getting Data In 07-23-2024
0 1
0
1
Nawab
We are using a clustered index environment and want to use NAS as our cold storage. I mapped NAS to a local folder fo...
by Nawab Communicator in Getting Data In 07-23-2024
0 2
0
2
sc3
Hello, We are interested in capturing Microsoft Teams PSTN call records.  There is a Microsoft Graph API  with specif...
by sc3 New Member in Getting Data In 07-23-2024
0 2
0
2
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors