Getting Data In

Getting Data In
Community Activity
patricianaguit
Whats the difference between calling one transforms and two transforms in a props.conf file? 1 transform: TRANSFORMS...
by patricianaguit Explorer in Getting Data In 07-18-2018
0 1
0
1
R_B
Hi everyone, In my environment, we are collecting logs from several types of devices on a syslog server, then forwar...
by R_B Path Finder in Getting Data In 07-18-2018
1 7
1
7
dennisSplunk201
So my original data looks like this: AUDIT_CREATED_TS 7/17/2018 1:15:30 AM 7/17/2018 1:10:30 AM 7/17/2018 1:05:41 AM ...
by dennisSplunk201 New Member in Getting Data In 07-18-2018
0 6
0
6
Naren26A
I have existing Universal Forwarder setup for our prod Splunk Enterprise instance. Now, I am trying to setup a dev Sp...
by Naren26A Engager in Getting Data In 07-18-2018
0 5
0
5
chrishartsock
I am doing some automation in which I am running some searches through the API, and if any results are found, it emai...
by chrishartsock Path Finder in Getting Data In 07-18-2018
0 5
0
5
Salma1
0
3
JuhiSaxena
I have an index whose data is being fetched from UDP port. Index is experiencing latency [lag in events] and we suspe...
by JuhiSaxena Explorer in Getting Data In 07-18-2018
0 12
0
12
swetar
Hi, I am passing a log file . The field values for message field is incomplete. Also the Message field has many patt...
by swetar New Member in Getting Data In 07-18-2018
0 2
0
2
pokpok
Hello, I'm facing a strong issue with using a mstats command, working in a post-processing components on a dynamic w...
by pokpok New Member in Getting Data In 07-18-2018
0 0
0
0
gots
Is it possible to get data in splunk from unix stream socket? Not tcp\udp socket, but socket like this - https://en.w...
by gots Path Finder in Getting Data In 07-18-2018
0 7
0
7
patricianaguit
1) When to use SEDCMD? 2) When to use transforms and props for data masking? 3) Which is better?
by patricianaguit Explorer in Getting Data In 07-18-2018
0 2
0
2
Pharaon
Hi. I am a newborn splunk user. Logs come in the following format --Format-- @@dd/mm/yyyy_HH MMSS.msecond|Message... ...
by Pharaon Engager in Getting Data In 07-18-2018
0 2
0
2
Nadhiyaa
i have the https url and how to pull the xml data using the url from Splunk. Below is the sample url https://10.10...
by Nadhiyaa Path Finder in Getting Data In 07-18-2018
0 2
0
2
sarahkrisher
Is there an API call that can rebuild the forwarder asset table as opposed to going into the Distributed Management C...
by sarahkrisher New Member in Getting Data In 07-17-2018
0 2
0
2
khmohammadzadeh
Hello I want to change host name in TA-nmon and I have set the value of override_sys_hostname in /dbdata1/splunkforwa...
by khmohammadzadeh New Member in Getting Data In 07-17-2018
0 4
0
4
evinasco
Hi Splunkers I am working with Azure AD and Splunk Cloud and I need to get information about member's group like who...
by evinasco Communicator in Getting Data In 07-17-2018
0 1
0
1
LukeMurphey
If I have a modular input written in Python, will Splunk attempt to execute it on a Universal Forwarder if the host h...
by LukeMurphey Champion in Getting Data In 07-17-2018
1 6
1
6
Log_wrangler
I have an ec2 splunk instance writing frozen data to an s3 bucket (via s3fs). Where would I find in the splunk logs ...
by Log_wrangler Builder in Getting Data In 07-17-2018
0 2
0
2
ericlarsen
I have a JSON log file that I'm attempting to ingest (Splunk v6.6.5). The events parse correctly, but the epoch time...
by ericlarsen Path Finder in Getting Data In 07-17-2018
0 2
0
2
ssyed2009
I would like to convert an event similar to the one below to be a single event when sending it out to an external Sys...
by ssyed2009 New Member in Getting Data In 07-17-2018
0 2
0
2
bschaap
I'm ingesting logs that have both event timestamps as well as timestamps within the contents of the logs. My props.c...
by bschaap Path Finder in Getting Data In 07-17-2018
0 2
0
2
GenRockeR
Hi guys. In my splunk cluster i've distributed search indexers. On one of them I've this message. What can I fix thi...
by GenRockeR Explorer in Getting Data In 07-17-2018
0 2
0
2
Zamoraw
Hi there, I'm fairly new to Splunk and I am still a bit confused as to how I can tell what an instance is considered....
by Zamoraw New Member in Getting Data In 07-17-2018
0 1
0
1
neerajshah81
Hello, We have a single instance splunk deployment. I have installed Universal Forwarder on an Win 2012 R2 Active ...
by neerajshah81 Path Finder in Getting Data In 07-17-2018
0 6
0
6
yg
Can the "exception" log record that looks different from the regular log records and is spanned across a bunch of lin...
by yg Explorer in Getting Data In 07-17-2018
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...