| Thread Info | |||||
|---|---|---|---|---|---|
| 
        We have client with splunk enterprise instance and we need to send some logs from this instance directly to elasticse...
        
         
           by 
           
                
                    
                        smstoyanov
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               07-11-2018
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        So, I pushed Splunk out to our entire non-production AIX farm. It is working on 50 hosts just fine, but, fails on a s...
        
         
           by 
           
                
                    
                        ericmck2000
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               11-01-2016
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        Hi,  
  I have set up a deployment server with a test app directory under etc/deployment-app along with a default inp...
        
         
           by 
           
                
                    
                        Suyalag
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               09-06-2016
             
           
         
        | 
		
		0
   | 
	  
	  14
	 | |||
| 
        Hello, 
  I have taken on a project at work to migrate all of our old MSSQL reports into Splunk. The SQL in these rep...
        
         
           by 
           
                
                    
                        sochsenbein
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               07-10-2018
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hello, Could you please let me know how to install eventgen in window environment. Regards, Anjan
        
         
           by 
           
                
                    
                        anjchatt
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               05-02-2018
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Can IBM SMF records be input to Splunk from z/OS? I am interested in indexing RACF data specifically.
        
         
           by 
           
                
                    
                        CZ1900Splunker
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               12-02-2013
             
           
         
        | 
		
		0
   | 
	  
	  12
	 | |||
| 
        I trying to create a graph which will be display difference beetwen values at different time.  "2018-07-10 15:37:16,3...
        
         
           by 
           
                
                    
                        slipinski
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-10-2018
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi Splunk experts,  
  Need to understand the basic function of these stanza's FORMAT, DEST_KEY, SOURCE_KEY and MV_AD...
        
         
           by 
           
                
                    
                        Hemnaath
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               06-21-2018
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi all, 
  we saw this log from cisco IOS in splunk: ...Jul 4 16:43:42 HOSTNAME 19028: 10.1.1: Jul 4 16:43:42.804: %L...
        
         
           by 
           
                
                    
                        tfechner
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-04-2018
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi splunk professionals, 
  I see a unexpected behavior about inputlookup command in ver 7.1.1. The detail of unexpec...
        
         
           by 
           
                
                    
                        Shuhei052492
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-04-2018
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I'm trying import an xml and using Line_breakers and such I could get clean events that have my data of interest. Res...
        
         
           by 
           
                
                    
                        splunk2day
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-05-2018
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have splunk setup in multiple environments (DEV/TST/PRD) with their own SearchHead, Deployment Servers, License Ser...
        
         
           by 
           
                
                    
                        sharkannon
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-04-2018
             
           
         
        | 
		
		0
   | 
	  
	  9
	 | |||
| 
        good afternoon 
     I'm trying to capture a particular field, but sometimes my events come several times, and declar...
        
         
           by 
           
                
                    
                        efaundez
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-06-2018
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi, to test the upgrade process, we created a clone of our current splunk server (6.6.8 running on Windows Server 201...
        
         
           by 
           
                
                    
                        BerndS
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               06-28-2018
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I am currently unable to parse my multi-line event properly using Splunk. Here is an example from the start of the ev...
        
         
           by 
           
                
                    
                        smcdonald20
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-09-2018
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I have NAS servers and splunk installed in Windows server, my new logs in a NAS server stopped indexing. I did troubl...
        
         
           by 
           
                
                    
                        CONSORP
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Getting Data In
           
           
              
               07-06-2018
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi, 
  Is it possible to do the following on one Splunk Universal Forwarder: 
  inputs.conf 
  `[WinEventLog://Securi...
        
         
           by 
           
                
                    
                        Ant1D
                    
                
           
             
             
               Motivator
             
           
           in
           Getting Data In
           
           
              
               07-09-2018
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Layer7 was acquired by CA and is offered as an API Management Platform. It seems that Layer7 should be able to send l...
        
         
           by 
           
                
                    
                        Phranquelyn
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               02-09-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello Experts!!! 
  I am new to Splunk and just started learning Splunk from couple of days. 
  We are using an in-ho...
        
         
           by 
           
                
                    
                        gaurav_bhide
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               07-08-2018
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi all, 
  I do have a log which does look like this: 
  Jul  6 09:31:18.729: %SYS-5-CONFIG_I: Configured from consol...
        
         
           by 
           
                
                    
                        MERBAG
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-06-2018
             
           
         
        | 
		
		0
   | 
	  
	  15
	 | |||
| 
        Hi all, I need some help parsing a JSON containing none/one/multiple nested messages that I have imported via REST AP...
        
         
           by 
           
                
                    
                        claudio_palmeri
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-06-2018
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        We have a cloud foundry set up and wants to forward the logs to splunk as syslog drain. The TCP/UDP input method is n...
        
         
           by 
           
                
                    
                        sgp0637
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-13-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, I would like to forward pcap data using tcpreplay on a remote machine which has installed a stream forwarder to f...
        
         
           by 
           
                
                    
                        weicheng98
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-07-2018
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Events from our DEV/PROD servers are ingested into the same index. This index already has events since 1 year. The on...
        
         
           by 
           
                
                    
                        ReachDataScient
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-06-2018
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        I have the _raw data in the following format. I just need to split that data and show each value in a separate column...
        
         
           by 
           
                
                    
                        arkisa
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               07-06-2018
             
           
         
        | 
		
		0
   | 
	  
	  1
	 |