Getting Data In

Getting Data In
Community Activity
yohhpark
using UF to send json file and below are the props.conf.[test_json]pulldown_type = trueLINE_BREAKER = ([\r\n]+)INDEXE...
by yohhpark Path Finder in Getting Data In 07-30-2024
0 21
0
21
m130carbine
I am wanting to go into the Splunk Web and monitor the USBSTOR in Windows 10.  I am selecting the "New Registry Monit...
by m130carbine Loves-to-Learn Lots in Getting Data In 07-30-2024
0 1
0
1
tuts
Hello everyone, I want the Kerio Control technical guide that provides details on how to set up and configure a Syslo...
by tuts Path Finder in Getting Data In 07-30-2024
1 2
1
2
chandrasekhar46
i have json data but all the data getting in single event not parsing properly each event here is adding the event da...
by chandrasekhar46 Loves-to-Learn Everything in Getting Data In 07-30-2024
0 6
0
6
sarvesh_11
Hello,I am currently using Splunk UF 7.2 on a Windows Server, and my UF is configured on D Drive.I am getting below e...
by sarvesh_11 Communicator in Getting Data In 07-29-2024
0 3
0
3
sarit_s6
HelloI have one big index with lots of files which I want to reroute logs from there to different indexesThe reroute ...
by sarit_s6 Engager in Getting Data In 07-29-2024
0 12
0
12
benmstl
Hello Splunk communityin a nutshell my problem is i have set up splunk and a forwarder on a server, added input and o...
by benmstl New Member in Getting Data In 07-27-2024
0 2
0
2
splunkreal
Hello, we receive data using _TCP_ROUTING from forwarders from another team using another Splunk cluster.We don't use...
by splunkreal Influencer in Getting Data In 07-26-2024
0 2
0
2
Silah
Hey allI am taking input over TCP by having this in my inputs.conf [tcp://1.2.3.4:123] connection_host = ip index = i...
by Silah Path Finder in Getting Data In 07-26-2024
0 4
0
4
pavithra
Hi All,Data is not getting indexed after adding the conf
by pavithra Explorer in Getting Data In 07-25-2024
0 3
0
3
oreoshake
I have log files with color codes and control characters that we'd like to strip because they clutter the search resu...
by oreoshake Communicator in Getting Data In 07-25-2024
1 9
1
9
DoubleAka
How can I cut some parts of my message prior to index time?I tried to use both SEDCMD and transform on raw messages b...
by DoubleAka Observer in Getting Data In 07-25-2024
0 4
0
4
Gil
Hi, in our organization we use wef to monitor windows. we configure an inputs.conf for monitoring from the Event view...
by Gil Explorer in Getting Data In 07-25-2024
0 8
0
8
msalghamdi
Hello Splunkersi have clustered splunk 9.2.1 on prem, i have pushed an app from the CM to search head cluster and try...
by msalghamdi Path Finder in Getting Data In 07-24-2024
0 2
0
2
c86
HelloI am building an app using the Splunk Add-on builder. Can I use the helper.new_event method in order to send a m...
by c86 Loves-to-Learn in Getting Data In 07-24-2024
0 0
0
0
splunkreal
Subject moved to https://community.splunk.com/t5/All-Apps-and-Add-ons/Solution-Splunk-Enterprise-Security-ES-incident...
by splunkreal Influencer in Getting Data In 07-23-2024
0 1
0
1
jcorcorans
linux logs only showing epoch time - how to convert epoch time upon ingestion in props/trans ?is there a way or a con...
by jcorcorans Explorer in Getting Data In 07-23-2024
0 1
0
1
Nawab
We are using a clustered index environment and want to use NAS as our cold storage. I mapped NAS to a local folder fo...
by Nawab Communicator in Getting Data In 07-23-2024
0 2
0
2
sc3
Hello, We are interested in capturing Microsoft Teams PSTN call records.  There is a Microsoft Graph API  with specif...
by sc3 New Member in Getting Data In 07-23-2024
0 2
0
2
Rizqi_Iskandar
Hello everyone, im new in Splunk and still need a lot to know.I want to ask question, how to forward data in JSON for...
by Rizqi_Iskandar Loves-to-Learn Lots in Getting Data In 07-21-2024
0 4
0
4
splunkville
_raw data exported from a search query. This not the actual raw data stream from the sending device, correct? This is...
by splunkville Observer in Getting Data In 07-21-2024
0 1
0
1
ddrillic
We can reach via https://<deployment server>:8089/services/deployment/server/applications/<app name> to the deplo...
by ddrillic Ultra Champion in Getting Data In 07-20-2024
0 16
0
16
kmm2
get-brokersession is run via powershell and sent to a txt file.   The information is getting into splunk however, eve...
by kmm2 Path Finder in Getting Data In 07-19-2024
0 1
0
1
vijreddy30
The above screen shot Blue color line event into one Event and above Blue color lines in to single event please provi...
by vijreddy30 Loves-to-Learn Everything in Getting Data In 07-19-2024
0 6
0
6
ibraheem
With load balancing the Universal Forwarder sends data to all the indexers equally so that no indexer should get all ...
by ibraheem Explorer in Getting Data In 07-19-2024
0 0
0
0
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors