Getting Data In

Getting Data In
Community Activity
caughtnakul
I have setup splunk add-on for AWS. For generic S3 bucket, we tried to add different format files into the bucket. Th...
by caughtnakul New Member in Getting Data In 06-29-2018
0 0
0
0
tezarin
Hi, I would like the Guacamole logs to get forwarded to the Splunk server and I added the log forwarding parameters...
by tezarin New Member in Getting Data In 06-29-2018
0 5
0
5
responsys_cm
There seems to be a bug searching events with JSON data if the field names are nested. For example: sourcetype=cmdb...
by responsys_cm Builder in Getting Data In 06-29-2018
0 2
0
2
npr72
Hi all, Is there any native way of configuring splunk or forwarders to periodically collect files using SFTP ? It...
by npr72 New Member in Getting Data In 06-29-2018
0 3
0
3
dwodeyla_bit9
I'm indexing some JSON data that describes an AWS security group. Inside this JSON are nested pairs of port combinati...
by dwodeyla_bit9 Engager in Getting Data In 06-29-2018
0 5
0
5
Hoekb03
I use a simple query to determine the amount of data I've sent to splunk: index=x |eval esize=len(_raw) |timechart s...
by Hoekb03 Explorer in Getting Data In 06-29-2018
0 1
0
1
MAMAOUI
Hello , I used spath command to extract field from json data: {"key":"value", "key":"value", "key":"value", "key":"...
by MAMAOUI Explorer in Getting Data In 06-29-2018
0 4
0
4
ashikuma
Getting issue while parsing events which have no timestamp in logs, it should use date\time from last log event times...
by ashikuma Explorer in Getting Data In 06-29-2018
0 9
0
9
pfabrizi
We are trying to pull in slack data using function1 which is not work as we are using the new api. We had a call with...
by pfabrizi Path Finder in Getting Data In 06-29-2018
0 4
0
4
the_wolverine
I've got a large number of orphaned objects that I'd like to clean up (delete). I don't see any way to do this in th...
by the_wolverine Champion in Getting Data In 06-28-2018
0 5
0
5
pfabrizi
I am using Graylog to forward my windows events, all the events field names start with winlogbeat, but some are _even...
by pfabrizi Path Finder in Getting Data In 06-28-2018
0 2
0
2
jimmynguy
I have some data from Tenable and I am trying to weed out the rows with multiple values into its own row. A good e...
by jimmynguy Explorer in Getting Data In 06-28-2018
0 4
0
4
thisissplunk
I ingested SQL ERRORLOGs and SQLAGENT logs with my forwader but didn't have the props.conf setup correctly. They show...
by thisissplunk Builder in Getting Data In 06-28-2018
0 9
0
9
pfabrizi
I am forwarding windows events from graylog to a UF and then UF to Indexer. I have a props.conf to create field alias...
by pfabrizi Path Finder in Getting Data In 06-28-2018
0 2
0
2
harshal_chakran
Hi, I am using an Universal Forwarder to send a specific file to a Splunk instance on another machine. On this machi...
by harshal_chakran Builder in Getting Data In 06-28-2018
2 4
2
4
erikgrasman
I got a file which get new log entries during the day, when a user logs out, the first line of the log is updated wit...
by erikgrasman Engager in Getting Data In 06-27-2018
0 4
0
4
anewell
I am attempting to collect perfmon counters to track garbage collection in a .NET application. I can create the co...
by anewell Path Finder in Getting Data In 06-27-2018
0 3
0
3
kmattern
I have four files in the same directory, "/opt/SplunkData". I can see three of them in "Manager » Data inputs » Files...
by kmattern Builder in Getting Data In 06-27-2018
1 6
1
6
hunterpj
I need to locate the savedsearches.conf on a Splunk web server i.e. I can only reach this Splunk instance with a URL....
by hunterpj Path Finder in Getting Data In 06-27-2018
0 5
0
5
hunterpj
I am using a search command to find the savedsearches.conf for an alert. I created a search which can list all of the...
by hunterpj Path Finder in Getting Data In 06-27-2018
0 3
0
3
katzr
so I upgraded my Splunk version from 6.3.3 to 7.1.1, put it on a new server, split out the volumes on my server and t...
by katzr Path Finder in Getting Data In 06-27-2018
0 1
0
1
splunk_worker
Hi All I want to move the spath from search query to the auto extraction configuration ie in props.conf and transform...
by splunk_worker Path Finder in Getting Data In 06-27-2018
4 3
4
3
grivera_kudaw
Hi. I have a requirement of a client, he has a file that indexes every day, but that file is modified at different t...
by grivera_kudaw Explorer in Getting Data In 06-27-2018
0 1
0
1
tamduong16
I have a csv file in which it contains random double quotes and I want to remove all these quotes before it actually ...
by tamduong16 Contributor in Getting Data In 06-27-2018
0 6
0
6
dmcgeearke
I am looking for a way to monitor a folder for files that are [not yet defined] into a sourcetype so that i can have ...
by dmcgeearke Explorer in Getting Data In 06-27-2018
0 2
0
2
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors