Getting Data In

Getting Data In
Community Activity
rashid47010
We have different syslog sources. Should I create one syslog server and configure all the syslog sources to send logs...
by rashid47010 Communicator in Getting Data In 05-10-2018
0 2
0
2
perfecto25
Hello, we have a proxy network appliance running Websense, sending its logs via syslog to Splunk, We have a data la...
by perfecto25 Path Finder in Getting Data In 05-10-2018
0 6
0
6
jdunlea_splunk
I am monitoring /etc/hosts.allow and /etc/hosts.deny for change, with a poll period of 300 seconds. [fschange:/etc/h...
by jdunlea_splunk Splunk Employee Splunk Employee in Getting Data In 05-10-2018
2 4
2
4
JordanPeterson
So I am trying to monitor a file on the local indexer. I am setting it up through the Web UI to be sure it works. I g...
by JordanPeterson Path Finder in Getting Data In 05-10-2018
1 3
1
3
hexx
I would like to check that a given file has been fully indexed by Splunk. I tried counting the lines in the source f...
by hexx Splunk Employee Splunk Employee in Getting Data In 05-10-2018
9 4
9
4
riqbal
Initially, I have a cluster environment( 3 indexes + 1 master node) I want to configure my setup like below: window...
by riqbal Communicator in Getting Data In 05-10-2018
0 1
0
1
JRamirezEnosys
Hi everybody, We just started to ingest SCCM v1606 Logs into our Splunk, the main goal is to see the following: -Se...
by JRamirezEnosys Explorer in Getting Data In 05-10-2018
1 2
1
2
Mick
I have a Search Macro in my Splunk application. I would like to invoke this Search Macro via REST API. To do that, ...
by Mick Splunk Employee Splunk Employee in Getting Data In 05-10-2018
5 2
5
2
richnavis
Hi Guys, I'm trying to ingest an entire html file as a single event everytime it gets written. The html file ALWAYS...
by richnavis Contributor in Getting Data In 05-10-2018
0 5
0
5
Sagar0511
Hi Folks, I am testing log forwarding using universal forwarder from Windows to Splunk but can't seem to receive any...
by Sagar0511 Explorer in Getting Data In 05-09-2018
0 4
0
4
ericlavalley
I've installed UF on a Windows 2012 R2 server and created a directory monitor via the inputs.conf file at C:\Program ...
by ericlavalley Explorer in Getting Data In 05-09-2018
0 10
0
10
jcadena
I'm having a hard time coming up with the right query or search. My dilemma is I have 2 separate lists containing nam...
by jcadena New Member in Getting Data In 05-09-2018
0 2
0
2
krisreeves
I've recently added some configuration that creates indexes for data. Each index has a corresponding role that adds b...
by krisreeves Path Finder in Getting Data In 05-09-2018
0 3
0
3
thisissplunk
I've seen older answers that state you cannot ingest only certain files from a zip file. Say, only .csv files from a ...
by thisissplunk Builder in Getting Data In 05-09-2018
0 0
0
0
skoelpin
I need to lengthen the lines in my events so I went into Splunk\etc\system\local\props.conf and added [SRV-DCP01UVW...
by SplunkTrust SplunkTrust in Getting Data In 05-09-2018
0 10
0
10
AaronMoorcroft
Hey Guys, So I'm setting up a lab for some testing, what I would like to do is index only set Windows Security Event...
by AaronMoorcroft Communicator in Getting Data In 05-09-2018
0 10
0
10
nicolociraci
I've a CSV file like the one reported below, and on my UF I've added the following props but on the search heads the ...
by nicolociraci New Member in Getting Data In 05-09-2018
0 9
0
9
robertlynch2020
Hi I have been looking at this doc on Capacity Planning Manual http://docs.splunk.com/Documentation/Splunk/7.1.0/Cap...
by robertlynch2020 Influencer in Getting Data In 05-09-2018
1 4
1
4
leongchongyu
I am running Splunk on an RHEL7 VM. I wish to be able to receive data from a Lexmark printer, which I have configured...
by leongchongyu Explorer in Getting Data In 05-09-2018
0 8
0
8
wbw4am
We are looking to utilize the splunktcptoken as additional security measure to validate that we trust the sender of d...
by wbw4am New Member in Getting Data In 05-08-2018
0 0
0
0
westpointis
Hello. We are currently running Splunk 7.0.2 on Windows Server 2012 r2 and are attempting to send syslog data from ou...
by westpointis New Member in Getting Data In 05-08-2018
0 3
0
3
sylim_splunk
We have rsyslog writing files to numerous directories on Splunk heavy forwarders. In order to keep the logfiles from...
by sylim_splunk Splunk Employee Splunk Employee in Getting Data In 05-07-2018
0 1
0
1
sylim_splunk
This screenshot speaks the issue. Due to no Http Event collector I'm not able to create one.
by sylim_splunk Splunk Employee Splunk Employee in Getting Data In 05-07-2018
0 1
0
1
eymanu
Audit event generator: Now skipping indexing of internal audit events, because the downstream queue is not accepting ...
by eymanu Explorer in Getting Data In 05-07-2018
2 1
2
1
daniel333
All, How long by default does it take for the old FSCHANGE type to notice a change? thanks -Daniel
by daniel333 Builder in Getting Data In 05-07-2018
0 0
0
0
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...
Top Solution Authors