Getting Data In

Getting Data In
Community Activity
maheshnc
I need to integrate Dell Switches with Splunk using syslog-ng which is installed on, On-Prem HF, what are the prerequ...
by maheshnc Path Finder in Getting Data In 09-26-2025
0 1
0
1
Nraj87
I would like to run a copy of  PROD Indexer servers’ VMs in another site (DR setup) without mapping Cold Storage, to ...
by Nraj87 Explorer in Getting Data In 09-24-2025
0 4
0
4
sswigart
I am running windows version of Splunk Enterprise 9.4.2 stand alone. I have 17 older security logs saved in a  separa...
by sswigart Explorer in Getting Data In 09-24-2025
0 1
0
1
_joe
This is a comment rather than a question.  Please add the ability to ingest audit logs in to the Dynatrace add-on. 
by _joe Contributor in Getting Data In 09-22-2025
0 1
0
1
marycordova
I've installed the Splunk Add-On Builder but the UI is blank/won't load...I've tried installing on my HF (Heavy Forwa...
by SplunkTrust SplunkTrust in Getting Data In 09-22-2025
0 10
0
10
prioska
Hello everyone, I have a splunk server installed locally and there are logs being ingested already. I'd like to forwa...
by prioska Loves-to-Learn in Getting Data In 09-21-2025
0 1
0
1
hrawat
Here are the configs for on-prem customers willing to apply and avoid adding more hardware cost.9.4.0 and above most ...
by hrawat Splunk Employee Splunk Employee in Getting Data In 09-20-2025
0 6
0
6
sigma
I'm working on a transforms.conf to extract fields from a custom log format. Here's my regex:REGEX = ^\w+\s+\d+\s+\d+...
by sigma Path Finder in Getting Data In 09-20-2025
0 3
0
3
rickymckenzie10
index=_internal [`set_local_host`] source=*license_usage.log* type="Usage" | eval h=if(len(h)=0 OR isnull(h),"(SQUAS...
by rickymckenzie10 Explorer in Getting Data In 09-19-2025
0 1
0
1
zksvc
Hi All, i do create new index but the source data is from savedsearch let say i create savedsearch from index=ABC the...
by zksvc Contributor in Getting Data In 09-19-2025
0 6
0
6
Cerum
Has anyone had any luck getting Open AI Compliance API logs into Splunk Cloud? This API ships logs that provide visib...
by Cerum Loves-to-Learn in Getting Data In 09-17-2025
0 2
0
2
lucacaldiero
How can I clone data from a HF to two different splunk instances? Doubling defaultgroup in outputs.conf does not work...
by lucacaldiero Path Finder in Getting Data In 09-16-2025
0 4
0
4
vincentwhn
Can anyone give me some examples of using STOP_PROCESSING_IF in transforms.conf? Seems there is no examples exists wi...
by vincentwhn Engager in Getting Data In 09-16-2025
0 6
0
6
Fares_Hossam
How can I configure my F5 BIG-IP to forward logs from a load-balanced server pool to Splunk?
by Fares_Hossam Engager in Getting Data In 09-16-2025
0 1
0
1
utoddl
I have a not-very-complicated query that returns a table of my roles and associated default search indexes. One role ...
by utoddl Explorer in Getting Data In 09-15-2025
0 1
0
1
davidoff96
Hello,We're currently having an issue of SC4S tagging Cisco firepower data as nix:syslog, but I was having this issue...
by davidoff96 Path Finder in Getting Data In 09-15-2025
0 2
0
2
lucacaldiero
Hello,I wanna forward all data from a single HF to two splunk different instances. How can i do that? Thanks #splunk ...
by lucacaldiero Path Finder in Getting Data In 09-15-2025
0 10
0
10
lucacaldiero
How can I specify all host or sources in a stanza of props.conf?Thank you @gcusello 
by lucacaldiero Path Finder in Getting Data In 09-15-2025
0 3
0
3
vincentwhn
Due to privacy concerns, I would like to modify the _raw content during the data onboarding phase in order to impleme...
by vincentwhn Engager in Getting Data In 09-15-2025
0 7
0
7
Ghostoverflow25
I have a source of logs that I want to ingest into splunk, where each line documents a seperate event. After having s...
by Ghostoverflow25 Engager in Getting Data In 09-14-2025
0 1
0
1
jackbenimble
What would it take to use something like REST API to pull down documents from Splunk Documentation website? The searc...
by jackbenimble New Member in Getting Data In 09-12-2025
0 1
0
1
hrawat
Apply following workaround in default-mode.confAdditionally you can also push this change via DS push across thousand...
by hrawat Splunk Employee Splunk Employee in Getting Data In 09-12-2025
4 17
4
17
JyPl4wNYu7GV1uL
CentOS 7.7.1908, Splunk  v9.1.0.2I want to get an example event for each sourcetype on each host (excluding one host)...
by JyPl4wNYu7GV1uL Explorer in Getting Data In 09-12-2025
0 4
0
4
kumva01
Hi All,I’m looking for an SPL query that can return the list of Tag Names along with their associated field-value pai...
by kumva01 Loves-to-Learn Lots in Getting Data In 09-12-2025
0 2
0
2
taskmaster
I'm new to Splunk... I'm currently running Splunk on an Ubuntu system.  I've noticed that the /proc directory is show...
by taskmaster Engager in Getting Data In 09-12-2025
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...