Getting Data In

Getting Data In
Community Activity
gregory_cordier
Hi, We have an auditing setup which logs in Windows event logs (Forwarded Events) as "MSSQLSERVER$AUDIT" source. th...
by gregory_cordier Explorer in Getting Data In 04-03-2018
0 2
0
2
jared_anderson
We want to monitor Active Directory changes and security Events We are planning to deploy the Universal forwarder to ...
by jared_anderson Path Finder in Getting Data In 04-03-2018
0 4
0
4
MedralaG
I would like to configure rsyslog so that it keeps logs generated by the localhost in the /var/log/messages but then ...
by MedralaG Communicator in Getting Data In 04-03-2018
0 7
0
7
anandhalagarasa
Hi All, We have set the data retention has 1 year (365 days) for in cluster master. But when we search the data in S...
by anandhalagarasa Path Finder in Getting Data In 04-03-2018
1 5
1
5
sebardgz
Hello everyone, I have a lab in a Ubuntu VM. In this lab, I have the UF and the Splunk E. The forwarder monitors a f...
by sebardgz New Member in Getting Data In 04-03-2018
0 6
0
6
clorne
Hello, I have a log with a timestamp that does not contain the year. Moreover the events are not in a chronological o...
by clorne Communicator in Getting Data In 04-03-2018
0 2
0
2
Kinngk789
So we are wondering if by implementing the collection of Sysmon logs, we can stop collecting other logs all together....
by Kinngk789 New Member in Getting Data In 04-02-2018
0 1
0
1
ddrillic
The admin class (lab) says that for json we need the following in the props.conf of the forwarder. INDEXED_EXTRACTIO...
by ddrillic Ultra Champion in Getting Data In 04-02-2018
0 2
0
2
josue198_s
alt text I have installed universal forwarder on my windows host and the forwarder does forward the events to the Spl...
by josue198_s New Member in Getting Data In 04-02-2018
0 2
0
2
tabbtharrington
I am new to Splunk and I have it installed on my PC at work. I have Aruba Clear Pass syslog target set to forward to ...
by tabbtharrington New Member in Getting Data In 04-02-2018
0 2
0
2
xinde
Search a same log file on many different hosts . Use transaction : startwith and endwith to capture one process w...
by xinde Path Finder in Getting Data In 04-02-2018
0 2
0
2
pachurrito62
Is there a way to change the URL form en-GB to en-US so the dateTime picker shows MM/DD/YY? http://1xx.1xx.1xx.1xx:9...
by pachurrito62 Explorer in Getting Data In 04-02-2018
1 2
1
2
pfabrizi
I need to set a value based on another value. How would I do this: if severity = 1 severity=high One of my cust...
by pfabrizi Path Finder in Getting Data In 04-02-2018
0 2
0
2
ddrillic
Is there a way to simply the props.conf configurations and do the following in one command - FIELDALIAS-alias01 = "a...
by ddrillic Ultra Champion in Getting Data In 04-02-2018
0 3
0
3
Klimdy
I have universal forwarder with Splunk_TA_Stream and my app _server_app_audit where in inputs.conf I write _TCP_Routi...
by Klimdy Explorer in Getting Data In 04-02-2018
0 2
0
2
roysoman
Hi.. I have a question From a heavy forwarder , based on the incoming host, I like to send the logs into a separate...
by roysoman Engager in Getting Data In 04-02-2018
0 3
0
3
ddrillic
The following sourcetype works fine when we upload a file against this sourcetype, but via the forwarder the csv fiel...
by ddrillic Ultra Champion in Getting Data In 04-01-2018
0 12
0
12
ranjitbrhm1
the reason for this is because someone made a mix-up on the UF and then some hosts are indexing to the wrong index. I...
by ranjitbrhm1 Communicator in Getting Data In 04-01-2018
0 2
0
2
siva_cg
Hi All, I am trying to create a summary index which will gives us the license usage by index and sourcetype, which w...
by siva_cg Path Finder in Getting Data In 03-31-2018
0 4
0
4
ddrillic
We have the following in props.conf - FIELDALIAS-alias1 = apiRequest.apiInfo.clientID AS clientID It doesn't seem ...
by ddrillic Ultra Champion in Getting Data In 03-31-2018
0 3
0
3
albert111
I am trying to write a query in Splunk that will tell me if any user IDs in my CSV file were used to log into any mac...
by albert111 New Member in Getting Data In 03-31-2018
0 3
0
3
Log_wrangler
Not sure if it is possible, but before I try, thought I would ask. I need to ingest json files uploaded to a google ...
by Log_wrangler Builder in Getting Data In 03-30-2018
1 1
1
1
PaulTszeYuenChu
When I tried to download the Universal Forwarder Credentials from my trial Splunk Cloud on to my MacBook Pro, I got a...
by PaulTszeYuenChu Explorer in Getting Data In 03-30-2018
0 1
0
1
lakromani
I have a big corporate network with many routers. All routes ha a loopback IP used for syslog. Ex 10.252.1.10/32 Wh...
by lakromani Builder in Getting Data In 03-30-2018
0 2
0
2
tinylund
We are trying to setup the universal forwarder on a Windows AD server. After configuring the index to receive on port...
by tinylund Explorer in Getting Data In 03-30-2018
0 4
0
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors