| Hi Splunkers, I collect syslog(/var/log/messages) data by Universal Forwarder, not UDP like this. Sep 3 12:42:1... by sunrise Contributor in Getting Data In 12-20-2017 1 5 | 1 | 5 | ||
| I am hoping someone can help me out with a filtering blacklist issue I am having. I am currently filtering out event ... by zward Path Finder in Getting Data In 12-20-2017 0 4 | 0 | 4 | ||
| Is there a config available that would push out the same format as Snare from a Heavy Forwarder? i.e. UniversalForwar... by CletisNPT Explorer in Getting Data In 12-20-2017 0 4 | 0 | 4 | ||
| Could you suggest the compatible UF package for the Operating system Knoppix and Fedora? I have checked on this link... by arunkumarvinoba New Member in Getting Data In 12-20-2017 0 2 | 0 | 2 | ||
| I'm trying to index a 3.5 GB csv file, but splunk is not reading it. Any clues ? by premforsplunk Explorer in Getting Data In 12-20-2017 0 3 | 0 | 3 | ||
| Hi there, i tried to upload a csv-file. During Uploading I could separate the fields with a "comma" and the field n... by wes7bb New Member in Getting Data In 12-20-2017 0 3 | 0 | 3 | ||
| Ladies and Gents, I'm struggling trying to transform some of my data. props.conf [st1] NO_BINARY_CHECK = true SHOU... by kendrickt Path Finder in Getting Data In 12-19-2017 1 2 | 1 | 2 | ||
| I am playing with a custom format for data going into Splunk on Splunk 7.0, and I am trying to extract fields at inde... by rjthibod Champion in Getting Data In 12-19-2017 0 3 | 0 | 3 | ||
| May I know the answers for the below questions. what happens if DEST_KEY = MetaData:Host? Does the Host metadata r... by ankithreddy777 Contributor in Getting Data In 12-19-2017 1 2 | 1 | 2 | ||
| How can I have multiple host stanzas in transforms.conf all be applied? I'd like to pull content out of some entries ... by timbCFCA Path Finder in Getting Data In 12-19-2017 0 6 | 0 | 6 | ||
| The bundle in the search head has grown upto 776 MB. Its not getting pushed as a result. How to reduce the bundle si... by nawazns5038 Builder in Getting Data In 12-19-2017 0 7 | 0 | 7 | ||
| Hi all, I have configured the line breaking parameter as (SHOULD_LINEMERGE = true) to read a log file that contains ... by danillopavan Communicator in Getting Data In 12-19-2017 0 6 | 0 | 6 | ||
| Hi all, I am trying to have a combination of SHOULD_LINEMERGE=true with filtering just to index some lines of the lo... by danillopavan Communicator in Getting Data In 12-19-2017 0 5 | 0 | 5 | ||
| I am trying to pull incoming tcp data into the Metrics Store using this information: http://docs.splunk.com/Document... by walkerhound Path Finder in Getting Data In 12-19-2017 0 4 | 0 | 4 | ||
| Task: Mask PII data at Index Time Current Setup: Universal forwards to forward logs to Splunk Based on documentatio... by catchaj88 Explorer in Getting Data In 12-19-2017 0 4 | 0 | 4 | ||
| Hi Team, We have an log file in one of the server and which is keep generated in the directory for every 10 mins on... by senthamilselvan Engager in Getting Data In 12-19-2017 0 5 | 0 | 5 | ||
| I wanna to run WinNetMon on UF and I put to SplunkUniverstalForwarder\etc\system\local\inputs.conf by test_qweqwe Builder in Getting Data In 12-19-2017 0 1 | 0 | 1 | ||
| hello, I made my Anonymize data based on this http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Anonymizedata a... by ahmadjabr Engager in Getting Data In 12-19-2017 0 9 | 0 | 9 | ||
| My current splunk install handles logs for about 80 different development groups. Each one with their own idea of wha... by twinspop Influencer in Getting Data In 12-18-2017 0 3 | 0 | 3 | ||
| Running Splunk Enterprise 6.5.6. I am parsing incoming events of sourcetype weblogic_stdout, and am having some trou... by rkilen Explorer in Getting Data In 12-18-2017 0 5 | 0 | 5 | ||
| I'm using a set of universal forwarders to send data to a central indexer. I would like to send events from "WinEven... by fernandoandre Communicator in Getting Data In 12-18-2017 0 14 | 0 | 14 | ||
| Hi, I need to read the below json file in python script and send each json to splunk. [[[ with open('sampledata... by sawgata12345 Path Finder in Getting Data In 12-18-2017 0 10 | 0 | 10 | ||
| I created a new F: drive for my archiving or Frozen path. Currently everything is configured to the default and filli... by dbatts Explorer in Getting Data In 12-18-2017 0 2 | 0 | 2 | ||
| I have an inputlookup table with list of email addresses . I already have a pre existing field called user . How do I... by Mohsin123 Path Finder in Getting Data In 12-18-2017 0 5 | 0 | 5 | ||
| Hi, We are monitoring a csv file which has date included in the filename, with the filename format: abc_xxx_yz-2017-... by nikita_p Contributor in Getting Data In 12-17-2017 0 5 | 0 | 5 |