Getting Data In

Getting Data In
Community Activity
marcokrueger
Currently, we want to delete some events (that is, all events with a certain sourcetype in a defined range in 2016) f...
by marcokrueger Path Finder in Getting Data In 11-22-2017
0 18
0
18
behudelson
Hello, This seems like it should be straightforward but I am struggling to find a solution. I would like to filter t...
by behudelson Path Finder in Getting Data In 11-22-2017
0 4
0
4
andreac81
Hi to all, I installed on monitored server, by universal forwarding, an app that uses python script to load data abou...
by andreac81 Explorer in Getting Data In 11-22-2017
1 3
1
3
mkarimi17
I have a JSON that is for emails like the following: { [-] computer: { [+] } date: 2018-03...
by mkarimi17 Path Finder in Getting Data In 11-22-2017
0 6
0
6
Robbie1194
Hi Guys, My question is, is it possible to only forward specific data to my Splunk environment? So my situation i...
by Robbie1194 Communicator in Getting Data In 11-22-2017
0 2
0
2
ribicU
Could somebody help me with this problem, i have simple powershell script: Write-Host "Num Args:" $args.Length; fore...
by ribicU Engager in Getting Data In 11-22-2017
0 1
0
1
ebruozys
I want to calculate how long it takes until a event from one sourcetype switches to another sourcetype. For example e...
by ebruozys Path Finder in Getting Data In 11-22-2017
0 5
0
5
althomas
Hi, We have a requirement to pull data out of a report that they want updated at (near-enough) real time, so we've c...
by althomas Communicator in Getting Data In 11-22-2017
1 2
1
2
Shridhar7Hitesh
Let' s say 2 servers behaving as Indexers which have Splunk Enterprise already deployed on them. There is one Forwa...
by Shridhar7Hitesh Explorer in Getting Data In 11-22-2017
0 6
0
6
patrickfeerick
I am a new user to Splunk and had the assumption that when using a json file as a continuously monitored datasource S...
by patrickfeerick New Member in Getting Data In 11-21-2017
0 2
0
2
afamoyib
I have a script generating an output, however all my output is being registered as one event. I am trying to break ea...
by afamoyib Path Finder in Getting Data In 11-21-2017
0 3
0
3
afamoyib
I am trying to extract a field but it is not working properly. I am able to extract single words but when spaces gets...
by afamoyib Path Finder in Getting Data In 11-21-2017
0 4
0
4
ddrillic
How can I get a license usage for one index broken down by sourcetype? I know this question came up recently in diffe...
by ddrillic Ultra Champion in Getting Data In 11-21-2017
0 4
0
4
Hemnaath
Hi All, I have a requirement from data base team to monitor bunch of Microsoft SQL server in our organization. I had ...
by Hemnaath Motivator in Getting Data In 11-21-2017
0 4
0
4
Hemnaath
Hi All, We have more than 100 + servers that needs to be monitored via splunk to capture SQL Error logs from these se...
by Hemnaath Motivator in Getting Data In 11-21-2017
0 5
0
5
ericmoss
How do I monitor only the changes (add, delete, change value) to Windows Registry? I am only interested in seeing ch...
by ericmoss Explorer in Getting Data In 11-21-2017
0 2
0
2
tnewrelic
Hi, We are looking to integrate Splunk 6.x with Netcool OMNIbus. Please help us how can we proceed. Thanks!!
by tnewrelic New Member in Getting Data In 11-21-2017
0 5
0
5
pramit46
I have a query as follows: index="idx" sourcetype="st" host="host" |search Port=1/0/23 It shows "No Results Found" ...
by pramit46 Contributor in Getting Data In 11-20-2017
0 8
0
8
jbreu
I am trying to configure the Exchange Reputation piece in Splunk and am a little confused by the instructions. In th...
by jbreu Explorer in Getting Data In 11-20-2017
1 5
1
5
mjan635
I am using Splunk 6.5.3 ES and I don't have curl command. Does curl not ship with Splunk? If not, how I can use it? P...
by mjan635 New Member in Getting Data In 11-20-2017
0 1
0
1
benbabich
I want to blacklist 4698, 4699, 4700, 4701,4702 if they contain 'Microsoft\Windows' in the Task Name. Would either o...
by benbabich Explorer in Getting Data In 11-20-2017
0 2
0
2
carlyleadmin
Hey Guys, i am forwarding iis logs from our web servers.And from what i read so far that people are saying that they...
by carlyleadmin Contributor in Getting Data In 11-20-2017
0 1
0
1
simpkins1958
Based on this answer link text Looks like there is not enough disk space for the window swap file. Splunk is instal...
by simpkins1958 Contributor in Getting Data In 11-20-2017
0 1
0
1
robsenk
We have the need to set a high level sourcetype in the inputs.conf to one sourcetype and override some of those sourc...
by robsenk Engager in Getting Data In 11-20-2017
0 3
0
3
a101755
I want to index 'earthquake' data. Source is "https://earthquake.usgs.gov/fdsnws/event/1/query?format=xml&starttime=2...
by a101755 Explorer in Getting Data In 11-20-2017
0 10
0
10
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...