Getting Data In

Getting Data In
Community Activity
2powder
I have been tasked with figuring out how to monitor server activity using splunk and create alerts
by 2powder New Member in Getting Data In 10-03-2017
0 5
0
5
heats
Scenario: We're doing an active directory upgrade which will effect applications that currently point to specific dom...
by heats Explorer in Getting Data In 10-03-2017
0 1
0
1
benziebgpcl
Hi, I'd like to be able to monitor the amount of data indexed daily (ie, "so far today") so I can surface this up to...
by benziebgpcl New Member in Getting Data In 10-02-2017
0 5
0
5
harry521
we use csv to track app's performance. I added the csv to forwarder and keep monitoring it. The problem is that while...
by harry521 New Member in Getting Data In 10-02-2017
0 3
0
3
rajnish1202
Hi, I need helkp regarding extraction of key value pair from a json input being forwarded to out indexer. I have alre...
by rajnish1202 Explorer in Getting Data In 10-02-2017
0 10
0
10
varad_joshi
Not that familiar with *NIX hence the question. I created the user and group called splunk and then ran Splunk for ...
by varad_joshi Communicator in Getting Data In 10-01-2017
0 2
0
2
johnmccash
I'm interested in storing csv output from the sysinternals autoruns tool in Splunk. But I will be pulling in from a r...
by johnmccash Explorer in Getting Data In 09-29-2017
0 6
0
6
thisissplunk
Whenever I enable this EXTRACTION stanza on my universal forwarder, my TRANSFORM extraction stops working on my index...
by thisissplunk Builder in Getting Data In 09-29-2017
0 2
0
2
ByteFlinger
I have an indexer cluster with a minimum replication factor of 2 to prevent data loss. I would like to setup Splunk t...
by ByteFlinger Engager in Getting Data In 09-29-2017
0 2
0
2
kcollori
Hello there, I have two sets of data under two different indexes. The fields for each index are respectively [custom...
by kcollori Explorer in Getting Data In 09-29-2017
0 4
0
4
stwong
Hi all, I'd like to join 2 Windows events using instance_ID as following: sourcetype="WinEventLog:security" EventC...
by stwong Communicator in Getting Data In 09-29-2017
0 5
0
5
NickLaurent
Hello fellow Splunkers, I need some help with HEC (HTTP Event Collector). The problem is that no events are appearing...
by NickLaurent New Member in Getting Data In 09-29-2017
0 1
0
1
MousumiChowdhur
Hi! I have AIX servers on which Splunk universal forwarders are installed where splunkd process suddenly consumed hi...
by MousumiChowdhur Contributor in Getting Data In 09-29-2017
4 3
4
3
tlam_splunk
Setup the web.conf using dhFile at 2048 encryption web.conf dhFile = $SPLUNK_HOME\etc\auth\splunkweb\DH2048.pem ...
by tlam_splunk Splunk Employee Splunk Employee in Getting Data In 09-29-2017
1 3
1
3
yutaka1005
I am thinking about building an environment in a country where daylight saving time exists, but as for the server, I ...
by yutaka1005 Builder in Getting Data In 09-29-2017
0 1
0
1
dougsummersett
Hi, I'm brand new to Splunk and been given an existing Splunk environment to manage. I need to get a universal forwar...
by dougsummersett New Member in Getting Data In 09-28-2017
0 1
0
1
DrFedtke
Hi all, I tried to find a way to extract fields automatically after adding new data. The input is of the type: Log...
by DrFedtke Explorer in Getting Data In 09-28-2017
0 3
0
3
daniel333
All, A bit concern for us lately is Splunk downtime. Search head clustering has been helpful, so now we're looking ...
by daniel333 Builder in Getting Data In 09-28-2017
0 4
0
4
freedg
I am upgrading to Splunk 7.0. The installer hangs and does not complete. Running Win10 1703 on vmware 12 looking fo...
by freedg Engager in Getting Data In 09-28-2017
1 5
1
5
vaibhavagg2006
Hi Experts I have following monitor stanza . I want to blacklist "data/xyz/logs/router.jar.log" but want to monitor "...
by vaibhavagg2006 Communicator in Getting Data In 09-28-2017
0 6
0
6
cdstealer
Hi, I'm ingesting data in pure json and all fields are being extracted. However, all fields are strings regardle...
by cdstealer Contributor in Getting Data In 09-27-2017
0 3
0
3
chintan_shah
I have created an alert which checks if logs are not present in last 20 mins per source. I have around 32 source file...
by chintan_shah Path Finder in Getting Data In 09-27-2017
0 2
0
2
ahmedhassanean
How to increase the retention time of Splunk monitoring console Reports in distributed environment?
by ahmedhassanean Explorer in Getting Data In 09-27-2017
0 4
0
4
hrithiktej
In our Slave-Apps directory on the 2 peers/indexers we have a custom app created by the prev admin which has setting ...
by hrithiktej Communicator in Getting Data In 09-27-2017
1 24
1
24
RexStout
I've asked about this before and now I've re-loaded the raw data without any modifications. It looks like this (wit...
by RexStout Explorer in Getting Data In 09-27-2017
0 5
0
5
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors