Getting Data In

Getting Data In
Community Activity
srividyareddy
Able to see the system logs but cannot see the remote logs (in the same server) where the log files are installed. M...
by srividyareddy New Member in Getting Data In 09-20-2017
0 6
0
6
smcdonald20
Hi, I have imported an XML file to Splunk, but want to change the field names to something more user friendly. I kn...
by smcdonald20 Path Finder in Getting Data In 09-20-2017
0 1
0
1
Tim_1
Hi all, I want to know if it is possible to route data to different indexes based on the value of a regex dynamical...
by Tim_1 Path Finder in Getting Data In 09-20-2017
0 5
0
5
craigwilkinson
Hi All, Is it possible to monitor the queue size without access to the search head or related applications ? I curr...
by craigwilkinson Path Finder in Getting Data In 09-19-2017
1 1
1
1
dileepmandapam
Here is my use-case: For every hour, I need to download a .csv file from my server using REST API. Using Splunk, I...
by dileepmandapam New Member in Getting Data In 09-19-2017
0 3
0
3
scottj1y
We have events coming from hosts that need to have additional information added to them from two configuration files....
by scottj1y Path Finder in Getting Data In 09-19-2017
0 2
0
2
sandeep23
Is compression (like Gzip) supported in HEC batched payload ? One of the Splunk blog mentioned it, but can't find any...
by sandeep23 Engager in Getting Data In 09-19-2017
1 2
1
2
balagurivid1
We have installed and configured Splunk Universal forwarder 6.6.1 on AIX server. It is working fine and I am able to ...
by balagurivid1 New Member in Getting Data In 09-19-2017
0 3
0
3
brent_weaver
I have an event like: {"app":"EventHub Service","caller":"kafka.go:110","fn":"gi.build.com/predix-data-services/even...
by brent_weaver Builder in Getting Data In 09-19-2017
1 7
1
7
mala_splunk_91
Hi guys, Please provide your input on the below scenario. I have some events like below. Here , I want to extract so...
by mala_splunk_91 Explorer in Getting Data In 09-19-2017
1 4
1
4
kearaspoor
Have a bunch of CSV files that were generated (and will continue to be generated) based on a human readable form that...
by SplunkTrust SplunkTrust in Getting Data In 09-18-2017
0 2
0
2
wkupersa
I have an app with an inputs.conf that has a stanza for [WinEventLog://Microsoft-Security-Logs] to an index and uses...
by wkupersa Path Finder in Getting Data In 09-18-2017
0 1
0
1
R_B
Hey everyone, I currently have several devices forwarding syslog data to a syslog server. All of the devices data ge...
by R_B Path Finder in Getting Data In 09-18-2017
0 4
0
4
sbattista09
i am bit lost on selective indexing. I wanted to configure on of my prod indexers to send logs to a dev indexer and a...
by sbattista09 Contributor in Getting Data In 09-18-2017
0 1
0
1
moesaidi
I have a query that runs once a day to tell me if certain source types have no data coming in after X time. The quer...
by moesaidi Path Finder in Getting Data In 09-18-2017
0 6
0
6
echalex
Due to certain reasons, we have a number of destination indexes that need to be rewritten before indexing. Basically ...
by echalex Builder in Getting Data In 09-18-2017
0 3
0
3
frizzoS3
I am trying to send logs from Cisco Meraki FW to our Splunk instance. No universal forwarder is on the FW. Can I stil...
by frizzoS3 New Member in Getting Data In 09-18-2017
0 6
0
6
cliffton_merz
Hello all, I'm having an issue with my environment while trying to index a set of logs i get from a file nightly and...
by cliffton_merz Explorer in Getting Data In 09-18-2017
0 4
0
4
deodion
Is there any guideline or best practice what .conf to put in gui/indexer/forwarder level? I mean each .conf has its ...
by deodion Path Finder in Getting Data In 09-18-2017
0 1
0
1
sf-mike
All, Here is the file name and my datetime.xml config. When I apply this and try to import the data, Splunk gets stu...
by sf-mike Splunk Employee Splunk Employee in Getting Data In 09-17-2017
1 5
1
5
stevennoble
If I'm using an index time props.conf setting (in this case SEDCMD) do I edit props.conf on the master or do I have t...
by stevennoble Explorer in Getting Data In 09-17-2017
1 4
1
4
arpit_1210
We have a indexer cluster{10 indexers] in our environment, and 2 search heads. If we create indexes on a search head...
by arpit_1210 Explorer in Getting Data In 09-17-2017
0 2
0
2
younes17
I am trying to import JSON file on Splunk Enterprise, my sourcetype is below: CHARSET=UTF-8 INDEXED_EXTRACTIONS=jso...
by younes17 Explorer in Getting Data In 09-16-2017
1 3
1
3
vikram_m
in system/local directory below is the configuration. [monitor:\{Log Location}] sourcetype=test index=chilqa disable...
by vikram_m Path Finder in Getting Data In 09-15-2017
0 9
0
9
mvjaarsveldt
Hi - I've seen various discussions on this topic, namely 8089 used by vCenter as well as SPLUNK's deployment server b...
by mvjaarsveldt Engager in Getting Data In 09-15-2017
0 1
0
1
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors