Getting Data In

Getting Data In
Community Activity
raventura
Hi, we are having trouble installing Universal Forwarder (32-bit) to a server that has system specifications of: OS: ...
by raventura Observer in Getting Data In 06-19-2017
0 2
0
2
SplunkCSIT
Hi, If i need to filtering some data in the log before forward to indexing, how to go abt doing it? thks
by SplunkCSIT Communicator in Getting Data In 06-19-2017
1 11
1
11
ltrand
So, I'm slightly confused. I'm looking at the Splunk documentation and they reference only sending 50 GB/day to an i...
by ltrand Contributor in Getting Data In 06-19-2017
0 10
0
10
andreac81
Hi to all, I configured a forwarder as following In Splunk Server: - in /opt/splunk/etc/deployment-apps I copyed th...
by andreac81 Explorer in Getting Data In 06-18-2017
0 5
0
5
ofaura
Hello, I am trying to index following files: c:\test\access.log c:\test\access_00.0.log c:\test\access_00.0.t...
by ofaura Path Finder in Getting Data In 06-18-2017
0 3
0
3
madisonAvalos
All my other indexes are indexing data. I created a new one, and i need to have 1164 data and its only appear 994, i ...
by madisonAvalos Engager in Getting Data In 06-17-2017
0 1
0
1
vanderaj2
Hi Splunkers! I’d like to pick your brain to see if you know of 3-5 key windows event log events to monitor that wou...
by vanderaj2 Path Finder in Getting Data In 06-17-2017
2 1
2
1
riotto
I have a korn shell that creates a log. I want to run the script via the inputs.conf, every Monday at 5am. I don't w...
by riotto Path Finder in Getting Data In 06-16-2017
0 6
0
6
sunnybrarjpmc
Is it possible to have multiple tcp output groups in outputs.conf and have the events autoLB'd between them? My unde...
by sunnybrarjpmc New Member in Getting Data In 06-16-2017
0 3
0
3
yuanliu
For example, if I put this in inputs.conf [script:/bin/ls /*/lib /var/lib /usr/lib ] sourcetype = ls The latter tw...
by SplunkTrust SplunkTrust in Getting Data In 06-16-2017
0 7
0
7
msichani
Hi, I've reviewed almost all the question about event line breaking but still have some inconsistency with data inges...
by msichani Explorer in Getting Data In 06-16-2017
1 4
1
4
pimco_rgoyal
The substr function is not working for json logs for us in 6.5.2 for Dev version. Whereas the Prod version of the Spl...
by pimco_rgoyal Observer in Getting Data In 06-16-2017
0 10
0
10
vanderaj2
I was wondering if possible for a single splunk universal forwarder to be managed by two different deployment servers...
by vanderaj2 Path Finder in Getting Data In 06-16-2017
0 3
0
3
lukasz92
Hi, I need to use Splunk rest command in search - but I wish to generate a POST request instead of GET. Is it possib...
by lukasz92 Communicator in Getting Data In 06-16-2017
0 3
0
3
isha_rastogi
I am working in the FIX log messages and have two fields that contain timestamps. I need to check for one field and i...
by isha_rastogi Path Finder in Getting Data In 06-16-2017
0 8
0
8
rangineniarunku
I have deployed SplunK_TA_Windows and setup monitoring for Applicatiom, System ,Security, HardwareEvents and Setup wi...
by rangineniarunku Explorer in Getting Data In 06-16-2017
0 1
0
1
karthi2809
index=bp_prod NOT ([|inputlookup serverBP.csv|fields Servers Status |where Status=="N"] ) |eventstats count as "total...
by karthi2809 Builder in Getting Data In 06-16-2017
0 1
0
1
thamohit
I have a requirement where I will be getting logs from various sources in Splunk, extract some useful information fro...
by thamohit New Member in Getting Data In 06-15-2017
0 4
0
4
sillingworth
I have 2 VMs, one running an indexer: hostname "splunkbox" ip 192.168.56.151 and one running a universal forwarder...
by sillingworth Path Finder in Getting Data In 06-15-2017
0 5
0
5
jw44250
I have 10 indexes...i want to find the actual size of the index before splunk adding its indexing. and after as well...
by jw44250 New Member in Getting Data In 06-15-2017
0 4
0
4
shinde0509
2017-04-02 22:45:19.023 -0600 so-splunky.local sshd[68061]: Accepted keyboard-interactive/pam for sowings from xx.xx....
by shinde0509 Explorer in Getting Data In 06-15-2017
0 3
0
3
amantjes
Hi all, In our case timestamps within the splunk events are standard GMT where people working from different timezo...
by amantjes New Member in Getting Data In 06-15-2017
0 2
0
2
fernandoandre
At Indexer level how to force props.conf linebreaking setup to be applied to a specific sourcetype of data arriving f...
by fernandoandre Communicator in Getting Data In 06-15-2017
0 5
0
5
dbatts
On all the Universal Forwarders, any user has the ability to access REST API called Splunk ATOM Feed:Splunkd. They c...
by dbatts Explorer in Getting Data In 06-15-2017
1 3
1
3
MarcHelou
let's say i have a file that I would like to input it to splunk. but I want to have a better parser, a smarter one. h...
by MarcHelou New Member in Getting Data In 06-15-2017
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...