Getting Data In

Getting Data In
Community Activity
kkomar
I have splunk in domain mode set to look through 2 inputs over UNC path that are IIS logs. I have the inputs the same...
by kkomar New Member in Getting Data In 06-12-2017
0 2
0
2
bport15
We currently have our perf and N1 environments combined and I need to route certain logs to certain indexes based on ...
by bport15 Path Finder in Getting Data In 06-12-2017
0 6
0
6
bowendenning
Hi all, I need to strip cookie values from IIS events. The sourcetype is correctly set as "iis" and the following co...
by bowendenning Path Finder in Getting Data In 06-12-2017
0 9
0
9
ibob0304
We have a windows forwarder running on vm02, and forwarding data to vm01 which is the main Splunk Enterprise. we co...
by ibob0304 Communicator in Getting Data In 06-10-2017
0 3
0
3
kritho
Hi, I have a SEDCMD simalar to SEDCMD-remove-values = s/<Value>.+<\/Value>/removed-by-splunk/g which works fin...
by kritho Explorer in Getting Data In 06-09-2017
0 1
0
1
twinspop
I've tried the /servicesNS/userid/-/data/ui/views endpoint but maybe I'm not using it correctly. I have a known view ...
by twinspop Influencer in Getting Data In 06-09-2017
0 5
0
5
the_scissor
Is it possible to provide inputs to Splunk through command line argument (similar to python for compiling)? Instead o...
by the_scissor Engager in Getting Data In 06-09-2017
1 2
1
2
dantimola
OS: Windows Server 2008 R2 Enterprise Splunk Universal Forwarder version: 6.2.6 (build 274160) Hi, Good Day. Would ...
by dantimola Communicator in Getting Data In 06-09-2017
0 4
0
4
gots
We have big file with events in each line of file. Every minute file transfers via rsync to forwarder with new events...
by gots Path Finder in Getting Data In 06-09-2017
0 1
0
1
JChute
Basically I need time/date code to add within my Panel so that each tiem it opens, the Panel searches from 8AM the fo...
by JChute Explorer in Getting Data In 06-09-2017
0 2
0
2
darinmoon
I'm trying to escape JSON data at index time because I can't do it from within the application that is generating the...
by darinmoon Explorer in Getting Data In 06-09-2017
1 7
1
7
anaqvi
I am trying to blacklist the following in the inputs.conf Currently I have this: [monitor:///var/log] disabled = f...
by anaqvi Explorer in Getting Data In 06-08-2017
0 8
0
8
nabeel652
I am monitoring WinEventLogs for Direct Access Troubleshooting using stanzas like: [WinEventLog://Microsoft-Windows-...
by nabeel652 Builder in Getting Data In 06-08-2017
0 2
0
2
infinitiguy
Hi, I'm trying to determine the best way to parse out data before it gets to my splunk indexer. It looks like a heav...
by infinitiguy Path Finder in Getting Data In 06-08-2017
0 14
0
14
wessam
Hello All, I have a column list of records as below recordA recordB recordA RecordB RecordC RecordD and I would l...
by wessam Explorer in Getting Data In 06-08-2017
0 19
0
19
vr2312
We have around 10 Search Heads and 13 Indexers. Since this morning, we are seeing the below errors and our SH is not ...
by vr2312 Builder in Getting Data In 06-08-2017
1 5
1
5
JSapienza
Does anyone know how to get the full output (including the details tab) or XML version of event logs out of Server 20...
by JSapienza Contributor in Getting Data In 06-08-2017
1 2
1
2
thard_splunk
Hello, I have a CSV in which I am attempting to shorten a 128 character string down to the last 8 characters. I used...
by thard_splunk Splunk Employee Splunk Employee in Getting Data In 06-08-2017
0 1
0
1
yutaka1005
Splunk ver 6.2.0 has been introduced in my separate environment, and recently I installed forwarder ver 6.6.1 on a ne...
by yutaka1005 Builder in Getting Data In 06-08-2017
0 3
0
3
smudge797
Is it possible to rename an index in the same way sourcetype and source can be renamed with props and transforms.
by smudge797 Path Finder in Getting Data In 06-08-2017
0 2
0
2
a212830
Hi, When the maxVolumeDataSizeMB for the primary volume is exceeded, will the events automatically roll over to the ...
by a212830 Champion in Getting Data In 06-07-2017
1 3
1
3
rwcbp
Splunk Docs do not specifically state that default encryption is active between Universal Forwarders and Heavy Forwar...
by rwcbp Explorer in Getting Data In 06-07-2017
1 5
1
5
davidpaper
I'm seeing the following two log messages on my UF. I'm also seeing big spikes in events every few minutes from this ...
by davidpaper Contributor in Getting Data In 06-07-2017
0 1
0
1
amanteja
Does Splunk forwarder 6.0.3 support TLSv1.2 or does it only support SSL v3?
by amanteja Path Finder in Getting Data In 06-07-2017
0 4
0
4
loatswil
I can't find the correct way to recursively monitor sub-directories in Windows for all files ending in .log. Can som...
by loatswil Path Finder in Getting Data In 06-07-2017
0 12
0
12
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...