Getting Data In

Getting Data In
Community Activity
yuanliu
For example, if I put this in inputs.conf [script:/bin/ls /*/lib /var/lib /usr/lib ] sourcetype = ls The latter tw...
by SplunkTrust SplunkTrust in Getting Data In 06-16-2017
0 7
0
7
msichani
Hi, I've reviewed almost all the question about event line breaking but still have some inconsistency with data inges...
by msichani Explorer in Getting Data In 06-16-2017
1 4
1
4
pimco_rgoyal
The substr function is not working for json logs for us in 6.5.2 for Dev version. Whereas the Prod version of the Spl...
by pimco_rgoyal Observer in Getting Data In 06-16-2017
0 10
0
10
vanderaj2
I was wondering if possible for a single splunk universal forwarder to be managed by two different deployment servers...
by vanderaj2 Path Finder in Getting Data In 06-16-2017
0 3
0
3
lukasz92
Hi, I need to use Splunk rest command in search - but I wish to generate a POST request instead of GET. Is it possib...
by lukasz92 Communicator in Getting Data In 06-16-2017
0 3
0
3
isha_rastogi
I am working in the FIX log messages and have two fields that contain timestamps. I need to check for one field and i...
by isha_rastogi Path Finder in Getting Data In 06-16-2017
0 8
0
8
rangineniarunku
I have deployed SplunK_TA_Windows and setup monitoring for Applicatiom, System ,Security, HardwareEvents and Setup wi...
by rangineniarunku Explorer in Getting Data In 06-16-2017
0 1
0
1
karthi2809
index=bp_prod NOT ([|inputlookup serverBP.csv|fields Servers Status |where Status=="N"] ) |eventstats count as "total...
by karthi2809 Builder in Getting Data In 06-16-2017
0 1
0
1
thamohit
I have a requirement where I will be getting logs from various sources in Splunk, extract some useful information fro...
by thamohit New Member in Getting Data In 06-15-2017
0 4
0
4
sillingworth
I have 2 VMs, one running an indexer: hostname "splunkbox" ip 192.168.56.151 and one running a universal forwarder...
by sillingworth Path Finder in Getting Data In 06-15-2017
0 5
0
5
jw44250
I have 10 indexes...i want to find the actual size of the index before splunk adding its indexing. and after as well...
by jw44250 New Member in Getting Data In 06-15-2017
0 4
0
4
shinde0509
2017-04-02 22:45:19.023 -0600 so-splunky.local sshd[68061]: Accepted keyboard-interactive/pam for sowings from xx.xx....
by shinde0509 Explorer in Getting Data In 06-15-2017
0 3
0
3
amantjes
Hi all, In our case timestamps within the splunk events are standard GMT where people working from different timezo...
by amantjes New Member in Getting Data In 06-15-2017
0 2
0
2
fernandoandre
At Indexer level how to force props.conf linebreaking setup to be applied to a specific sourcetype of data arriving f...
by fernandoandre Communicator in Getting Data In 06-15-2017
0 5
0
5
dbatts
On all the Universal Forwarders, any user has the ability to access REST API called Splunk ATOM Feed:Splunkd. They c...
by dbatts Explorer in Getting Data In 06-15-2017
1 3
1
3
MarcHelou
let's say i have a file that I would like to input it to splunk. but I want to have a better parser, a smarter one. h...
by MarcHelou New Member in Getting Data In 06-15-2017
0 5
0
5
phoenixdigital
Hi All, So following this excellent blog post I thought I found a solution to ingesting a binary logfile with Splunk...
by phoenixdigital Builder in Getting Data In 06-15-2017
0 8
0
8
rune_hellem
Running Splunk 6.0.1 (build 189883), all on Windows-servers, a mix of 2008/2012-servers. Indexing a lot of SystemOut...
by rune_hellem Contributor in Getting Data In 06-14-2017
1 2
1
2
evanwyk11
Good Day I've got two issues with my HTTP event collector. 1st issue: I created an event collector when I installe...
by evanwyk11 Engager in Getting Data In 06-14-2017
1 4
1
4
LuiesCui
Hey guys, I'm new to splunk and I really need ur help!!! As what I know, once the data from a .log file are loaded b...
by LuiesCui Communicator in Getting Data In 06-14-2017
1 11
1
11
Svill321
I apologize in advance if this is an extremely basic question, but I need to be sure I do this correctly. I'm resear...
by Svill321 Path Finder in Getting Data In 06-14-2017
0 2
0
2
ssaenger
Hi All, I have a log file that has a non standard date/time and special characters and i am trying to split the line...
by ssaenger Communicator in Getting Data In 06-14-2017
0 2
0
2
pkeller
A user is reporting that their indexed json data has a 'source' key that is being extracted. "source": "[{label:'Tre...
by pkeller Contributor in Getting Data In 06-14-2017
1 1
1
1
evan_roggenkamp
This is the way my data looks: { "NODE-A":{ "DATA":{ "SNR_DATA":{ "Cable3/0/3-...
by evan_roggenkamp Path Finder in Getting Data In 06-14-2017
0 1
0
1
psalibindla9524
I would like to search index=main type=router OR type=switch OR type=firewall OR type=sysproxy .. Instead i wan...
by psalibindla9524 New Member in Getting Data In 06-14-2017
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...
Top Solution Authors