Getting Data In

Getting Data In
Community Activity
helge
Server 2016 was released approximately 6 months ago, but it is still not listed as a supported OS on the system requi...
by helge Builder in Getting Data In 05-12-2017
0 4
0
4
deepak02
Hi, My data flows in from the forwarder where index=idx1 and sourcetype=sourcetypeA have been set using inputs.conf....
by deepak02 Path Finder in Getting Data In 05-12-2017
0 7
0
7
fairje
I know the WinHostMon input can be used to poll the status of all the services on a host, but it also outputs a lot o...
by fairje Communicator in Getting Data In 05-12-2017
0 1
0
1
quasikaze
We have a single inputs.conf stanza that sends the data from "targetLog.log" to a different indexer, "indexerB", than...
by quasikaze Explorer in Getting Data In 05-12-2017
0 6
0
6
nicocin
Hello Where can I find Information about Windows Server 2016 compatibility (universal forwarder)? Regards
by nicocin Path Finder in Getting Data In 05-12-2017
4 15
4
15
tgiles
Hi, I'm running into occasional errors from one of my indexers reporting "skipped indexing of internal audit event w...
by tgiles Path Finder in Getting Data In 05-12-2017
0 3
0
3
sassens1
Hello, I'd like to disable all the input on the Splunk_TA_microsoft_ad, is there a handy way to do this? for exampl...
by sassens1 Path Finder in Getting Data In 05-12-2017
0 3
0
3
abhinav_maxonic
I am forwarding some logs from a Heavy Forwarder to 2 indexers. I want to check if forwarder is balancing load/distr...
by abhinav_maxonic Path Finder in Getting Data In 05-11-2017
0 2
0
2
BlueSocket
Hi, I have a log file that I need to import into Splunk and I want to get it as efficient as possible, as there is a...
by BlueSocket Contributor in Getting Data In 05-11-2017
0 2
0
2
lloydknight
Hello Splunkers, So I have this csv file that a certain field contains 10+ numbers. Please see sample image below: ...
by lloydknight Builder in Getting Data In 05-11-2017
0 5
0
5
skuma30
Hi, I'm facing some issue that our indexers are not following the local indexes.conf settings in my local indexes.co...
by skuma30 New Member in Getting Data In 05-11-2017
0 3
0
3
sassens1
Hello I configured Splunk to handle TCP syslog from ironport appliances: [tcp://514] connection_host = dns index = ...
by sassens1 Path Finder in Getting Data In 05-11-2017
1 1
1
1
khhenderson
I have been trying to index a one line JSON file with 55,000 characters in a single line. Splunk seems to cut it off ...
by khhenderson Path Finder in Getting Data In 05-11-2017
1 4
1
4
jfraiberg
I was having major issues getting splunk to work with the "text" file that we are pushing all AIX commands to. Origi...
by jfraiberg Communicator in Getting Data In 05-11-2017
4 3
4
3
theouhuios
Hello I have few files for which I want to index just the first line and ignore everything else as its purely being ...
by theouhuios Motivator in Getting Data In 05-11-2017
0 5
0
5
Tejkumar451
HI I have a scenario where I need to filter the data present in a log. I need to index only the last line from that l...
by Tejkumar451 Explorer in Getting Data In 05-11-2017
0 3
0
3
koshyk
AS per props.conf documentation Use a comma-separated list to apply multiple transform stanzas to a single TRANSFOR...
by koshyk Super Champion in Getting Data In 05-11-2017
0 2
0
2
jagadeeshm
I have events with the following format - [Thread-2505_GOOGLE_INT_20170424155901301f9e61-1493049600619-NSRLM_2_1_RT...
by jagadeeshm Contributor in Getting Data In 05-11-2017
0 3
0
3
splunkreal
Hello, Does the Windows user for Splunk forwarder need "Remote Desktop access" rights? In general, what kind of Win...
by splunkreal Influencer in Getting Data In 05-11-2017
0 3
0
3
andrei_radu
Hi, I am trying to create a diag file on one of my indexers and the process is stuck at "Getting index listings..." ...
by andrei_radu New Member in Getting Data In 05-11-2017
0 2
0
2
dsofoulis
Hi, I would like to replace the "action" field so it conforms with the CIM datamodel. action at present will alway e...
by dsofoulis Path Finder in Getting Data In 05-11-2017
0 1
0
1
Sriram
I have sporadic issues where not all the logs from application logs are getting forwarded to Splunk. I see gaps in lo...
by Sriram Communicator in Getting Data In 05-11-2017
0 1
0
1
heats
It's always something! Now my Linux forwarder is saying the following: 05-10-2017 09:11:02.584 -0400 WARN TcpOut...
by heats Explorer in Getting Data In 05-10-2017
0 1
0
1
wplank
Hello, I'm currently testing the 6.2 Feature renderXML=1 for Windows Event Logs, but it seems to me the information ...
by wplank Path Finder in Getting Data In 05-10-2017
4 9
4
9
simpkins1958
I am forwarding data from Splunk Enterprise on one server to Splunk Enterprise on a second server. Data is getting in...
by simpkins1958 Contributor in Getting Data In 05-10-2017
0 1
0
1
Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...
Top Solution Authors