Getting Data In

Getting Data In
Community Activity
eddieddieddie
I'm trying to measure the amount of data leaving a heavy forwarder (called HVYFWD01).This is in preparation to moving...
by eddieddieddie Path Finder in Getting Data In 02-17-2026
0 1
0
1
ilhwan
I'm trying to rewrite the host field on events that are coming into a HEC on a HF.  It's populating the hostname of t...
by ilhwan Path Finder in Getting Data In 02-17-2026
0 8
0
8
sswigart
My network has Splunk Enterprise 10.0.2, and it is air-gapped.I want to run a Linux and Windows enterprise server sid...
by sswigart Explorer in Getting Data In 02-16-2026
0 4
0
4
spl_aficionado
@richgalloway explained clearly in the post, that INDEXED_EXTRACTIONS=CSV makes all the fields indexed. What would be...
by spl_aficionado Path Finder in Getting Data In 02-10-2026
0 1
0
1
spl_aficionado
I just set INDEXED_EXTRACTIONS = CSV for a large data ingestion sourcetype, and validating with tstats, and it seems ...
by spl_aficionado Path Finder in Getting Data In 02-09-2026
0 2
0
2
adnankhan5133
Hi,Does anyone know how to ingest the WAF logs generated by the Oracle Cloud Web Application Firewall service? The lo...
by adnankhan5133 Communicator in Getting Data In 02-09-2026
0 2
0
2
cmeo-bcit
I see from the latest release notes that the recommended sourcetype is ms:iis:auto and the others have been deprecate...
by cmeo-bcit Explorer in Getting Data In 02-08-2026
0 4
0
4
Navanitha
I am trying to forward win event security logs from server using UF to our Heavy forwarder.  UF has all the required ...
by Navanitha Path Finder in Getting Data In 02-06-2026
0 4
0
4
muradgh
I have a Fortigate firewall that was configured to send UDP logs, lately, I have configured it to send TCP logs inste...
by muradgh Path Finder in Getting Data In 02-06-2026
1 20
1
20
StuartMacL
I have the Splunk add-on for Amazon Web Services v 8.0.0 installed on a Heavy Forwarder and we have several inputs wo...
by StuartMacL Path Finder in Getting Data In 02-06-2026
0 1
0
1
Nraj87
please advise whether there is a solution or monitoring use case to identify interruptions in HEC base data ingestion...
by Nraj87 Explorer in Getting Data In 02-05-2026
0 3
0
3
Poojitha
Hi Everyone, I have created a custom app that clones current raw data , extracts metrics and dimensions from existing...
by Poojitha Communicator in Getting Data In 02-04-2026
0 2
0
2
danielbb
We recently experienced a data gap for our Google index lasting several days. Our environment uses the following two ...
by danielbb Motivator in Getting Data In 02-02-2026
0 1
0
1
GSNRMUVW
Hi Community,how to cut..., "q": 0, "user": "system.user.admin"...from...{ "val": 0, "ts": 1770058561014, "q": 0, "us...
by GSNRMUVW Loves-to-Learn in Getting Data In 02-02-2026
0 6
0
6
briancronrath
I have been tasked with building out new instances of anything that runs an older OS, and for our EC2 instances this ...
by briancronrath Contributor in Getting Data In 02-02-2026
0 1
0
1
Jayanthan
We have employed Cymulate, a BAS (Breach Attack Simulation) Solution for Red Teaming activity and Detection Engineeri...
by Jayanthan Loves-to-Learn Everything in Getting Data In 01-30-2026
0 0
0
0
danielbb
I have this "innocent" regex to send to the nullQueue in transforms.conf, and it doesn't work. I'm scratching my head...
by danielbb Motivator in Getting Data In 01-29-2026
0 5
0
5
msaleh7422
We would like your guidance on how to calculate the required number of Splunk indexers for our environment.Currently,...
by msaleh7422 Engager in Getting Data In 01-28-2026
0 2
0
2
LM_ACN
Hello Splunker, i need your help.I have a problem with monitoring a single XML file that records events from an appli...
by LM_ACN Engager in Getting Data In 01-27-2026
0 2
0
2
ws
Hi,I understand that ports below 1024 are reserved for root access. Is there any supported way for Splunk to listen o...
by ws Path Finder in Getting Data In 01-26-2026
0 6
0
6
_pravin
Hi,I have incoming data from 2 Heavy Forwarders.Both of forward HEC data and the internal logs, how do I identify whi...
by _pravin Contributor in Getting Data In 01-22-2026
0 14
0
14
spl_aficionado
Hello Splunk Community,My team is currently processing logs from a single source that can contain events with differe...
by spl_aficionado Path Finder in Getting Data In 01-21-2026
0 6
0
6
bil151515
Hey!My team is interested in integration of Splunk (especially ES) and TheHive Project products.The goal is to provid...
by bil151515 Engager in Getting Data In 01-20-2026
1 3
1
3
kn450
 Hi,I’m trying to use Splunk as a log aggregation solution, and eventually as a SIEM. I have three industrial plants ...
by kn450 Explorer in Getting Data In 01-19-2026
0 1
0
1
ibrahim1
We have a distributed on-prem Splunk environment with strict network segmentation between sites.Scenario:Site B:Sourc...
by ibrahim1 Explorer in Getting Data In 01-19-2026
0 11
0
11
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors