Getting Data In

Getting Data In
Community Activity
Jtorge
I recently started pulling Tenable data in through the Tenable Add-on for Splunk, and when I search the data in Searc...
by Jtorge Explorer in Getting Data In 02-24-2026
0 1
0
1
Jtorge
I have a RHEL admin who is building two syslog servers to ingest data from one RHEL node redundantly. These two syslo...
by Jtorge Explorer in Getting Data In 02-23-2026
0 5
0
5
anmolxmr
What Splunk servers should the installation be on? What components of the app will go into - HF- Cluster Master- Sear...
by anmolxmr Explorer in Getting Data In 02-23-2026
0 1
0
1
JJ_Splunk
Okay, I just want to make sure I understand everything correctly.I'm currently working on a Splunk environment, it cu...
by JJ_Splunk New Member in Getting Data In 02-22-2026
0 1
0
1
amimulahasun
Hi Team,I’m looking for guidance on designing a Splunk SIEM ingestion strategy for the following scenario:We receive ...
by amimulahasun Explorer in Getting Data In 02-22-2026
0 6
0
6
Sagittis
I've an infrastructure where everyone are administrator and therefore can change the universal forwarder configuratio...
by Sagittis Explorer in Getting Data In 02-21-2026
0 6
0
6
cutright_jm
I'm running Splunk Universal Forwarder with a Splunk Enterprise deployment. On a new install, all information is popu...
by cutright_jm New Member in Getting Data In 02-20-2026
0 7
0
7
tkwaller1
HelloCurrently all data forwarded to our on-prem HF goes to Splunk Cloud, I now have a single file that I want to ind...
by tkwaller1 Path Finder in Getting Data In 02-19-2026
0 4
0
4
harman
i am uploading the data in the text format and that data contains logs but when i successfully upload the data of par...
by harman Explorer in Getting Data In 02-18-2026
0 5
0
5
eddieddieddie
I'm trying to measure the amount of data leaving a heavy forwarder (called HVYFWD01).This is in preparation to moving...
by eddieddieddie Path Finder in Getting Data In 02-17-2026
0 1
0
1
ilhwan
I'm trying to rewrite the host field on events that are coming into a HEC on a HF.  It's populating the hostname of t...
by ilhwan Path Finder in Getting Data In 02-17-2026
0 8
0
8
sswigart
My network has Splunk Enterprise 10.0.2, and it is air-gapped.I want to run a Linux and Windows enterprise server sid...
by sswigart Explorer in Getting Data In 02-16-2026
0 4
0
4
spl_aficionado
@richgalloway explained clearly in the post, that INDEXED_EXTRACTIONS=CSV makes all the fields indexed. What would be...
by spl_aficionado Path Finder in Getting Data In 02-10-2026
0 1
0
1
spl_aficionado
I just set INDEXED_EXTRACTIONS = CSV for a large data ingestion sourcetype, and validating with tstats, and it seems ...
by spl_aficionado Path Finder in Getting Data In 02-09-2026
0 2
0
2
adnankhan5133
Hi,Does anyone know how to ingest the WAF logs generated by the Oracle Cloud Web Application Firewall service? The lo...
by adnankhan5133 Communicator in Getting Data In 02-09-2026
0 2
0
2
cmeo-bcit
I see from the latest release notes that the recommended sourcetype is ms:iis:auto and the others have been deprecate...
by cmeo-bcit Explorer in Getting Data In 02-08-2026
0 4
0
4
Navanitha
I am trying to forward win event security logs from server using UF to our Heavy forwarder.  UF has all the required ...
by Navanitha Path Finder in Getting Data In 02-06-2026
0 4
0
4
muradgh
I have a Fortigate firewall that was configured to send UDP logs, lately, I have configured it to send TCP logs inste...
by muradgh Path Finder in Getting Data In 02-06-2026
1 20
1
20
StuartMacL
I have the Splunk add-on for Amazon Web Services v 8.0.0 installed on a Heavy Forwarder and we have several inputs wo...
by StuartMacL Path Finder in Getting Data In 02-06-2026
0 1
0
1
Nraj87
please advise whether there is a solution or monitoring use case to identify interruptions in HEC base data ingestion...
by Nraj87 Explorer in Getting Data In 02-05-2026
0 3
0
3
Poojitha
Hi Everyone, I have created a custom app that clones current raw data , extracts metrics and dimensions from existing...
by Poojitha Communicator in Getting Data In 02-04-2026
0 2
0
2
danielbb
We recently experienced a data gap for our Google index lasting several days. Our environment uses the following two ...
by danielbb Motivator in Getting Data In 02-02-2026
0 1
0
1
GSNRMUVW
Hi Community,how to cut..., "q": 0, "user": "system.user.admin"...from...{ "val": 0, "ts": 1770058561014, "q": 0, "us...
by GSNRMUVW Loves-to-Learn in Getting Data In 02-02-2026
0 6
0
6
briancronrath
I have been tasked with building out new instances of anything that runs an older OS, and for our EC2 instances this ...
by briancronrath Contributor in Getting Data In 02-02-2026
0 1
0
1
Jayanthan
We have employed Cymulate, a BAS (Breach Attack Simulation) Solution for Red Teaming activity and Detection Engineeri...
by Jayanthan Loves-to-Learn Everything in Getting Data In 01-30-2026
0 0
0
0
Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...
Top Solution Authors