Getting Data In

Getting Data In
Community Activity
Douglas
Hello! So here is a doozy. We have blacklists in place using Regx. In particular this one:[WinEventLog://Microsoft-Wi...
by Douglas New Member in Getting Data In 04-08-2024
0 4
0
4
zach-keener
Hello,I have this data here: 2024-04-03 13:57:54 10.237.8.167 GET / "><script>alert('struts_sa_surl_xss.nasl-17121526...
by zach-keener Explorer in Getting Data In 04-08-2024
0 6
0
6
sahityasweety
How to keep specific events and discard the rest in props.conf and transforms.confWe are Receiving large amount of da...
by sahityasweety Explorer in Getting Data In 04-08-2024
0 4
0
4
cdavidsonbp
Hello, When I try to sample data for the WinEventLog sourcetype in Ingest Actions I get an error message:     "No res...
by cdavidsonbp Observer in Getting Data In 04-08-2024
0 3
0
3
danielbb
Since we are in early stages of using Splunk cloud, we don't define props.conf as part of the onboarding process, and...
by danielbb Motivator in Getting Data In 04-07-2024
0 1
0
1
Moshe
Hi,I'm looking for a way to connect the SPLUNK to a ODCB data base, so the Splunk will be able to pull any data neede...
by Moshe New Member in Getting Data In 04-07-2024
0 5
0
5
ramesh_babu71
We are gathering logs from various devices that contain security, performance, and availability-related information. ...
by ramesh_babu71 Path Finder in Getting Data In 04-06-2024
0 2
0
2
BoxerguyT89
Hello all I hope this is the right forum,I am having some trouble with the Barracuda Email Security Gateway Add-on an...
by BoxerguyT89 Loves-to-Learn Lots in Getting Data In 04-06-2024
0 2
0
2
dionrivera
I already have the Salesforce add-on for Splunk. Does Salesforce have an email source that I can tap on to get those ...
by dionrivera Communicator in Getting Data In 04-05-2024
0 0
0
0
WumboJumbo675
Hello all -Trying to get Azure Event Hub data to flow into Splunk. Having issues configuring it with the add-on for M...
by WumboJumbo675 Explorer in Getting Data In 04-05-2024
0 5
0
5
shocko
I’m using Splunk Enterprise 9 with Universal Forwarder 9 on Windows. I'd like to monitor several structured log files...
by shocko Contributor in Getting Data In 04-05-2024
0 8
0
8
_joe
Hello all,SynApp: 3.0.3OS: RHEL8 FIPSSplunk 9.0.xI configured this app and changed the index IPs in the local inputs....
by _joe Contributor in Getting Data In 04-05-2024
0 0
0
0
Ulwur2
I'm experimenting with doing ETW logging of Microsoft IIS, where the IIS log ends up as XML in a windows eventlog.But...
by Ulwur2 Loves-to-Learn in Getting Data In 04-05-2024
0 2
0
2
gazoscreek
I'm trying to remove some Windows events from being ingested ... example below:The regex I've tried in both Ingest Ac...
by gazoscreek Path Finder in Getting Data In 04-04-2024
0 2
0
2
Rosie2287
Is there a Splunk query I can use to list when CD drive is access and written to and the users associated with those ...
by Rosie2287 Explorer in Getting Data In 04-04-2024
0 5
0
5
Rosie2287
Is there a query I can add to my splunk dashboard that will list accounts inactive over 35 days?
by Rosie2287 Explorer in Getting Data In 04-04-2024
0 4
0
4
AvivBenSha
From what I understand about Splunk, it works on the raw data and does not parse it. It does mark and "segments" area...
by AvivBenSha New Member in Getting Data In 04-04-2024
0 2
0
2
JLopez
Hi Splunkers,Let me provide a bit of background,   We are ingesting logs into splunk using an API from our DLP servic...
by JLopez Explorer in Getting Data In 04-04-2024
0 1
0
1
billy
I have a universal forwarder running on my Domain Controller which only captures logon/logff events.inputs.conf```[Wi...
by billy Loves-to-Learn Everything in Getting Data In 04-04-2024
0 2
0
2
VinayakJamadar
I am sending logs from application to splunk server by Splunk logging for java using Http Event Collector with log4j2...
by VinayakJamadar Loves-to-Learn Lots in Getting Data In 04-03-2024
0 3
0
3
CarolinaHB
Hello, I need to event break the following events, but they have a different date format. At the beginning, only at t...
by CarolinaHB Explorer in Getting Data In 04-03-2024
0 7
0
7
Splunker2024
I ran a |REST search to export the list of savedsearches along with their cronjob schedules.  The cronjob scheduled a...
by Splunker2024 New Member in Getting Data In 04-03-2024
0 1
0
1
alexcybrill12
Is it possible for the next version of the add-on to add MS defender vulnerabilty API calls to this add-on? Currently...
by alexcybrill12 Engager in Getting Data In 04-03-2024
0 1
0
1
conan_wall
I've setup Splunk enterprise as a trial in a test domain however im having issues importing logs from different remot...
by conan_wall New Member in Getting Data In 04-03-2024
0 3
0
3
Hiattech
I have an odd task I'm trying to fulfill and I'm not entirely sure how to go about it. We have a print server that fo...
by Hiattech Explorer in Getting Data In 04-03-2024
0 7
0
7
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors