Getting Data In

Getting Data In
Community Activity
dionmitchell
Hi all, Like the title says, is it possible to run Splunk Light with 2 indexers and a search head? Or is this a Spl...
by dionmitchell Engager in Getting Data In 02-07-2017
0 4
0
4
erinaldo
Hello all, I'm looking for guidance about a logging problem I am trying to solve. Right now we have a few security ...
by erinaldo Explorer in Getting Data In 02-07-2017
0 6
0
6
AzmathShaik
Hello I am running Splunk as not root user. my Splunk universal forwarder is not indexing data from all files. whe...
by AzmathShaik Path Finder in Getting Data In 02-07-2017
0 6
0
6
karlbosanquet
I have a WinEventLog://System log which rolls to archive every hour or so. I have 4 questions; 1) is the Splunk Univ...
by karlbosanquet Path Finder in Getting Data In 02-07-2017
0 2
0
2
karlbosanquet
I am deploying Indexer Cluster settings in an app to multiple Universal Forwarders via the Deployment Server. The iss...
by karlbosanquet Path Finder in Getting Data In 02-07-2017
1 2
1
2
saifuddin9122
Hello i have a log event as DEBUG 2017.02.06 17:15:35.385: (common.work) Parsed source address, source='10.0.0.2' i w...
by saifuddin9122 Path Finder in Getting Data In 02-07-2017
0 2
0
2
heathramos
I installed the Cisco Security suite as well as the Cisco ESA add-on. I am forwarding the mail_logs from Cisco ESA t...
by heathramos Path Finder in Getting Data In 02-07-2017
0 6
0
6
jarapally
Hi, I have logs with multi line events and I am trying to line break before the timestamp, but before date there is ...
by jarapally Explorer in Getting Data In 02-07-2017
0 2
0
2
henrysoon
Hi Splunker, Currently, we are panning upgrade to Windows Server 2016, may i know, will Splunk release latest msi ve...
by henrysoon New Member in Getting Data In 02-06-2017
0 1
0
1
Feedy
I've been trying to capture bash_history logs but I am not seeing this log populate in Splunk. I am able to get top, ...
by Feedy New Member in Getting Data In 02-06-2017
0 3
0
3
sbrice
I have two indexers, a search head, and universal forwarders. Post 6.5 upgrade, I am seeing a ton of these messages o...
by sbrice Explorer in Getting Data In 02-06-2017
0 3
0
3
seanperry
We would like to use Splunk to dashboard business level metrics. For these metrics, we would like to populate the "c...
by seanperry New Member in Getting Data In 02-06-2017
0 2
0
2
john_dagostino
So after months of battling an issue with our indexers dropping connections, we determined that there was a problem w...
by john_dagostino Path Finder in Getting Data In 02-06-2017
0 2
0
2
areeter
Hello. I really hope someone on here will be able to help me out. Long story short: I am having some difficulties re...
by areeter Explorer in Getting Data In 02-06-2017
3 5
3
5
twmjim
Hello, I'm trying to pull in a logfile that is named different on each workstation, using a regular expression in the...
by twmjim New Member in Getting Data In 02-06-2017
0 3
0
3
hartfoml
I have my frozen time set like this frozenTimePeriodInSecs = 47304000 (1.5 years) yet when I do this search | metad...
by hartfoml Motivator in Getting Data In 02-06-2017
0 7
0
7
naqviah
Is there a way to monitor Splunk server logon/logoff, basically trying to find the best way to audit access to Splunk...
by naqviah Explorer in Getting Data In 02-06-2017
0 2
0
2
feng_zhang
Hi Guys I have an issue with line breaking. I used data preview in Splunk Web and it breaks line as what I wanted. B...
by feng_zhang New Member in Getting Data In 02-05-2017
0 9
0
9
stwong
Hi, we're going to monitor following files on a host with universal forwarder installed: /data/asav/gw1new/log1.gz /...
by stwong Communicator in Getting Data In 02-05-2017
0 4
0
4
shahk
Hello, In my organization we are planning to use distributed search and index where our requirement is 3Gb data vol...
by shahk Explorer in Getting Data In 02-05-2017
0 3
0
3
grantsmiley
I have the following stanza in the universal forwarder Splunk 6.3: [WinEventLog://Security] disabled = 0 blacklist1=...
by grantsmiley Path Finder in Getting Data In 02-05-2017
0 6
0
6
lakromani
Hi My input file /tmp/log.txt looks like this. 192.168.22.5 93.x.x.x 456 2 192.168.22.10 183.x.x.x 63 1 src_ip dest...
by lakromani Builder in Getting Data In 02-04-2017
0 4
0
4
kteng2024
Under inputs.conf on Universal Forwarder (UF), i have these config as below:- 1.) [monitor:///var/home/jboss/logs/*....
by kteng2024 Path Finder in Getting Data In 02-03-2017
0 2
0
2
velocityehs
Hi, Probably a basic question, but I have tested out manually importing json logs into Splunk using a curl command w...
by velocityehs New Member in Getting Data In 02-03-2017
0 1
0
1
deepak02
Hi, This question is off-topic for Splunk, but please help me out since I need to set up the configuration urgently....
by deepak02 Path Finder in Getting Data In 02-03-2017
0 6
0
6
Get Updates on the Splunk Community!

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...
Top Solution Authors