Getting Data In

Getting Data In
Community Activity
stwong
Hi, we're going to monitor following files on a host with universal forwarder installed: /data/asav/gw1new/log1.gz /...
by stwong Communicator in Getting Data In 02-05-2017
0 4
0
4
shahk
Hello, In my organization we are planning to use distributed search and index where our requirement is 3Gb data vol...
by shahk Explorer in Getting Data In 02-05-2017
0 3
0
3
grantsmiley
I have the following stanza in the universal forwarder Splunk 6.3: [WinEventLog://Security] disabled = 0 blacklist1=...
by grantsmiley Path Finder in Getting Data In 02-05-2017
0 6
0
6
lakromani
Hi My input file /tmp/log.txt looks like this. 192.168.22.5 93.x.x.x 456 2 192.168.22.10 183.x.x.x 63 1 src_ip dest...
by lakromani Builder in Getting Data In 02-04-2017
0 4
0
4
kteng2024
Under inputs.conf on Universal Forwarder (UF), i have these config as below:- 1.) [monitor:///var/home/jboss/logs/*....
by kteng2024 Path Finder in Getting Data In 02-03-2017
0 2
0
2
velocityehs
Hi, Probably a basic question, but I have tested out manually importing json logs into Splunk using a curl command w...
by velocityehs New Member in Getting Data In 02-03-2017
0 1
0
1
deepak02
Hi, This question is off-topic for Splunk, but please help me out since I need to set up the configuration urgently....
by deepak02 Path Finder in Getting Data In 02-03-2017
0 6
0
6
strousseau
Hello, I'm trying to import this kind of file : \#DATE TITRE1 TITRE2 TITRE3 #LINE TO IGNORE 20170101 LIGNE1COL1 LI...
by strousseau Path Finder in Getting Data In 02-03-2017
0 10
0
10
uhkc777
Hi, I have a scheduled report which runs every midnight over last 30 days data and indexing into summary index. But,...
by uhkc777 Explorer in Getting Data In 02-02-2017
0 5
0
5
hagjos43
We have SNMP data being sent from a heavy forwarder to our indexers into an index that we'll call cacti. We want SOM...
by hagjos43 Contributor in Getting Data In 02-02-2017
0 2
0
2
deepak02
Hi, I am trying a POC on my personal PC where Forwarder is on one machine (Linux)Indexer + Search Head on another m...
by deepak02 Path Finder in Getting Data In 02-02-2017
0 2
0
2
Waltersr24
Bad regex value: '\s+([.-\w]+)\s+RT_FLOW', of param: transforms.conf / [dvc_for_junos_fw] / REGEX; why: invalid range...
by Waltersr24 New Member in Getting Data In 02-02-2017
0 2
0
2
tgendron_splunk
I need to get a proper timestamp from raw data that looks like this: Date Of Incident: 12/02/2015 12:00:00 AM, Time ...
by tgendron_splunk Splunk Employee Splunk Employee in Getting Data In 02-02-2017
1 7
1
7
fab73
In order to filter out non-administrator logon events on WinEventLog:Security sourcetype, I inserted the following st...
by fab73 Path Finder in Getting Data In 02-02-2017
0 5
0
5
hemendralodhi
Hello Team, I have some confusion on calculating maxTotalDataSizeMB for configuring in indexes.conf file. Below are ...
by hemendralodhi Contributor in Getting Data In 02-01-2017
0 6
0
6
82padarthi
hi.. in one of my windows server the universal forwarder stopped unexpected. found and restarted the universal forwa...
by 82padarthi Explorer in Getting Data In 02-01-2017
0 10
0
10
jayakumar89
I have log file that has combination of plain text and key value pairs separated by "|". How can i extract all the fi...
by jayakumar89 Explorer in Getting Data In 02-01-2017
0 4
0
4
ericmck2000
So... I am attempting to setup a TCP input, which will automatically set metadata, from the event. The _Raw looks li...
by ericmck2000 Explorer in Getting Data In 02-01-2017
0 2
0
2
praveenbandi
Hi Splunkers, Is there any way to list all the saved searches in Splunk? I want to export the saved searches details...
by praveenbandi Explorer in Getting Data In 02-01-2017
1 2
1
2
aholzer
I have configured monitoring for a set of files. I have configured the props.conf to use the 'last modified' time of ...
by aholzer Motivator in Getting Data In 02-01-2017
0 7
0
7
ereed18
I have rows where data looks like.. Value1^Value2^Value3Value4^Value5Value6Value7^Value8 My query (below)... searc...
by ereed18 Engager in Getting Data In 02-01-2017
0 2
0
2
christopherr_sp
 The Error Message on the screen isenter code here: "UniversalForwarder Setup ended prematurely"  Versions older tha...
by christopherr_sp Splunk Employee Splunk Employee in Getting Data In 02-01-2017
4 1
4
1
msutfin1
Or to restate the question : Why is Splunk Web reflecting the results of the CLI command, but inputs.conf file doesn'...
by msutfin1 Explorer in Getting Data In 01-31-2017
1 5
1
5
simon21
I have a csv file kept in a central path which is only uploaded once in a day. The moment i search the data on my sea...
by simon21 Path Finder in Getting Data In 01-31-2017
0 1
0
1
dperry
this is the format: {<!-- --> "epoch": "1485892851.94944", "id": "3952418", "name": "WMI Performance...
by dperry Communicator in Getting Data In 01-31-2017
0 3
0
3
Get Updates on the Splunk Community!

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...
Top Solution Authors