Getting Data In

Getting Data In
Community Activity
dwoehr
Hello, I'm trying to figure out the following setup: At the moment we have one rotating log file that should be forw...
by dwoehr Explorer in Getting Data In 12-14-2016
0 4
0
4
jhigginsmq
Hi. We have recently been inadvertently sending some events to the null queue, due to a new data source that matche...
by jhigginsmq Path Finder in Getting Data In 12-14-2016
0 5
0
5
nickbijmoer
Hello guys, I got Cisco firewalls and switches. Now we enabled syslog but I want to see when a port status goes from...
by nickbijmoer Path Finder in Getting Data In 12-13-2016
0 4
0
4
TeganDeloitte
I have one forwarder that is showing duplicate on my Splunk server. I updated 3 forwarders to test them. It was from ...
by TeganDeloitte New Member in Getting Data In 12-13-2016
0 1
0
1
ankithreddy777
I learned that Splunk compresses the incoming data and creates some index files to point towards compressed raw data....
by ankithreddy777 Contributor in Getting Data In 12-13-2016
0 9
0
9
schose
Hi forum, I'm trying to monitor an xml structured logfile like this: <Events> <Event>line1</Events> <Event>line2</E...
by schose Builder in Getting Data In 12-13-2016
0 1
0
1
evang_26
Hi users, I recently installed universal forwarder on a Windows machine, aiming to forward logs from there to the Sp...
by evang_26 Communicator in Getting Data In 12-13-2016
0 5
0
5
IngloriousSplun
I have a requirement to route data that falls within two /24 CIDR ranges to a separate index, say 10.0.1.0/24 and 10....
by IngloriousSplun Communicator in Getting Data In 12-13-2016
0 3
0
3
a212830
Hi, I have a bunch of different hosts going to a network port for syslog and need to route to different indexes/sour...
by a212830 Champion in Getting Data In 12-12-2016
0 2
0
2
rsingh
i need help with adding this to my inputs.conf file on Splunk forwarder servers. i need Splunk to search this specifi...
by rsingh Explorer in Getting Data In 12-12-2016
0 5
0
5
responsys_cm
I have a light forwarder listening on tcp:514. It forwards data to three indexers, all of whose clocks are set to UTC...
by responsys_cm Builder in Getting Data In 12-12-2016
0 1
0
1
paimonsoror
Hi Folks; Hopefully this isn't a strange question, but I had a question regarding the consolidation of configuration...
by paimonsoror Builder in Getting Data In 12-12-2016
0 4
0
4
roychen
Hi, I'm trying to configure performance monitoring inputs on a Windows universal forwarder, to send to a Linux index...
by roychen Path Finder in Getting Data In 12-12-2016
0 4
0
4
ddrillic
We have a case in which the client has directories, each containing a couple of thousands of log files, like - 20161...
by ddrillic Ultra Champion in Getting Data In 12-12-2016
0 5
0
5
allen_edmondso1
Hi, We have a number of forwarders in our Splunk Enterprise. And I've been asked to chart the "uptime" of the forwar...
by allen_edmondso1 New Member in Getting Data In 12-12-2016
0 6
0
6
arkonner
I am monitoring the directory where IIS logs are stored. The universal forwarder is sending the information on a dedi...
by arkonner Path Finder in Getting Data In 12-12-2016
0 4
0
4
mzorzi
Assuming I have a forwarder with inputs.conf: [monitor:///var/log/notcritical] index=datacritical [monitor:///var/l...
by mzorzi Splunk Employee Splunk Employee in Getting Data In 12-12-2016
0 1
0
1
bosch_softtec
Hi, Splunk 6.5.0 I have the scenario that I have to import every hour a csv (File A) file from a system which has n...
by bosch_softtec Path Finder in Getting Data In 12-12-2016
0 2
0
2
Deepali529
Uploaded File size: 717MB Current Index size: 811MB ( settings -> Data -> Indexes ) Index Size: 0.79 GB ( Monitoring...
by Deepali529 Explorer in Getting Data In 12-11-2016
0 8
0
8
elindemann
Hello there, I'm currently trying to whilelist incoming Windows events by EventCode, but it doesn't actually filter...
by elindemann Engager in Getting Data In 12-10-2016
0 10
0
10
KagotaniMasato
以下のような前段のコマンドから結果を読み込み、自作の関数の結果を新しいカラムとして差し込んで次のコマンドへ引き渡す外部スクリプトを実行すると、以下のようなエラーになります。エラーにならない場合もあります。 commands.conf...
by KagotaniMasato Explorer in Getting Data In 12-09-2016
0 1
0
1
sravankaripe
i have a data like this: capturedTime = "12/6/16, 9:08 PM"; indymeDepartmentNumber = 250; lastCacheTime = "1...
by sravankaripe Communicator in Getting Data In 12-09-2016
0 2
0
2
dleifer_mercury
The learned app is creating objects owned by "nobody". This creates logged error messages about ERROR Authenticati...
by dleifer_mercury New Member in Getting Data In 12-09-2016
0 1
0
1
mukherjee_mk
Hello fellow-splunkers! Problem Statement - My logs have INFO, WARNING and DEBUG log entries. The DEBUG log entries...
by mukherjee_mk Explorer in Getting Data In 12-08-2016
1 4
1
4
Splunk0n
Hello Splunkers - Using Splunk Web, can I search/index a specific host name or IP address that returns the “Identifie...
by Splunk0n New Member in Getting Data In 12-08-2016
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors