Getting Data In

Getting Data In
Community Activity
AzmathShaik
Hello i am trying to remove inner double quotes from json data here is my sample data: {"msg": "the message "is p...
by AzmathShaik Path Finder in Getting Data In 11-22-2016
0 2
0
2
mrtolu6
I have over 300 Universal forwarders and I'm getting several eventcode=5156 events errors. Is there a way to blackli...
by mrtolu6 Path Finder in Getting Data In 11-22-2016
0 4
0
4
koshyk
Reading through the "offline" documentation & "maintenance" mode documentation, I'm slighly confused, if we need to d...
by koshyk Super Champion in Getting Data In 11-22-2016
0 2
0
2
tom8h
I configured Forwarder Monitoring Setup of DMC function for monitoring status of forwarders, but the Distributed Mana...
by tom8h Explorer in Getting Data In 11-21-2016
0 3
0
3
ankithreddy777
I have a single line event as shown. I have to break it to multiple lines starting at {IBP_LKL . May I know what set...
by ankithreddy777 Contributor in Getting Data In 11-21-2016
0 1
0
1
seeia
I initially tested the Splunk Server on a Windows 7 machine and installed the Universal Forwarder on another WIndows ...
by seeia Engager in Getting Data In 11-21-2016
0 1
0
1
ddrillic
I wonder what would be an efficient way for a custom app to communicate with an indexer? Can the custom app write to ...
by ddrillic Ultra Champion in Getting Data In 11-21-2016
0 3
0
3
vikas_gopal
Hi Experts, I got a situation. By mistake, I uploaded the same license that I used for Indexers and Master node. Now...
by vikas_gopal Builder in Getting Data In 11-21-2016
0 1
0
1
dstaulcu
When using automatic load balancing of outputs from universal forwarders (UF), the default number of seconds a forwar...
by dstaulcu Builder in Getting Data In 11-21-2016
0 1
0
1
ebrand
For our "ATA42_NETWORK" application we have indexed *.NCD files These files are located in an “input directory” moni...
by ebrand New Member in Getting Data In 11-21-2016
0 6
0
6
skoelpin
I'm migrating a standalone indexer from Windows to Linux. I mounted the snapshot onto the Linux box and currently mov...
by SplunkTrust SplunkTrust in Getting Data In 11-21-2016
0 5
0
5
nmensah
I'm a bit confused about the user-seed.conf. Based on the documentation provided by Splunk, it seems this is to set u...
by nmensah Explorer in Getting Data In 11-21-2016
1 3
1
3
hulahoop
When Splunk monitors hundreds/thousands of files, there seems to be a long lag between the time the event is generate...
by hulahoop Splunk Employee Splunk Employee in Getting Data In 11-21-2016
12 7
12
7
andresito123
Hello! I am preparing for the architect exam and I have set the following lab: 10.37.129.10 spl-search-head ...
by andresito123 Communicator in Getting Data In 11-20-2016
2 31
2
31
eyirik
Hi i want to read vehicle data in Splunk.. Data is seen on vehice network like below: ID data le...
by eyirik Explorer in Getting Data In 11-20-2016
0 1
0
1
gianpaolodelgro
Hi, we have to implement a Splunk architecture (for a development/test environment). We have 2 virtual devices, and w...
by gianpaolodelgro New Member in Getting Data In 11-18-2016
0 4
0
4
pavanae
Hi the following were the splunkd.log messages in the deployment client. I don't know why it isn't showing any warnin...
by pavanae Builder in Getting Data In 11-18-2016
0 7
0
7
nmensah
Hello everyone, I have in theory a very simple question. Hopefully this is as simple as I think it is. I have a depl...
by nmensah Explorer in Getting Data In 11-18-2016
1 5
1
5
TheJagoff
Hello, I forgot to have an index ready when I started to ingest data (log file with data from last week to present) ...
by TheJagoff Communicator in Getting Data In 11-18-2016
1 2
1
2
yqifan83
My props.conf is like: BREAK_ONLY_BEFORE_DATE = true TIME_PREFIX = GMT TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N MAX_DAYS_...
by yqifan83 New Member in Getting Data In 11-18-2016
0 6
0
6
brian1_tate
Hello all, I am trying to build a workflow for our new Splunk product and want to know what top three regular daily ...
by brian1_tate Path Finder in Getting Data In 11-18-2016
0 8
0
8
anaqvi
I am trying to monitor the Active Directory Server for logs. I have a universal forwarder installed on a Windows AD S...
by anaqvi Explorer in Getting Data In 11-18-2016
0 1
0
1
prabhasgupte
I am trying to install a TA from Splunk command line. Referring to http://docs.splunk.com/Documentation/Splunk/6.5.0/...
by prabhasgupte Communicator in Getting Data In 11-18-2016
0 1
0
1
guimilare
Hello Splunkers. I'm working on 2 scenarios, and I'm sure you guys can help me. Scenario 1: We have about 15 indexe...
by guimilare Communicator in Getting Data In 11-18-2016
0 2
0
2
rodneyjerome
Hi, I'm using the below line, while creating custom command for key value field extraction. My events are in json f...
by rodneyjerome Explorer in Getting Data In 11-18-2016
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors