Getting Data In

Getting Data In
Community Activity
a212830
Hi, Is it possible to have a custom REST endpoint that executes scripts on a universal forwarder?
by a212830 Champion in Getting Data In 11-13-2016
0 5
0
5
englishjohn
I have two different file names in the same directory on a forwarder. The problem is, the data for both files are the...
by englishjohn New Member in Getting Data In 11-12-2016
0 4
0
4
anushareddy6767
We have a master image controlling 10 Citrix XenApp hosts, We have deployed Splunk Universal Forwarders via master im...
by anushareddy6767 Explorer in Getting Data In 11-12-2016
0 1
0
1
mmah123
Hello Experts, I am working on HEC rest api's /services/collector. Passing fields as given in the examples but gettin...
by mmah123 New Member in Getting Data In 11-11-2016
0 1
0
1
sayz
hi; we have 7 remote log servers which we are sending all of our logs from approximately 400 different servers(apach...
by sayz Path Finder in Getting Data In 11-11-2016
0 4
0
4
surekhasplunk
Hi, I have Splunk installed on my local Windows machine. From Splunk Web url, am doing below steps Settings -> Add ...
by surekhasplunk Communicator in Getting Data In 11-11-2016
0 5
0
5
ankithreddy777
I have a epoch time in my events: timestamp=1478787869121. How to write props.conf to extract this timestamp?
by ankithreddy777 Contributor in Getting Data In 11-10-2016
0 1
0
1
mfrost8
Hi, I'm struggling with an issue involving my old nemesis, inputs.conf rules :-). In this case, we have a catch-all...
by mfrost8 Builder in Getting Data In 11-10-2016
1 2
1
2
brdr
We will be installing the forwarder onto our domain controllers in DMZ. Question, can we hardwire a port on the DC w...
by brdr Contributor in Getting Data In 11-10-2016
0 3
0
3
Susannajuurinen
Is there a way to use external lists with whitelist filtering? For example if I had systems A and B with several host...
by Susannajuurinen Explorer in Getting Data In 11-10-2016
0 3
0
3
sebch
Hi, I'm using Splunk Enterprise 6.5.0 with Universal forwarders 6.5.0 for some years now to index log files from .Ne...
by sebch Engager in Getting Data In 11-10-2016
0 2
0
2
sadkha
Hello, I am trying to onboard an ActiveRoles server, however it doesn't seem that I'm configuring my inputs.conf ap...
by sadkha Path Finder in Getting Data In 11-10-2016
0 3
0
3
snehalk
Hello All, Is this possible in Splunk where we can add new fields and there value will depends on condition? in tran...
by snehalk Communicator in Getting Data In 11-10-2016
0 4
0
4
dbcase
Hi, I know Splunk will injest a TAR (and other types) file, my question is what if the file extension is NOT *.tar o...
by dbcase Motivator in Getting Data In 11-10-2016
0 2
0
2
Hajime
Hello, I want to know a retirement policy of the fishbucket on the universal forwarder for a disk sizing. The data ...
by Hajime Path Finder in Getting Data In 11-09-2016
0 5
0
5
krishnacasso
We need to monitor a log file on linux with the splunk forwarder(splunk user account which is local). Log file is own...
by krishnacasso Path Finder in Getting Data In 11-09-2016
0 1
0
1
fernandoandre
Hi I have some universal forwaders installed on linux (suse) and solaris. I have a user "splunk" to log to those ma...
by fernandoandre Communicator in Getting Data In 11-09-2016
0 2
0
2
dmacndawk
I'm trying to install Splunk Universal Forwarder on Red Hat OS. I am getting stuck at this step. Before this command,...
by dmacndawk New Member in Getting Data In 11-09-2016
0 1
0
1
reggie_123
Hi, What will splunk behave like in the two following cases: 1) File A.log, having the lines: 1 2 3 ...
by reggie_123 Explorer in Getting Data In 11-09-2016
1 2
1
2
crazyeva
i am test '_tcp_routing' in my virtual machines, before doing that on online system. simply i add: [monitor://afile] ...
by crazyeva Contributor in Getting Data In 11-09-2016
0 1
0
1
ozirus
Hi, I've a universal forwarder on a Linux machine that forwards Security Onion logs to my Splunk instance. Logs are...
by ozirus Path Finder in Getting Data In 11-09-2016
0 4
0
4
rh990
You'll have to pardon the newbie question. I'm sure this is crazy easy, but I'm having the worst time figuring it out...
by rh990 Engager in Getting Data In 11-08-2016
0 5
0
5
muebel
One of the new features in Splunk 6.0+ is the capability of a forwarder assigning a timezone to an event in the situa...
by SplunkTrust SplunkTrust in Getting Data In 11-08-2016
0 3
0
3
splk5000
Seeking help with TIME_FORMAT in props.conf. I'm trying to get Splunk to recognize a time format in the form of "J...
by splk5000 New Member in Getting Data In 11-08-2016
0 6
0
6
ankithreddy777
In inputs.conf for monitor stanza, can we write regex? If so, /opt/splunk/cgate* matches (/opt/splunk/cgateee) or ...
by ankithreddy777 Contributor in Getting Data In 11-08-2016
0 2
0
2
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...
Top Solution Authors