Getting Data In

Getting Data In
Community Activity
dmacndawk
I'm trying to install Splunk Universal Forwarder on Red Hat OS. I am getting stuck at this step. Before this command,...
by dmacndawk New Member in Getting Data In 11-09-2016
0 1
0
1
reggie_123
Hi, What will splunk behave like in the two following cases: 1) File A.log, having the lines: 1 2 3 ...
by reggie_123 Explorer in Getting Data In 11-09-2016
1 2
1
2
crazyeva
i am test '_tcp_routing' in my virtual machines, before doing that on online system. simply i add: [monitor://afile] ...
by crazyeva Contributor in Getting Data In 11-09-2016
0 1
0
1
ozirus
Hi, I've a universal forwarder on a Linux machine that forwards Security Onion logs to my Splunk instance. Logs are...
by ozirus Path Finder in Getting Data In 11-09-2016
0 4
0
4
rh990
You'll have to pardon the newbie question. I'm sure this is crazy easy, but I'm having the worst time figuring it out...
by rh990 Engager in Getting Data In 11-08-2016
0 5
0
5
muebel
One of the new features in Splunk 6.0+ is the capability of a forwarder assigning a timezone to an event in the situa...
by SplunkTrust SplunkTrust in Getting Data In 11-08-2016
0 3
0
3
splk5000
Seeking help with TIME_FORMAT in props.conf. I'm trying to get Splunk to recognize a time format in the form of "J...
by splk5000 New Member in Getting Data In 11-08-2016
0 6
0
6
ankithreddy777
In inputs.conf for monitor stanza, can we write regex? If so, /opt/splunk/cgate* matches (/opt/splunk/cgateee) or ...
by ankithreddy777 Contributor in Getting Data In 11-08-2016
0 2
0
2
yanivdutt
Hi, I am using below props file for CSV but data is not getting indexed or sent into Splunk. Need help in updating pr...
by yanivdutt Explorer in Getting Data In 11-08-2016
0 3
0
3
caitcait
I have the following string in the events and I would like to mask the password text using sedcmd. Content={"Login":...
by caitcait Explorer in Getting Data In 11-08-2016
0 2
0
2
nagarajugowdkal
Hi, What is the procedure to monitor changes to file content? As per knowledge we can add some parameters to props.c...
by nagarajugowdkal New Member in Getting Data In 11-07-2016
0 5
0
5
tmontney
I used the variable "$COMPUTERNAME" in my app's inputs.conf file. For all the PCs that got it, it's reporting their c...
by tmontney Builder in Getting Data In 11-07-2016
0 3
0
3
sravankaripe
Please help me with props.conf file i have sample data below i want to extract time stamp from the below sample data....
by sravankaripe Communicator in Getting Data In 11-07-2016
0 6
0
6
a212830
Hi, I'm looking at options for improving some reporting for a heavy feed from AD. Is INDEXED_EXTRACTIONS supported ...
by a212830 Champion in Getting Data In 11-07-2016
0 4
0
4
kearaspoor
I'm looking for an option to remove the automatic timestamp from the csv output filename attached to emails. Accordi...
by SplunkTrust SplunkTrust in Getting Data In 11-07-2016
0 3
0
3
Shark2112
Hey everyone. I read all nearest posts about timestamp and still can't make it work. So, i have events like this: ...
by Shark2112 Communicator in Getting Data In 11-07-2016
0 4
0
4
k_harini
I have a source file with multiple dates and timestamp as separate fields. I want to use last_changed and last_change...
by k_harini Communicator in Getting Data In 11-07-2016
0 2
0
2
sylbaea
My Splunk infrastructure (search head, indexer, etc.) is deployed on Windows servers. As for any other Windows serve...
by sylbaea Communicator in Getting Data In 11-07-2016
0 9
0
9
thezero
Hi Team, We are currently forwarding Windows logs to third party siem and logstash but there is problem. Looks like ...
by thezero Path Finder in Getting Data In 11-07-2016
0 4
0
4
Hemnaath
Hi All, I could this message into my Heavy Forwarder instance (Splunkd.log) I am not sure what is the problem why I a...
by Hemnaath Motivator in Getting Data In 11-07-2016
0 8
0
8
jwhathaway
I am trying to deploy apps from a *nix Deployment Server to a Windows client. When the app folders are pulled down, t...
by jwhathaway New Member in Getting Data In 11-06-2016
0 4
0
4
ctaf
Hello, In order to reduce Splunk Licence, I am considering to remove the timestamp from _raw but only after the time...
by ctaf Contributor in Getting Data In 11-06-2016
0 6
0
6
nravichandran
I am in the middle of understanding an already built environment and trying to figure out how a splunk universal forw...
by nravichandran Communicator in Getting Data In 11-05-2016
0 4
0
4
ayushchoudhary
I have configured transforms.conf and props.conf on below path /opt/splunk/etc/apps/search/local transforms.conf [...
by ayushchoudhary Path Finder in Getting Data In 11-05-2016
0 7
0
7
rf_aperez
Hi everyone ! Recently in my city, we've changed from summer to winter time and, of course, the server where Splunk...
by rf_aperez New Member in Getting Data In 11-05-2016
0 2
0
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...