Getting Data In

Getting Data In
Community Activity
michaeltay
I have a Splunk Enterprise indexer (v 6.5.0) that is forwarding Windows security events. Everything was going smooth...
by michaeltay Path Finder in Getting Data In 11-02-2016
0 2
0
2
ankithreddy777
I have to index the historic data along with real time data from the log file. May I know from which point the indexi...
by ankithreddy777 Contributor in Getting Data In 11-02-2016
0 3
0
3
saifuddin9122
Oct 20, 2016 11:49:56 PM UTC here is my time format and every event starts with with time. in my props.conf i had ...
by saifuddin9122 Path Finder in Getting Data In 11-02-2016
0 1
0
1
rfc360
I have in the input.conf as an example a scripted input on the server where the Splunk Universal Forwarder is install...
by rfc360 New Member in Getting Data In 11-02-2016
0 7
0
7
FritzWittwer_ol
I have a WMI Input defined on a universal forwarder and I get the following error while starting Splunk, and of cours...
by FritzWittwer_ol Contributor in Getting Data In 11-02-2016
0 3
0
3
j4adam
I've always been very careful in setting my indexes sizes to be something along the lines of 1.1* <peak indexed volu...
by j4adam Communicator in Getting Data In 11-02-2016
0 1
0
1
Lucas_K
I have already read this older thread on the subject -> : http://splunk-base.splunk.com/answers/5426/entire-file-cont...
by Lucas_K Motivator in Getting Data In 11-01-2016
3 9
3
9
alacercogitatus
I have written two Modular Inputs for Splunk. Both exhibit the same behavior. Steps to reproduce: Issue "splunk re...
by SplunkTrust SplunkTrust in Getting Data In 11-01-2016
0 10
0
10
sylim_splunk
We have configured large number of CloudWatch log groups as a separate input in our heavy forwarder. We have noticed ...
by sylim_splunk Splunk Employee Splunk Employee in Getting Data In 11-01-2016
1 2
1
2
myorkows
Would like the events to be split after ) --[End]--------------------$ (0x03000000:NameValue)urn:hl7-org:v2xml:Rem...
by myorkows Explorer in Getting Data In 11-01-2016
0 7
0
7
Deepali529
Hi, I am trying to find the subthread_count of logfiles of splunk on linux by command ps -eLo user=|sort|uniq -c > s...
by Deepali529 Explorer in Getting Data In 11-01-2016
0 1
0
1
JohnTelus
I have multiple forwarders and an indexer cluster. If the syslogs source devices were to send syslogs to both forward...
by JohnTelus New Member in Getting Data In 11-01-2016
0 3
0
3
ram_85
I want to display the payload with line breaks for better readability on Splunk Web. Splunk receives the payload a...
by ram_85 Explorer in Getting Data In 11-01-2016
0 4
0
4
rjthibod
I have a deployment server app that makes changes on the target client. Part of the process requires closing another ...
by rjthibod Champion in Getting Data In 11-01-2016
0 17
0
17
msboers
Hello Splunk community, Currently I am doing research as an intern at a government agency if their Windows services ...
by msboers Engager in Getting Data In 11-01-2016
0 6
0
6
wouterr
Hi, I am installing the universal forwarder (6.2) on redhat. I am running into several issues with the SSL setup. I ...
by wouterr Explorer in Getting Data In 11-01-2016
1 5
1
5
Michael
I have a small LAN with a couple dozen servers all running Solaris. They are sending into a single instance of Splunk...
by Michael Contributor in Getting Data In 10-31-2016
0 4
0
4
johnpof
We've recently locked down everything to use TLS 1.2 and I think i've fixed just about everything, however, my deploy...
by johnpof Path Finder in Getting Data In 10-30-2016
0 3
0
3
changux
Hi all. I have a set of logs without a timestamp field, so, this value is taken from "Current time" on each sourcety...
by changux Builder in Getting Data In 10-30-2016
0 14
0
14
Admiral_Marith
I'm seeing a sudden spike in data coming from our firewalls (edge and internal). On average an increase of 202% daily...
by Admiral_Marith Explorer in Getting Data In 10-29-2016
0 3
0
3
jrodman
I've been told that the copy-truncate pattern is a poor choice for log rotation, and that it should only be used when...
by jrodman Splunk Employee Splunk Employee in Getting Data In 10-29-2016
6 5
6
5
chris
We have a couple of files, that are rotated by copying and then truncating the original file (so no new inode is crea...
by chris Motivator in Getting Data In 10-29-2016
4 8
4
8
dbcase
Hi, We have a proxy server where multiple log files get uploaded. The average is about 15 million events per day. C...
by dbcase Motivator in Getting Data In 10-28-2016
0 4
0
4
sravankaripe
i have text file with some data below. how can i define my props.conf file with respective sourcetypes? file 1 of so...
by sravankaripe Communicator in Getting Data In 10-28-2016
0 2
0
2
kiran331
Hello I have to get only the selected events from Windows Security logs, so I have added the whitelist in inputs.con...
by kiran331 Builder in Getting Data In 10-28-2016
1 2
1
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...
Top Solution Authors