Getting Data In

Getting Data In
Community Activity
Jarohnimo
Is it possible to set up Splunk with Just 1 Indexer, and 1 Search head? I began to attempt this through the Distribut...
by Jarohnimo Builder in Getting Data In 07-25-2016
0 8
0
8
lorenh
I am trying to set up a universal forwarder (Windows) to send data to our new Splunk Light trial account. I am follo...
by lorenh Explorer in Getting Data In 07-25-2016
0 6
0
6
saifuddin9122
Hello I am using DNS lists for load balancing. I am pointing my forwarders to send data to my DNS, but I was wonderi...
by saifuddin9122 Path Finder in Getting Data In 07-25-2016
0 10
0
10
saifuddin9122
a universal forwarder will request to resolve XXXXXX (DNS) and it may get an IP address of the indexer that is no lon...
by saifuddin9122 Path Finder in Getting Data In 07-25-2016
0 1
0
1
bvivi57
We use splunk to generate reports and provide them to an external application (Tableau). The data source are csv file...
by bvivi57 Observer in Getting Data In 07-25-2016
0 7
0
7
a212830
Hi, I am reading an Active Directory eventfeed, and it has an extensive blacklist (see below). Are these blacklists ...
by a212830 Champion in Getting Data In 07-25-2016
0 5
0
5
banderson7
We're bringing in syslog's from datapower units, and they have a rough log setup: Jul 22 09:00:20 10.214.8.104 [0x80...
by banderson7 Communicator in Getting Data In 07-25-2016
0 8
0
8
tmortiboy
I have some structured json logs that indicate some validation errors, and depending on the error, a different proper...
by tmortiboy New Member in Getting Data In 07-25-2016
0 1
0
1
jardakanian
Hi I am deploying Splunk in an environment and would like to capture as many security aspects from the SANS top 20 ...
by jardakanian New Member in Getting Data In 07-24-2016
0 1
0
1
Cuyose
from btools prop list run on search head. The events still break on dates within the events rather than the "--------...
by Cuyose Builder in Getting Data In 07-23-2016
0 9
0
9
andrewdidone
Hi. I have an Indexer/SearchHead/Deploy server sitting on one zone, and a Heavy Forwarder/Deploy server sitting on a...
by andrewdidone Path Finder in Getting Data In 07-23-2016
1 5
1
5
Jarohnimo
Always place your edits in local directors.  (Removed the question because it was confusing)
by Jarohnimo Builder in Getting Data In 07-23-2016
1 3
1
3
splunker9999
Hi, Is there a way we can upload all my saved search results to CSV file for scheduled search? Thanks
by splunker9999 Path Finder in Getting Data In 07-23-2016
1 4
1
4
Cuyose
What would a props/transform look like on an indexer that would append to the hostname field at index time based on t...
by Cuyose Builder in Getting Data In 07-23-2016
0 3
0
3
thompsonsgg
We have moved some of our jobs over to a NetApp configuration on a brand new server, but I cannot get the data forwar...
by thompsonsgg New Member in Getting Data In 07-22-2016
0 3
0
3
jphelps2011
I saw the new VMWare app ath .conf2011. When will it be available for download?
by jphelps2011 New Member in Getting Data In 07-22-2016
0 4
0
4
eosi
I am new to Splunk and can see previous post for filtering out Security logs. Please would anyone be able to help wit...
by eosi New Member in Getting Data In 07-22-2016
0 3
0
3
janderson19
Hello I'm having a problem with Windows Event logs coming into Splunk. Windows Events log every time that the Forwa...
by janderson19 Path Finder in Getting Data In 07-22-2016
2 5
2
5
mlindsey
I have about 1300 hosts configured with uni forwarders sending data to a single heavy forwarder. The heavy forwarder ...
by mlindsey Explorer in Getting Data In 07-22-2016
5 6
5
6
john_byun
I've installed a universal forwarder on a linux box and configured it, but I'm getting the following errors. I'm run...
by john_byun Path Finder in Getting Data In 07-22-2016
1 8
1
8
external_alien_
I have a folder monitored by Splunk where CSV files are uploaded and sucked into Splunk. Splunk reads them no sweat a...
by external_alien_ Explorer in Getting Data In 07-22-2016
1 3
1
3
GGMJhgitR
Hello Community, My Problem: I have a Dashboard, where I want to parse multiple default or initial Values to a Text...
by GGMJhgitR New Member in Getting Data In 07-22-2016
0 2
0
2
ebaileytu
I need to retain data for 6 months with 400 GB of data max in warm and 5 tb in cold. Will the below work? I am confus...
by ebaileytu Communicator in Getting Data In 07-22-2016
0 4
0
4
srmohan
We would like to enable frozenTimePeriodInSecs and enableTsidxReduction = true with timePeriodInSecBeforeTsidxReducti...
by srmohan New Member in Getting Data In 07-21-2016
0 1
0
1
blakezinc
Hi, I'm new to splunk, and I know there have been a thousand questions on extracting timestamps out of filenames, and...
by blakezinc Engager in Getting Data In 07-21-2016
2 4
2
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors