Getting Data In

Getting Data In
Community Activity
mmensch
Hi, I understand that best practice is to install a universal forwarder on a server and send the logs directly to a...
by mmensch Path Finder in Getting Data In 05-16-2016
0 1
0
1
BlakeDC
ComputerTarget=EDITED; NeededCount=31; DownloadedCount=0; NotApplicableCount=82225; NotInstalledCount=31; InstalledCo...
by BlakeDC New Member in Getting Data In 05-16-2016
0 5
0
5
kpers
For some time now I have been using Splunk to log all the basic Windows event logs such as App, Security, Setup, Syst...
by kpers Path Finder in Getting Data In 05-16-2016
0 1
0
1
working_dog
At the indexer, I am trying to exclude event records from incoming windows logs that have Logon Type=3. Below is the...
by working_dog Explorer in Getting Data In 05-15-2016
1 5
1
5
unclesvenno
Sorry... total numbnut here... not much experience with *nix commands I'm sorry. I want to download the Universal Fo...
by unclesvenno Engager in Getting Data In 05-15-2016
0 5
0
5
daniel333
All, Just reading: http://blogs.splunk.com/2016/05/05/high-performance-syslogging-for-splunk-using-syslog-ng-part-1...
by daniel333 Builder in Getting Data In 05-14-2016
0 1
0
1
mkallies
Complex question here. I have the following set up: Universal forwarder[20G rotating file] -> Heavy Forwarder[props...
by mkallies Path Finder in Getting Data In 05-13-2016
0 2
0
2
msantich
Hello, our splunkforwarders are configured to pull in certain logs from various clients with a "[monitor://]" entry i...
by msantich Path Finder in Getting Data In 05-13-2016
0 3
0
3
rupeshhiremath
Hi, I am using Python SDK to perform search and get results. With below code I am able to see records in OrderedDic...
by rupeshhiremath Explorer in Getting Data In 05-13-2016
1 1
1
1
adamblock2
I am interested in configuring a universal forwarder on a syslog server, and have a question regarding how the log da...
by adamblock2 Path Finder in Getting Data In 05-13-2016
0 1
0
1
seksit
Hi I have 2 sourcetypes: websense_ss and pan:traffic. I want to correlate these 2 sourcetypes with timestamp and IP...
by seksit Explorer in Getting Data In 05-13-2016
0 1
0
1
gomuli100
Hi everyone, I would like to ask if there is an option to collect logs from a table I created in a SQL server in Spl...
by gomuli100 New Member in Getting Data In 05-13-2016
0 2
0
2
rchiii
Is there a way to use a file instead of entering ip's when wanting to exclude ranges of ip's from a search, such as N...
by rchiii New Member in Getting Data In 05-12-2016
0 1
0
1
rc0rning
I'm trying to understand if i can move raw data directly into splunk without any indexing
by rc0rning New Member in Getting Data In 05-12-2016
0 8
0
8
vil505
Is there a general way for me to use the text input in a form to filter it down to the top users, depending on the nu...
by vil505 Explorer in Getting Data In 05-12-2016
0 3
0
3
dhavamanis
Need your help, We are trying to increase the number of indexer nodes in the indexer cluster for max availability ap...
by dhavamanis Builder in Getting Data In 05-12-2016
0 1
0
1
OMohi
I am getting the following error message from inputs directing from splunk forwarder instance to indexer: 13:01:22.5...
by OMohi Path Finder in Getting Data In 05-12-2016
0 6
0
6
cannarella
We are trying to capture failed logons from our AD server but only want to capture specific event logs. We are using...
by cannarella Engager in Getting Data In 05-12-2016
3 11
3
11
JoanHorikawa
I have a server class (wineventlog) that has a whitelist in the inputs.conf. It looks like this: [WinEventLog://Secu...
by JoanHorikawa New Member in Getting Data In 05-12-2016
0 5
0
5
tlabue
When I startup Splunk (v6.3.0 for Linux), I've notices warning message when Splunk is Checking conf files for problem...
by tlabue Path Finder in Getting Data In 05-12-2016
0 5
0
5
att35
Hi, I am planning to install Splunk app for Rapid7 Nexpose. We use Nexpose Enterprise edition. While checking the ap...
by att35 Builder in Getting Data In 05-12-2016
0 2
0
2
agneticdk
Hi all I have a search like this: index=\* earliest=+1m latest=+30h sourcetype="WinEventLog:Sys*" Message=\*Upgrade...
by agneticdk Path Finder in Getting Data In 05-11-2016
0 2
0
2
hemendralodhi
Hi Team, We are planning to migrate our existing indexed data to a new Enterprise Server which is up and running, se...
by hemendralodhi Contributor in Getting Data In 05-11-2016
0 4
0
4
bbeavise2g
Not so much a question, but an observation looking for confirmation. If true, looking to spread the word. Recently ...
by bbeavise2g Explorer in Getting Data In 05-11-2016
1 1
1
1
lemmerich
Hello guys, I am new to splunk and I am trying to input data from a perl script. Script is very simple, a helloworld...
by lemmerich Engager in Getting Data In 05-11-2016
2 1
2
1
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors