Getting Data In

Getting Data In
Community Activity
lsparrow
Hello! I was wondering how to use a directory name (segment) as an event tag. For example: C:\bin\code\python\test_...
by lsparrow New Member in Getting Data In 04-11-2016
0 1
0
1
brod_geico
Im getting below error on my heavy forwarder logs, 6 indexers are connect that HF , 4 indexers are working fine. Only...
by brod_geico Path Finder in Getting Data In 04-11-2016
0 3
0
3
michael_sleep
Hey there, We have a distributed Splunk environment... so, we have universal forwarders sending data to a heavy for...
by michael_sleep Communicator in Getting Data In 04-11-2016
0 1
0
1
svercelli
In my new data set, the time comes in the format 1652 as it relates to 4:52pm. However, when it is before 1AM it come...
by svercelli Path Finder in Getting Data In 04-11-2016
0 1
0
1
pnv2254
Is there a process I can use with Splunk to pull audit logs on how, who, when, and where directories are being create...
by pnv2254 New Member in Getting Data In 04-11-2016
0 2
0
2
Monica7
Hi, I have installed Splunk light in Windows and in Linux server also. I have installed a universal forwarder in the...
by Monica7 New Member in Getting Data In 04-11-2016
0 1
0
1
andig2
I have Splunk Light on Windows and the Universal Forwarder on Raspberry. According to docs, I need to create a server...
by andig2 Engager in Getting Data In 04-11-2016
0 2
0
2
kpavan
Hi All, I need to collect the logs from a Windows machine into Splunk without installing any agent (universal forwar...
by kpavan Path Finder in Getting Data In 04-11-2016
0 5
0
5
trflesher
“I am working with a customer who is a licensed and valid support contract holder with Splunk. They are currently run...
by trflesher Explorer in Getting Data In 04-11-2016
0 13
0
13
dlogvinenko
Is it even possible to configure Windows Event Logs through command line? PS C:\Program Files\SplunkUniversalForwar...
by dlogvinenko Engager in Getting Data In 04-11-2016
0 1
0
1
itsomana
Hi I would like to find out how I can "strip out" events from a input file before they reach the splunk indexer. I...
by itsomana Path Finder in Getting Data In 04-09-2016
3 6
3
6
Maite35
Hello, I am using FIELD_DELIMITER=; and am working on data that use commas instead of decimals. I want to use a SED ...
by Maite35 Explorer in Getting Data In 04-09-2016
1 11
1
11
Brolly75
I have had a host go down in aws that was not recoverable a few weeks ago and the universal forwarder is still showin...
by Brolly75 New Member in Getting Data In 04-09-2016
0 1
0
1
lisaac
I have a monitor that that isn't working. I turned debug on in log.cfg, and the Universal Forwarder reports no match ...
by lisaac Path Finder in Getting Data In 04-08-2016
0 1
0
1
belljar1
Hey, I am a total Splunk Noob. I am trying out Splunk Light. I can successfully import a file, but I cannot get sp...
by belljar1 New Member in Getting Data In 04-08-2016
0 4
0
4
henrym22
I have an index "main" and several sources associated with this index. The size limit of the index has been reach (15...
by henrym22 New Member in Getting Data In 04-08-2016
0 4
0
4
JeremyHagan
Hi, If I have multiple matching TZ references in my props.conf on my indexer which one does it use? Is it just the o...
by JeremyHagan Communicator in Getting Data In 04-07-2016
0 2
0
2
steadph
Hi, Splunk FSchange is deprecated. Is there another way to replicate information of what fschange does? I wan to sh...
by steadph New Member in Getting Data In 04-07-2016
0 2
0
2
abonuccelli_spl
Hi, I've mounted some NFS and nfs locally to Splunk some files I want to monitor remotely. Problem is files are con...
by abonuccelli_spl Splunk Employee Splunk Employee in Getting Data In 04-07-2016
0 2
0
2
a548506
Here is my outputs.conf : [tcpout] server=myserver.com:9997 Not sure, why we are receiving this error when we have...
by a548506 Path Finder in Getting Data In 04-07-2016
0 3
0
3
DaveyMeth
I have installed the forwarder in /opt/splunkforwarder and run the splunk start command. I get the license to read/...
by DaveyMeth Engager in Getting Data In 04-07-2016
1 4
1
4
splunkfly
I'm new to the Splunk tool. I heard very good feedback about Splunk and I want to implement in our company. I want to...
by splunkfly New Member in Getting Data In 04-07-2016
0 2
0
2
sysadm43
As unix support staff drafted to be an inexperienced Splunk support staffer, I hope I can appeal to someone who knows...
by sysadm43 New Member in Getting Data In 04-07-2016
0 3
0
3
tsunamii
Hi Splunkers, Is there a way to disable a search peer via the CLI or an API call? Specifically, I would like to s...
by tsunamii Path Finder in Getting Data In 04-07-2016
0 1
0
1
dmacgillivray
Hello Splunkers, I have a timestamp below that does not seem to want to get recognized / converted properly by Splun...
by dmacgillivray Communicator in Getting Data In 04-07-2016
0 2
0
2
Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...
Top Solution Authors