Getting Data In

Getting Data In
Community Activity
vinceskahan
We're trying to find a way to have the universal forwarder send data to the indexer essentially pre-marked with a sma...
by vinceskahan Path Finder in Getting Data In 03-01-2016
2 4
2
4
vinceskahan
I'm totally lost trying to decipher the impossibly dense abstract documentation here. I need to do something that I...
by vinceskahan Path Finder in Getting Data In 03-01-2016
0 5
0
5
koshyk
hi folks, We have an issue with our cold database filesystem and the estimate to bring it back is around 10 days. S...
by koshyk Super Champion in Getting Data In 03-01-2016
0 3
0
3
sunnyparmar
Hi, Could anyone please tell me that what is needed on the universal forwarder side to enable deployment server func...
by sunnyparmar Communicator in Getting Data In 03-01-2016
0 1
0
1
LewisWheeler
I have the following error message appearing every ~3 seconds. My searches have not yielded anyone who has this issue...
by LewisWheeler Communicator in Getting Data In 03-01-2016
1 5
1
5
nlspears01
Hi, I have Splunk monitoring a Kiwi log files of syslog data. The problem I am having is the the source of the data...
by nlspears01 Engager in Getting Data In 02-29-2016
1 10
1
10
hcipartners
I have Splunk Enterprise on an AWS EC2 Server, and need to install forwarders on two other EC2 Instances. Can someon...
by hcipartners Engager in Getting Data In 02-29-2016
1 2
1
2
babcolee
We have a condition where we need to filter out data based on the byte count in the log. We have collapsed the source...
by babcolee Path Finder in Getting Data In 02-29-2016
0 4
0
4
Nesrinepfe
Hi, I would like to know the environment to install in case I use Splunk Enterprise (Trial version). I just want to ...
by Nesrinepfe Path Finder in Getting Data In 02-29-2016
0 2
0
2
lycollicott
First off, let me say that we do not have plans to purchase the VMware app. I would like to be able to identify any ...
by lycollicott Motivator in Getting Data In 02-29-2016
0 1
0
1
sbattista09
I see a lot of documentation for black listing by index name in outputs.conf, but I am a bit confused as to the varia...
by sbattista09 Contributor in Getting Data In 02-29-2016
0 5
0
5
bowesmana
I've read through a number of answers, but none quite gives what I want. I have daily tests that run and my dashboa...
by SplunkTrust SplunkTrust in Getting Data In 02-29-2016
0 4
0
4
splunkIT
We are using Hunk with MapR. There is a dispatch directory that Hunk uses for the reduce of the map reduce. /mapr/tmp...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 02-26-2016
0 3
0
3
adamblock2
I am interested in forwarding syslog and Windows events from a DMZ to Indexers which reside inside our network. We a...
by adamblock2 Path Finder in Getting Data In 02-26-2016
0 4
0
4
kellihall
Each user can have two values of type: movement and check-in. There are some users that only have movement and never...
by kellihall New Member in Getting Data In 02-26-2016
0 1
0
1
ahmedhassanean
Dears, May I know please if it's possible to have a setup in which I will have only two machines: one of them will a...
by ahmedhassanean Explorer in Getting Data In 02-26-2016
0 1
0
1
michaelslab
All, The documentation is scattered in various places and not one place. Help. This should be simple and not ha...
by michaelslab New Member in Getting Data In 02-25-2016
0 6
0
6
w531t4
All -- I'm seeking any advice I can get at this point. A little background. I manage two different user communities ...
by w531t4 Path Finder in Getting Data In 02-25-2016
0 5
0
5
patrickcope
How to search a list of forwarders sending data to a single index or multiple indexes? ie: forwarder (A) sending to ...
by patrickcope New Member in Getting Data In 02-25-2016
0 1
0
1
kalianov
I need to monitor file changes and I want to know which changes were made. inputs.conf [fschange:///etc/passwd] d...
by kalianov Path Finder in Getting Data In 02-25-2016
0 1
0
1
athorat
Is there a way to restrict this search with upper case and lower case scenarios? index=aap_prod sourcetype="HDP:PROD...
by athorat Communicator in Getting Data In 02-25-2016
0 1
0
1
gozulin
The indexer pauses indexing when free space goes under 5GB on the main partition. This is caused by too many warm buc...
by gozulin Communicator in Getting Data In 02-25-2016
0 6
0
6
JKnightSplunk
Hi all, I'm looking to add some custom fields to the Splunk Forwarder, but am struggling to find the a way of achiev...
by JKnightSplunk Engager in Getting Data In 02-25-2016
0 3
0
3
sbattista09
I keep getting the "minimum free disk space (5000MB) reached for /var/run/splunk/dispatch" on one of my heavy forward...
by sbattista09 Contributor in Getting Data In 02-25-2016
0 2
0
2
Abilan1
Hi , We are about to reach the maximum size of the disk on our Indexer server. Please suggest if there is any way to...
by Abilan1 Path Finder in Getting Data In 02-25-2016
0 7
0
7
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...