Getting Data In

Getting Data In
Community Activity
ahmedhassanean
Dears, May I know please if it's possible to have a setup in which I will have only two machines: one of them will a...
by ahmedhassanean Explorer in Getting Data In 02-26-2016
0 1
0
1
michaelslab
All, The documentation is scattered in various places and not one place. Help. This should be simple and not ha...
by michaelslab New Member in Getting Data In 02-25-2016
0 6
0
6
w531t4
All -- I'm seeking any advice I can get at this point. A little background. I manage two different user communities ...
by w531t4 Path Finder in Getting Data In 02-25-2016
0 5
0
5
patrickcope
How to search a list of forwarders sending data to a single index or multiple indexes? ie: forwarder (A) sending to ...
by patrickcope New Member in Getting Data In 02-25-2016
0 1
0
1
kalianov
I need to monitor file changes and I want to know which changes were made. inputs.conf [fschange:///etc/passwd] d...
by kalianov Path Finder in Getting Data In 02-25-2016
0 1
0
1
athorat
Is there a way to restrict this search with upper case and lower case scenarios? index=aap_prod sourcetype="HDP:PROD...
by athorat Communicator in Getting Data In 02-25-2016
0 1
0
1
gozulin
The indexer pauses indexing when free space goes under 5GB on the main partition. This is caused by too many warm buc...
by gozulin Communicator in Getting Data In 02-25-2016
0 6
0
6
JKnightSplunk
Hi all, I'm looking to add some custom fields to the Splunk Forwarder, but am struggling to find the a way of achiev...
by JKnightSplunk Engager in Getting Data In 02-25-2016
0 3
0
3
sbattista09
I keep getting the "minimum free disk space (5000MB) reached for /var/run/splunk/dispatch" on one of my heavy forward...
by sbattista09 Contributor in Getting Data In 02-25-2016
0 2
0
2
Abilan1
Hi , We are about to reach the maximum size of the disk on our Indexer server. Please suggest if there is any way to...
by Abilan1 Path Finder in Getting Data In 02-25-2016
0 7
0
7
mahesh_ravji1
Hi. I have a requirement to route events to index based on the fields host, sourcetype, and index. Field host form...
by mahesh_ravji1 Explorer in Getting Data In 02-25-2016
1 5
1
5
hastrike
We are wanting to modify our Splunk forwarders on workstations to look at other log files and I am curious how to go ...
by hastrike New Member in Getting Data In 02-25-2016
0 10
0
10
arbabnazar
Hi, Can I enable the SSL for the universal forwarder that will access it through the public ip, but not the forwarde...
by arbabnazar New Member in Getting Data In 02-24-2016
0 1
0
1
mataharry
I have Linux servers with Splunk, and the process monit to check my processed. But sometimes I see an issue where mo...
by mataharry Communicator in Getting Data In 02-24-2016
2 2
2
2
apro
Hi, Currently I have a splunk server receiving logs from few servers. I will like to do a search that is scheduled ...
by apro Path Finder in Getting Data In 02-24-2016
0 7
0
7
JdeFalconr
If an input is specified identically in the inputs.conf file of multiple apps running on a Universal forwarder, will ...
by JdeFalconr Explorer in Getting Data In 02-24-2016
0 2
0
2
splunkn
I have made the following changes in my inputs.conf. However no luck Could anyone help me with this? [WinEventLog:S...
by splunkn Communicator in Getting Data In 02-24-2016
0 5
0
5
Hung_Nguyen
Hi, I have multiple queries that I use to do daily report on errors in our production Splunk. I would like to filte...
by Hung_Nguyen Path Finder in Getting Data In 02-24-2016
0 7
0
7
dsmc_adv
We have configured a default null queue to discard all events that we don't want to allow to be indexed without autho...
by dsmc_adv Path Finder in Getting Data In 02-24-2016
0 3
0
3
avisram
Hi there, I've been tasked with building a Splunk Enterprise 6.3 multisite virtual environment sandbox. The environ...
by avisram Path Finder in Getting Data In 02-24-2016
0 3
0
3
hettervik
Hi folks! I've made a search that returns all hosts that sends events of some kind to indexer, but does not send int...
by SplunkTrust SplunkTrust in Getting Data In 02-24-2016
0 7
0
7
thezero
Hi Team, We need to drop _internal logs forwarded by universal forwarders as _internal logs are consuming most of th...
by thezero Path Finder in Getting Data In 02-24-2016
0 4
0
4
Hajime
I think the precedence for "SEDCMD" attribute within single stanza is ASCII order. For example props.conf: [foo] SE...
by Hajime Path Finder in Getting Data In 02-23-2016
0 4
0
4
dwin02
Hi Splunk Support, When activating the Performance Monitoring in inputs.conf, I was able to send free disk space to ...
by dwin02 Explorer in Getting Data In 02-23-2016
0 3
0
3
earakam
Hi, I was monitoring Universal Forwarder's CPU usage with the environment below, and I put 13GB sized file on Unive...
by earakam Path Finder in Getting Data In 02-23-2016
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors