| Thread Info | |||||
|---|---|---|---|---|---|
| 
        http event data is not received at index
   
  though in the log it says HttpInputDataHandler - handled token name=xy...
        
         
           by 
           
                
                    
                        palyogit
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               07-16-2025
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi Splunkers,
  I'm having issues ingesting Windows DNS Server Analytical logs. What's strange is that I am able to p...
        
         
           by 
           
                
                    
                        vulnfree
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               01-20-2021
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Good morning All,
  I have been trying to figure out how can I create a data input on a heavy forwarder to forward da...
        
         
           by 
           
                
                    
                        BoscoBaracus
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-17-2025
             
           
         
        | 
		
		0
   | 
	  
	  12
	 | |||
| 
        I would greatly appreciate support for customer model as a correlation search option in the VT4splunk app.
        
         
           by 
           
                
                    
                        ez-secops-awn
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-14-2025
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi everyone!
  Quick question. I would like to know how can I send data to an index using a python script.
  We need ...
        
         
           by 
           
                
                    
                        MatheoCaneva1
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-15-2025
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I need to onboard Cisco Catalyst 8500 router logs into Splunk. When I was looking for addons, I found the below addon...
        
         
           by 
           
                
                    
                        dm1
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               07-16-2025
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        [monitor://\\njros1bva0597\d$\LogFiles\warcraft-9.0.71\logs\*]
disabled = false
host = NJROS1BVA0621
alwaysOpenFile =...
        
         
           by 
           
                
                    
                        Cheng2Ready
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               07-15-2025
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Trying to filter out all perfmon data using ingest actions. so, i try and see the samples and i get this error 
  
  ...
        
         
           by 
           
                
                    
                        tbarn005
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-10-2025
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        Hi Splunk Gurus, 
  I’m working on a script to programmatically check if logs from a specific host are available in S...
        
         
           by 
           
                
                    
                        asah
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-16-2025
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I'm cloning the event and before cloning  extracting sourcetype to use later.
  
   transforms.conf [copy_original_so...
        
         
           by 
           
                
                    
                        sudha_krish
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-15-2025
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Currently I have setup Splunkstream, but there is a condition where I want to disable some data sources from certain ...
        
         
           by 
           
                
                    
                        elend
                    
                
           
             
             
               Communicator
             
           
           in
           Getting Data In
           
           
              
               07-14-2025
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Configuring Internal Log Forwarding 
  1- 1sh 2 indx 2 if and 4 uf 1 mc
  2- I can see only idx internal logs though ...
        
         
           by 
           
                
                    
                        Mirza_Jaffar1
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Getting Data In
           
           
              
               07-14-2025
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I want to provide a standard Splunk user the ability to upload files via the web UI.Specifically, so that members of ...
        
         
           by 
           
                
                    
                        nickhills
                    
                
           
             
             
               Ultra Champion
             
           
           in
           Getting Data In
           
           
              
               07-14-2025
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have created a pipeline for filtering data coming into the sourcetype = fortigate_traffic.I would like to further a...
        
         
           by 
           
                
                    
                        Rani2
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Getting Data In
           
           
              
               07-09-2025
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Does anyone have a cheat sheet for btool to help newbies?
  Here is my version of btool cheat sheet:
   
  
   splunk...
        
         
           by 
           
                
                    
                        youngsuh
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               08-19-2020
             
           
         
        | 
		
		1
   | 
	  
	  8
	 | |||
| 
        Hi,
  We’re currently facing a load imbalance issue in our Splunk deployment and would appreciate any advice or best ...
        
         
           by 
           
                
                    
                        mcfabrero_acn
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-11-2025
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Dear splunk community,
  After successfully implementing the input from 
   @afx :
  "How to Splunk the SAP Security ...
        
         
           by 
           
                
                    
                        SPLAUR
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-07-2025
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        The Splunk app for Linux already provided a stanza for collecting all the .log files in the /var/log folder ([monitor...
        
         
           by 
           
                
                    
                        Na_Kang_Lim
                    
                
           
             
             
               Path Finder
             
           
           in
           Getting Data In
           
           
              
               07-10-2025
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
         
  Hi Splunk Community,
  I’m trying to reduce disk space usage on my Splunk Universal Forwarder by filtering out un...
        
         
           by 
           
                
                    
                        tbarn005
                    
                
           
             
             
               Engager
             
           
           in
           Getting Data In
           
           
              
               07-03-2025
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I feed data to Splunk using the HTTP Event Collector, sample event:
  {<!-- -->
  "event":{<!-- -->
  "event_id": "58512040",
  "even...
        
         
           by 
           
                
                    
                        mmaaxx
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               07-09-2025
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Guys i have Splunk Cloud , i created Http Event Collector & in prisma i gave url /service/collector
   
  but logs ar...
        
         
           by 
           
                
                    
                        XOR
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Getting Data In
           
           
              
               07-08-2025
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        When collecting Linux logs using a Universal Forwarder we are collecting a lot of unnecessary audit log from cronjobs...
        
         
           by 
           
                
                    
                        fatsug
                    
                
           
             
             
               Builder
             
           
           in
           Getting Data In
           
           
              
               07-08-2025
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi,
  I am running splunk standalone 8.4.1 with Citrix add-on installed 8.2.3.  Also, I have SC4S running version 3.3...
        
         
           by 
           
                
                    
                        corti77
                    
                
           
             
             
               Contributor
             
           
           in
           Getting Data In
           
           
              
               05-08-2025
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I'm getting duplicated data when using lambda function to send events from cloudwatch to splunk through HTTP Event Co...
        
         
           by 
           
                
                    
                        wsmworkhard
                    
                
           
             
             
               Explorer
             
           
           in
           Getting Data In
           
           
              
               05-06-2019
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        We are getting the following error when trying to ingest EXO mail logs into splunk using the add-in.
  line 151, in _...
        
         
           by 
           
                
                    
                        TestAdminHorst
                    
                
           
             
             
               New Member
             
           
           in
           Getting Data In
           
           
              
               07-02-2025
             
           
         
        | 
		
		0
   | 
	  
	  2
	 |