Getting Data In

Getting Data In
Community Activity
larryliang
We have four AWS accounts to host different development environments: Dev -> Tst -> Stg -> Prod Requirements: We wan...
by larryliang New Member in Getting Data In 01-27-2016
0 1
0
1
akshatj2
Hi All, I need to install a Universal forwarder in our environment, but due to strict policies, we cannot give the u...
by akshatj2 Path Finder in Getting Data In 01-27-2016
0 6
0
6
brian_meyer
I've been pulling my hair out on this one for weeks and I'm finally to the point where I need a sanity check. I'm ju...
by brian_meyer Explorer in Getting Data In 01-27-2016
0 1
0
1
vasanthmss
Hi splunkers I've configured 3rd party ssl between indexer and h.f. indexer 9997 open for tcp, 9996 for ssl. I've co...
by vasanthmss Motivator in Getting Data In 01-26-2016
1 1
1
1
matthewjohnson
I'm trying to set up the Splunk for A10 Networks app. It expects syslog data on UDP port 514. My data is collecte...
by matthewjohnson Explorer in Getting Data In 01-26-2016
0 7
0
7
horsefez
Hello fellow splunkers! I'm about to set up an universal forwarder monitoring a specific path on a server. On this s...
by horsefez Motivator in Getting Data In 01-26-2016
0 2
0
2
sideview
I maintain an app with a data input wizard, under the hood of which is a custom controller that can list and create ...
by SplunkTrust SplunkTrust in Getting Data In 01-26-2016
1 10
1
10
sbattista09
What stanza do i set in the Universal Forwarder to send data to the indexers from a folder path? I want to send ou...
by sbattista09 Contributor in Getting Data In 01-26-2016
0 6
0
6
renems
I'm struggling getting my data to break to events. A REST call gives me a csv in a long straight line, without any ch...
by renems Communicator in Getting Data In 01-26-2016
0 6
0
6
jonym4
Some background: So we are having some problems in our environment, we have a cluster of indexers and some of the se...
by jonym4 Explorer in Getting Data In 01-26-2016
0 10
0
10
Ricapar
I originally had this in my indexes.conf file: [myindex] homePath = $SPLUNK_DB/myindex/db coldPath = $SPLUNK_DB/myin...
by Ricapar Communicator in Getting Data In 01-25-2016
0 2
0
2
raby1996
Hi all, I have a field that i am calling "code_load_date" and I am running a stats command that groups them by associ...
by raby1996 Path Finder in Getting Data In 01-25-2016
0 2
0
2
JScordo
I currently have a syslog server forwarding data to our splunk instance. I wanted to know if there were any searches...
by JScordo Path Finder in Getting Data In 01-25-2016
0 1
0
1
thisissplunk
Basically, I want to have ONE log file populating TWO sourcetypes at the same time. Identical events in both. Eventua...
by thisissplunk Builder in Getting Data In 01-24-2016
0 1
0
1
Alan_Bradley
How can you differentiate between a forwarder being down and a forwarder not having any data to send ? i.e is there a...
by Alan_Bradley Path Finder in Getting Data In 01-22-2016
5 6
5
6
usd0872
I have the following requirement: <ul> <li> send WinEventLog://Application , except for one specific EventCode to one...
by usd0872 Path Finder in Getting Data In 01-22-2016
1 1
1
1
mcrawford44
As the question above states; Since the 6.2.1 update of Splunk, our active directory inputs are no longer gathering ...
by mcrawford44 Communicator in Getting Data In 01-22-2016
2 2
2
2
michael_sleep
I've been messing about with this for a while now and I can't seem to figure out the rhyme or reason behind how wildc...
by michael_sleep Communicator in Getting Data In 01-22-2016
0 5
0
5
shmoman
Any idea as to what causes this error: 02-19-2014 17:17:01.577 -0500 ERROR ScriptRunner - extern write error: errno=...
by shmoman Engager in Getting Data In 01-22-2016
1 1
1
1
uktechnologyser
Complete newbie to Splunk, have just setup a distributed search structure (1 deployment server, 1 search head, 2 inde...
by uktechnologyser Path Finder in Getting Data In 01-22-2016
0 3
0
3
xrtan
Here is my setup on my Heavy Forwarder inputs.conf [udp://:514] sourcetype = syslog connection_host = ip disabled ...
by xrtan Explorer in Getting Data In 01-22-2016
0 5
0
5
shankarananthth
Hi, my splunk log is falling as charlotte time. when people from dubai or London or Denver viewwing the report. Rep...
by shankarananthth Explorer in Getting Data In 01-22-2016
0 3
0
3
tweaktubbie
I have an issue with two servers with WebSphere logs that have an overriding different timezone setting in the jvm. O...
by tweaktubbie Communicator in Getting Data In 01-22-2016
0 2
0
2
msantich
hello We have a Linux server running Splunk forwarder which forwards to one of two heavy forwarders in an autolb co...
by msantich Path Finder in Getting Data In 01-22-2016
0 4
0
4
a212830
Hi, I have a Splunk Universal Forwarder running on Windows 2012, monitoring a bunch of files in different folders. ...
by a212830 Champion in Getting Data In 01-21-2016
0 4
0
4
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...
Top Solution Authors