Getting Data In

Getting Data In
Community Activity
ageorgiou
Hi, I've got a universal forwarder and I'm trying to monitor C:\Windows\System32\winevt\Logs. I've tried 2 solutions...
by ageorgiou Explorer in Getting Data In 11-25-2015
0 5
0
5
cam343
Hello, Trying to import a CSV with dates going back 50+ years (https://www.quandl.com/api/v3/datasets/BCB/UDJIAD1.csv...
by cam343 Path Finder in Getting Data In 11-25-2015
0 2
0
2
nibinabr
I had set the value of time_before_close attribute to 300 (5 mins) in one of my monitor stanzas. What I observed is t...
by nibinabr Communicator in Getting Data In 11-25-2015
0 1
0
1
imanpoeiri
Hi Experts, I dont want to wake up any zombies, hence I create new thread here. I have props.conf file works on my...
by imanpoeiri Communicator in Getting Data In 11-24-2015
0 8
0
8
lycollicott
My 6.3.1 inputs.conf is: [monitor://E:\Tomcat-instance1\logs] index=instance1_appl sourcetype=tomcat-appl ignoreolde...
by lycollicott Motivator in Getting Data In 11-24-2015
0 1
0
1
_dave_b
Hi. I just installed Splunk Enterprise 6.3 on a VM running Windows Server 2012. The install went fine, but when I...
by _dave_b Communicator in Getting Data In 11-24-2015
0 3
0
3
kearaspoor
I have an ldapsearch that is successfully retrieving multiple AD attributes including the whenCreated attribute. Unf...
by SplunkTrust SplunkTrust in Getting Data In 11-24-2015
0 4
0
4
lukasz92
Hi, I have complex events in files forwarded from Windows hosts with Universal Forwarders. These files are zip-compr...
by lukasz92 Communicator in Getting Data In 11-24-2015
0 5
0
5
lloydknight
Well, this is technically a Unix question but still asked it here since it involves with Splunk. I already installed...
by lloydknight Builder in Getting Data In 11-24-2015
0 2
0
2
proylea
I have a particular log file that for some reason, the forwarder will not read and send the data to the indexer. I se...
by proylea Contributor in Getting Data In 11-23-2015
0 5
0
5
ahmedhassanean
Dears, i have configured scripted input that poll snmp of network devices using snmpwalk command but problem that w...
by ahmedhassanean Explorer in Getting Data In 11-23-2015
0 1
0
1
jasonhebron
We are running SPLUNK 6.1.4. We have a server with a REST API feed which every so often stops processing. To start it...
by jasonhebron New Member in Getting Data In 11-22-2015
0 1
0
1
mdinkins
I have a group of hosts that use the blacklist function in a monitor stanza in inputs.conf. Here is the referenced st...
by mdinkins Engager in Getting Data In 11-21-2015
0 1
0
1
mkemmerer
I need to add an additional line break to events at the heavy forwarder. I'm trying to use transforms.conf: [add_lin...
by mkemmerer Explorer in Getting Data In 11-20-2015
0 1
0
1
SirHill17
Hi, I would like to remove data from an index when the file read is renamed. I have a file (prog.log.run) which con...
by SirHill17 Communicator in Getting Data In 11-20-2015
0 1
0
1
splunker12er
I am forwarding data from heavy-forwarder (HF-1) to heavy-forwarder(HF-2) which are in different network IP range. E...
by splunker12er Motivator in Getting Data In 11-20-2015
0 1
0
1
gcusello
I acquired some logs from a scrip (close to ps.sh) with a timestamp correctly recognized at index time. The problem i...
by SplunkTrust SplunkTrust in Getting Data In 11-20-2015
0 2
0
2
jwalzerpitt
I configured the following: 1) Malwarebytes syslog configured to send syslog to Splunk server 2) Configured rsyslog....
by jwalzerpitt Influencer in Getting Data In 11-20-2015
0 2
0
2
hylam
Will it break anything? Will it violate any certificates? I guess index=_internal will probably show a new machine fo...
by hylam Contributor in Getting Data In 11-20-2015
0 1
0
1
omuelle1
HI, I think this is a rather silly question, but I haven't been working with Splunk for too long and just can't figu...
by omuelle1 Communicator in Getting Data In 11-19-2015
1 4
1
4
estepgi
Hi. Just installed Splunk for the first time today. As a tes,t I took a CSV file and indexed it, and it worked fi...
by estepgi New Member in Getting Data In 11-19-2015
0 2
0
2
stevepraz
I recently upgraded Splunk to 6.3. Our environment has 1 search head, 2 indexers and 1 deployment/licensing server a...
by stevepraz Path Finder in Getting Data In 11-19-2015
2 1
2
1
chris_brown_ral
For Windows event-log events, Splunk displays the first 5 lines followed by "Show all [n] lines". Most of the time, t...
by chris_brown_ral New Member in Getting Data In 11-19-2015
0 2
0
2
pjoiner
I signed up for a Splunk Cloud trial, and set up a universal forwarder on one of our EC2 instances. However, I keep g...
by pjoiner Explorer in Getting Data In 11-18-2015
0 5
0
5
splunkIT
So I am trying to configure Hunk 6.3.1 to search my avro files in Hadoop. Here is an example of these .avro files in...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 11-18-2015
0 2
0
2
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors