Getting Data In

Getting Data In
Community Activity
pranov97
Recently we upgraded the Splunk version to 6.3.0 We are trying to filter certain event codes from Security and Syste...
by pranov97 New Member in Getting Data In 10-27-2015
0 3
0
3
mattvickers
I'm trying to monitor file changes within a specific location on a production server's d:\ drive (d:\filestomonitor),...
by mattvickers Engager in Getting Data In 10-27-2015
0 1
0
1
icyfeverr
I setup a field extraction two ways, neither have worked and have caused Splunk to not function in a manner I think i...
by icyfeverr Path Finder in Getting Data In 10-27-2015
0 2
0
2
AZYeti
Does anyone have any experience with Bluecoat Packeteer data and getting it in to Splunk? This isn't something that ...
by AZYeti Explorer in Getting Data In 10-27-2015
0 1
0
1
KarunK
Hi All, I have installed the website monitoring app in my PC (Splunk 6). But I couldn't make it working.Its says "Co...
by KarunK Contributor in Getting Data In 10-27-2015
0 5
0
5
sim_tcr
Hello, I am trying to setup a rc script on our indexer so that Splunk does 'splunk offline' whenever the indexer is ...
by sim_tcr Communicator in Getting Data In 10-27-2015
0 4
0
4
CREVITCH
I am new to Splunk and downloaded Splunk free to several machines, Linux and Windows. All machines are on the same s...
by CREVITCH Path Finder in Getting Data In 10-27-2015
0 3
0
3
omuelle1
Hi Splunk Users, I am having an issue with my indexes growing very large and clogging up the space on my disk. For ...
by omuelle1 Communicator in Getting Data In 10-27-2015
0 3
0
3
mux
When doing this via the search bar index=xxxx | chart count by source, when you select a source in search it automa...
by mux Explorer in Getting Data In 10-27-2015
0 7
0
7
hettervik
Hi. I have an environment with two Splunk indexers running on VMs with Linux OS, and I want to create an indexer cl...
by hettervik Builder in Getting Data In 10-27-2015
0 2
0
2
japala
It would be great if someone can help me get this answer, either in GUI or CLI (through commands). Thank you in advan...
by japala Path Finder in Getting Data In 10-26-2015
1 3
1
3
karlbosanquet
I am deploying Universal Forwarders by either Puppet or SCCM to multiple hosts. They will be forwarding to a 6.3.0 m...
by karlbosanquet Path Finder in Getting Data In 10-26-2015
0 2
0
2
edrivera3
Hi I have the following configuration in inputs.conf: [monitor:///<directory>] index=results crcSalt = <SOURCE> sou...
by edrivera3 Builder in Getting Data In 10-26-2015
0 9
0
9
jamesvz84
Hello, I am looking to enable an export to csv button in web framework (where you can hover over the bottom of a tab...
by jamesvz84 Communicator in Getting Data In 10-26-2015
1 4
1
4
erickopp
Right now I have Splunk set up on a single Windows server, but have found some apps that require a Linux server to ru...
by erickopp Engager in Getting Data In 10-26-2015
0 1
0
1
hylam
How could I parse this? section1String field1,field2,field3 value1,value2,value3 value1,value2,value3 value1,value2,...
by hylam Contributor in Getting Data In 10-26-2015
0 7
0
7
fademidun
I just installed a forwarder on a host and trying to connect it to the Enterprise server, but got an error when launc...
by fademidun Engager in Getting Data In 10-26-2015
1 1
1
1
rsolutions
Splunk-optimize is launching on our indexers and eating up a few GB of memory, then Redhat's out-of-memory manager ki...
by rsolutions Path Finder in Getting Data In 10-26-2015
0 10
0
10
zindain24
I have a sourcetype that has a non-descriptive host and a source defined (both appear to have been overwritten by sta...
by zindain24 Path Finder in Getting Data In 10-26-2015
0 1
0
1
a5003976
Hi all, our customer want to implement a policy that track logs of the last six months starting from the time in whic...
by a5003976 Explorer in Getting Data In 10-26-2015
0 9
0
9
sunnyparmar
Hi, Is there any way or any work around or any app through which I can know if Splunk stop receiving data from the f...
by sunnyparmar Communicator in Getting Data In 10-25-2015
1 6
1
6
splunker12er
Sample Warning Message: Search peer 10.0.1.1 has the following message: received event for unconfigured/disabled/del...
by splunker12er Motivator in Getting Data In 10-24-2015
0 2
0
2
thecoffeeguy14
Hey all. Trying to figure out how to clear up my issue. I'm getting two separate time stamps on a syslog entry comin...
by thecoffeeguy14 New Member in Getting Data In 10-24-2015
0 4
0
4
hylam
The sourcetype should be csv or tsv or psv, depending on the full path in the source field. For hosts we have host_re...
by hylam Contributor in Getting Data In 10-24-2015
0 1
0
1
khhenderson
I have added the following to my props.conf file. AMANDA JSON FILES [amanda] INDEXED_EXTRACTIONS = json KV_MODE = j...
by khhenderson Path Finder in Getting Data In 10-24-2015
0 3
0
3
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...