Getting Data In

Getting Data In
Community Activity
dominiquevocat
Is there a way to use kv_mode=json and remove levels of nesting during indexing or later? Example: we jave some json...
by SplunkTrust SplunkTrust in Getting Data In 07-22-2015
0 2
0
2
rakesh_498115
Hi , I have custom fonts for my dashboard and added the same in my app in the below path. /opt/splunk/etc/apps/MY_A...
by rakesh_498115 Motivator in Getting Data In 07-22-2015
1 2
1
2
brent_weaver
We are rebuilding our distributed search Splunk environment: 1 Deployment Server 1 Dedicated Search Head 1 License S...
by brent_weaver Builder in Getting Data In 07-22-2015
0 1
0
1
maxdessureault
Hi all, I am fairly new to Splunk and have been working on the following search time field extraction to grab window...
by maxdessureault Engager in Getting Data In 07-22-2015
0 6
0
6
sympatiko
Hi splunkers, I want to achieve 1 day retention for indexed data. How can I achieve this? I have a cluster setup wit...
by sympatiko Communicator in Getting Data In 07-21-2015
0 12
0
12
timospringer
Hello, This is my code for installing and updating the UniversalForwarder via the command line. msiexec.exe /i "\\s...
by timospringer New Member in Getting Data In 07-21-2015
0 2
0
2
kylerose
We have many systems with Universal Forwarders sending to a dedicated Heavy Forwarder. We would like to put a 3rd par...
by kylerose Explorer in Getting Data In 07-21-2015
1 6
1
6
aaron_schmuhl
So, here's my admittedly dumb situation. I have an IPAM appliance(s) that does both DNS and DHCP. The output port for...
by aaron_schmuhl Engager in Getting Data In 07-21-2015
0 2
0
2
edwardman88
I have a AIX 7.1 machine setup as a forwarder running Splunk 6.1.2. Splunk keeps crashing almost and I need help to f...
by edwardman88 Explorer in Getting Data In 07-21-2015
4 4
4
4
peter_gianusso
Recently my Windows Universal Forwarder stopped forwarding Windows application event log messages to my indexer. See...
by peter_gianusso Communicator in Getting Data In 07-21-2015
0 1
0
1
papalmi
We're looking to substitute the host field, which is an IP address, with the device name that corresponds to the IP a...
by papalmi New Member in Getting Data In 07-21-2015
0 5
0
5
pinVie
Hello all, In a current project, I have to work with an existing Splunk environment which is already in use for abo...
by pinVie Path Finder in Getting Data In 07-21-2015
0 3
0
3
bjensen_splunk
New to Splunk so any help is appreciated. I am uploading mytest.log and trying to use SEDCMD to unravel a few fields...
by bjensen_splunk New Member in Getting Data In 07-21-2015
0 2
0
2
abovebeyond
Hello, one of our application has the following log structure #Fields: Date ; Time ; Site Instance ; Event ; Clie...
by abovebeyond Communicator in Getting Data In 07-21-2015
0 4
0
4
archspangler
How do I wildcard any windows drive letter in the inputs.conf stanza below? inputs.conf [monitor://[A-Z]:\Data\Disk...
by archspangler Path Finder in Getting Data In 07-21-2015
0 4
0
4
LewisWheeler
I read somewhere this is possible, however I can't find where or how - looking for confirmation: Essentially I have ...
by LewisWheeler Communicator in Getting Data In 07-21-2015
0 4
0
4
dhasemore
I have downloaded the install file splunkforwarder-6.2.4-271043-SunOS10-sparc.tar.z for a server running solaris10. ...
by dhasemore Engager in Getting Data In 07-20-2015
0 3
0
3
pavan257
Here is the sample data. RED: 2086 GREEN: 1579 WHITE: 159 PINK: 348 ORANGE: 0
by pavan257 New Member in Getting Data In 07-20-2015
0 11
0
11
pcampion
Hi. I'm brand new to using Splunk and just downloaded the Splunk Light trial. I've followed the tutorial video for...
by pcampion New Member in Getting Data In 07-20-2015
0 13
0
13
vinchakov_a
I created an input in the _json format and send to it httpd access logs. I received such logs: Jul 14 14:35:44 172.1...
by vinchakov_a Path Finder in Getting Data In 07-20-2015
0 6
0
6
brent_weaver
I have two platforms to monitor. I want to create one application that I can apply to all hosts that come on board. I...
by brent_weaver Builder in Getting Data In 07-20-2015
0 1
0
1
pkeller
inputs.conf [monitor:///home/foo/logs/*/app] whitelist = \.gmt.log$ blacklist = monitor disabled = false Underneat...
by pkeller Contributor in Getting Data In 07-20-2015
0 2
0
2
jfinnig3
I know that I can create custom source types by adding them to /etc/system/local/props.conf. However, I've created a ...
by jfinnig3 Engager in Getting Data In 07-20-2015
0 3
0
3
adolan
Hi, I have a field that I want to expand to multiple lines (it's email transactions), so I have a CSV of: source,d...
by adolan New Member in Getting Data In 07-20-2015
0 1
0
1
ayushchoudhary
I want to monitor logs kept on a Linux box A, but I do not want to install a Splunk forwarder on box A. a Splunk forw...
by ayushchoudhary Path Finder in Getting Data In 07-20-2015
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...