Getting Data In

Getting Data In
Community Activity
peter_gianusso
Recently my Windows Universal Forwarder stopped forwarding Windows application event log messages to my indexer. See...
by peter_gianusso Communicator in Getting Data In 07-21-2015
0 1
0
1
papalmi
We're looking to substitute the host field, which is an IP address, with the device name that corresponds to the IP a...
by papalmi New Member in Getting Data In 07-21-2015
0 5
0
5
pinVie
Hello all, In a current project, I have to work with an existing Splunk environment which is already in use for abo...
by pinVie Path Finder in Getting Data In 07-21-2015
0 3
0
3
bjensen_splunk
New to Splunk so any help is appreciated. I am uploading mytest.log and trying to use SEDCMD to unravel a few fields...
by bjensen_splunk New Member in Getting Data In 07-21-2015
0 2
0
2
abovebeyond
Hello, one of our application has the following log structure #Fields: Date ; Time ; Site Instance ; Event ; Clie...
by abovebeyond Communicator in Getting Data In 07-21-2015
0 4
0
4
archspangler
How do I wildcard any windows drive letter in the inputs.conf stanza below? inputs.conf [monitor://[A-Z]:\Data\Disk...
by archspangler Path Finder in Getting Data In 07-21-2015
0 4
0
4
LewisWheeler
I read somewhere this is possible, however I can't find where or how - looking for confirmation: Essentially I have ...
by LewisWheeler Communicator in Getting Data In 07-21-2015
0 4
0
4
dhasemore
I have downloaded the install file splunkforwarder-6.2.4-271043-SunOS10-sparc.tar.z for a server running solaris10. ...
by dhasemore Engager in Getting Data In 07-20-2015
0 3
0
3
pavan257
Here is the sample data. RED: 2086 GREEN: 1579 WHITE: 159 PINK: 348 ORANGE: 0
by pavan257 New Member in Getting Data In 07-20-2015
0 11
0
11
pcampion
Hi. I'm brand new to using Splunk and just downloaded the Splunk Light trial. I've followed the tutorial video for...
by pcampion New Member in Getting Data In 07-20-2015
0 13
0
13
vinchakov_a
I created an input in the _json format and send to it httpd access logs. I received such logs: Jul 14 14:35:44 172.1...
by vinchakov_a Path Finder in Getting Data In 07-20-2015
0 6
0
6
brent_weaver
I have two platforms to monitor. I want to create one application that I can apply to all hosts that come on board. I...
by brent_weaver Builder in Getting Data In 07-20-2015
0 1
0
1
pkeller
inputs.conf [monitor:///home/foo/logs/*/app] whitelist = \.gmt.log$ blacklist = monitor disabled = false Underneat...
by pkeller Contributor in Getting Data In 07-20-2015
0 2
0
2
jfinnig3
I know that I can create custom source types by adding them to /etc/system/local/props.conf. However, I've created a ...
by jfinnig3 Engager in Getting Data In 07-20-2015
0 3
0
3
adolan
Hi, I have a field that I want to expand to multiple lines (it's email transactions), so I have a CSV of: source,d...
by adolan New Member in Getting Data In 07-20-2015
0 1
0
1
ayushchoudhary
I want to monitor logs kept on a Linux box A, but I do not want to install a Splunk forwarder on box A. a Splunk forw...
by ayushchoudhary Path Finder in Getting Data In 07-20-2015
0 1
0
1
attgjh1
the default _time are actually at the time of indexing. however my logs have another time string which i have to sepa...
by attgjh1 Communicator in Getting Data In 07-20-2015
0 7
0
7
domenico_perre
Hi All, I have been having significant trouble with one set of props/transforms for our environment. I have tried n...
by domenico_perre Path Finder in Getting Data In 07-19-2015
0 4
0
4
moneybox
Hello, In our use of Splunk we have encountered several problems in JSON indexing that caused to upgrade our Splunk ...
by moneybox Explorer in Getting Data In 07-19-2015
0 1
0
1
acharlieh
I've found myself recently looking at the Pipelines in Splunk, through the How Indexing Works wiki page, or @amrit an...
by acharlieh Influencer in Getting Data In 07-19-2015
1 2
1
2
aashish_122001
When I try to add Data Input, a blank screen appears. It s not moving forward and gives me no option to proceed.
by aashish_122001 Explorer in Getting Data In 07-18-2015
0 2
0
2
wegscd
Just had this pop up; there is only one instance of it in the notification area, but the time stamp keeps advancing, ...
by wegscd Contributor in Getting Data In 07-17-2015
0 10
0
10
ATT-CommonServi
The VM server is using the local name to bind to the application interface, thus data is being sent over on eth1-0, a...
by ATT-CommonServi New Member in Getting Data In 07-17-2015
0 3
0
3
cuppma
I'm fairly new to Splunk and I can't figure out how to get Splunk to index my logs. I have configured my WebSense dev...
by cuppma Explorer in Getting Data In 07-17-2015
0 16
0
16
rgilliam
Was wondering how I can view my data retention settings in Splunk. Installation is on a Linux platform.
by rgilliam Engager in Getting Data In 07-17-2015
4 3
4
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors