Getting Data In

Getting Data In
Community Activity
a212830
Hi, I'm stumped. I've been playing with the linebreaking trying to get the format properly, and it won't work. The f...
by a212830 Champion in Getting Data In 07-06-2015
0 15
0
15
davebo1896
Just noticed I have a duplicate GUID for two standalone, load balanced (via splunk conf, not F5) indexers. Can I just...
by davebo1896 Communicator in Getting Data In 07-06-2015
0 1
0
1
bnorthway
In my screenshot, you can see my events have duplicate fields. I am trying to figure out why this is occurring. The s...
by bnorthway Path Finder in Getting Data In 07-06-2015
3 3
3
3
syx093
I set up a small network using virtualbox and I am now having trouble forwarding data to the host. The laptop I am us...
by syx093 Communicator in Getting Data In 07-06-2015
0 1
0
1
mjones414
I have a shared search head used by different groups where those groups have set up their own indexers. They want to...
by mjones414 Contributor in Getting Data In 07-06-2015
0 2
0
2
jeromep83
Hi, I'm trying to stop forwarding _audit index. I put in my outputs.conf the following lines: [tcpout] forwardedind...
by jeromep83 Engager in Getting Data In 07-06-2015
0 1
0
1
borgy95
I want to add a field extracttion to props.conf that will extract a portion of the uri field to create a custom field...
by borgy95 Path Finder in Getting Data In 07-06-2015
0 2
0
2
suhprano
How can I configure splunk to index or accept the datestamp in the name of directories? The events only have time sta...
by suhprano Path Finder in Getting Data In 07-06-2015
0 1
0
1
skender27
Hi, I extracted from the default source field, in search-time, a new field called 'domain': | rex field=source "^(\/...
by skender27 Contributor in Getting Data In 07-06-2015
0 9
0
9
jeromep83
Hello, I use a Splunk heavy forwarder and I would like to send inputs to a remote a server. I have two channels on ...
by jeromep83 Engager in Getting Data In 07-05-2015
2 5
2
5
jtsplunk
I'm indexing a CSV that appears like the following in its raw form: Filenum,string 1,abc 2,defg 2,abc 3,xyz 3,abc 1,...
by jtsplunk Splunk Employee Splunk Employee in Getting Data In 07-05-2015
0 4
0
4
krusty
Hi, I'm trying to search a multiline event from a windows server. I need to find out which changes was made with a f...
by krusty Contributor in Getting Data In 07-05-2015
0 1
0
1
howyagoin
I get the feeling this is going to be a tough one to solve, but, I'm trying to aggregate results of a search based up...
by howyagoin Contributor in Getting Data In 07-05-2015
1 1
1
1
pshumate
The transform works and filters out the the matching line from going into the index but I still get these errors: WA...
by pshumate Explorer in Getting Data In 07-04-2015
0 1
0
1
Shtark
I need to apply a lookup only to events before a certain point in time (the data added by the lookup is now included ...
by Shtark Explorer in Getting Data In 07-04-2015
0 1
0
1
Aixia
I have a cluster of 4 indexers. The search head sends scheduled scans which always end up draining resources on one ...
by Aixia Engager in Getting Data In 07-03-2015
0 2
0
2
lanilim16
I've tried to run this.. ./splunk cmd python fill_summary_index.py -app search -name "summary" -et 06/14/2015:08:00:...
by lanilim16 Explorer in Getting Data In 07-03-2015
0 1
0
1
lanilim16
I have a universal forwarder installed in a few servers and I also have added the logs to be monitored for each. I'm ...
by lanilim16 Explorer in Getting Data In 07-03-2015
0 7
0
7
sbbadri
How to use POST REST Command in the search to reschedule the saved search scheduled time. for e.g saved search xxx ...
by sbbadri Motivator in Getting Data In 07-03-2015
0 3
0
3
Nicolasfm
I have a log file which is written out in XML through Microsoft.Practices.EnterpriseLibrary.ExceptionHandling. I want...
by Nicolasfm Engager in Getting Data In 07-03-2015
0 3
0
3
dominiquevocat
I have a deployment server from where i have a firewall rule that alows me to reach the 8089 management port of all f...
by SplunkTrust SplunkTrust in Getting Data In 07-03-2015
1 3
1
3
p_gurav
Hi, I have a Cassandra database. I want to index historical data as well as real time data that's coming to Cassandr...
by p_gurav Champion in Getting Data In 07-02-2015
2 5
2
5
fvasquezchacon
Hi! I'm using Splunk Free, specifically the monitor feature from a directory. I put several files in it, but not all ...
by fvasquezchacon Path Finder in Getting Data In 07-02-2015
0 1
0
1
someyoungfella
Hi there, I'm using a Splunk UF to monitor a Windows folder and syslog the events to a remote server where they are ...
by someyoungfella New Member in Getting Data In 07-02-2015
0 1
0
1
gyarici
Hi All, I have some log data that includes INFO, WARN, ERROR and DEBUG levels. I would like to index INFO, WARN, ER...
by gyarici Path Finder in Getting Data In 07-02-2015
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...