Getting Data In

Getting Data In
Community Activity
bbiandov
Hi everyone, How do I detect a host which stops sending logs? Ideally an alert would be the optimal application of an...
by bbiandov Path Finder in Getting Data In 07-08-2015
0 5
0
5
qazwsxedc994
I am looking to configure a single search head and indexer for testing purposes, however i cant seem to find any clea...
by qazwsxedc994 Explorer in Getting Data In 07-08-2015
0 1
0
1
shandman
I am trying to "Add new" in Forwarding and Receiving / Forward data. I simply want to add my Load Balanced Indexers, ...
by shandman Path Finder in Getting Data In 07-07-2015
1 3
1
3
Federica_92
Hi everyone, I created a deployment server with 2 forwarders that are sending data to 2 indexers, and they have to ...
by Federica_92 Communicator in Getting Data In 07-07-2015
0 7
0
7
chris1
Hi, I have installed splunk universal forwarder on one of my windows server, while installing I've given the log dir...
by chris1 Explorer in Getting Data In 07-07-2015
0 7
0
7
Abilan1
Hi , I wanted to modify access for a few users and also I want to modify the index. Can I make these changes from Se...
by Abilan1 Path Finder in Getting Data In 07-07-2015
0 7
0
7
vtsguerrero
I've exported an app to a client, but the sourcetypes were not exported automatically. Shouldn't they be inside the a...
by vtsguerrero Contributor in Getting Data In 07-07-2015
0 2
0
2
the_wolverine
Would this be automatic or would additional TZ configuration need to be set in order for this to work?
by the_wolverine Champion in Getting Data In 07-07-2015
0 7
0
7
duffeysplunk
We have a file being generated by a vendor that they write data to on a regular basis. I do not need to import the d...
by duffeysplunk Path Finder in Getting Data In 07-07-2015
0 2
0
2
felipesewaybric
Hi guys, i have this search: | dbquery PROD-UOL7-MANUT-MONITORACAO "select dat_collect_transaction as \"data\", da...
by felipesewaybric Contributor in Getting Data In 07-07-2015
0 2
0
2
a212830
Hi, I noticed that our AD log inputs has a "start_from = oldest" entry. My question is, with this setting, if th...
by a212830 Champion in Getting Data In 07-07-2015
0 1
0
1
Lindaiyu
Hello, I write a xxx.sh in the /splunk/etc/apps/my_apps/bin and by the commande line ./xxx.sh to execute the c...
by Lindaiyu Path Finder in Getting Data In 07-07-2015
0 1
0
1
trravi
Is there any way to monitor employees' browsing data or urls by using Splunk?
by trravi New Member in Getting Data In 07-07-2015
0 2
0
2
wibay
I'd like to take various actions against real-time events from Splunk. What's considering the best practice for this...
by wibay New Member in Getting Data In 07-07-2015
0 1
0
1
minkyuk
Where do I go & how should I do it? I know what to change, [$sourcetype] MAX_EVENT = 100000 I would appreciate yo...
by minkyuk Explorer in Getting Data In 07-07-2015
0 7
0
7
borgy95
I have some very large lookup tables for known bad domains.(4m+ entries) the lookup has a field called 'kap_chk' wh...
by borgy95 Path Finder in Getting Data In 07-07-2015
0 3
0
3
kpsajin
Hi, I have cisco ASA and cisco ISE syslogs coming to splunk on udp1026 port. I would like to differentiate the sourc...
by kpsajin Explorer in Getting Data In 07-07-2015
0 9
0
9
barrysvee
Our application had a defect in a logging interceptor that led to a field being duplicated in an event but where both...
by barrysvee New Member in Getting Data In 07-07-2015
0 5
0
5
Splunkster45
In my inputs.conf file, I have an entry for a sourcetype that I want to change. Currently, it monitors the path: /op...
by Splunkster45 Communicator in Getting Data In 07-06-2015
0 4
0
4
altink
I have configured Windows logs input to a certain index Index_test_03, but very few data - tens - go there. Most of t...
by altink Builder in Getting Data In 07-06-2015
0 10
0
10
swatijha
Below is the log: qCode="SOME_CODE", qValue="[{"id":null,"dayStart":"08:00","dayEnd":"18:00","dayOfWeek":"2","day":...
by swatijha New Member in Getting Data In 07-06-2015
0 4
0
4
a212830
Hi, I'm stumped. I've been playing with the linebreaking trying to get the format properly, and it won't work. The f...
by a212830 Champion in Getting Data In 07-06-2015
0 15
0
15
davebo1896
Just noticed I have a duplicate GUID for two standalone, load balanced (via splunk conf, not F5) indexers. Can I just...
by davebo1896 Communicator in Getting Data In 07-06-2015
0 1
0
1
bnorthway
In my screenshot, you can see my events have duplicate fields. I am trying to figure out why this is occurring. The s...
by bnorthway Path Finder in Getting Data In 07-06-2015
3 3
3
3
syx093
I set up a small network using virtualbox and I am now having trouble forwarding data to the host. The laptop I am us...
by syx093 Communicator in Getting Data In 07-06-2015
0 1
0
1
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...
Top Solution Authors