Getting Data In

Getting Data In
Community Activity
acidkewpie
Howdy, I want to ingest files on a universal forwarder that are still being written, and to delete them once the fil...
by acidkewpie Path Finder in Getting Data In 06-23-2015
0 1
0
1
AaronMoorcroft
Hey Guys I have a right one here. So I have a bunch of systems in a DMZ forwarding to a heavy forwarder that then fo...
by AaronMoorcroft Communicator in Getting Data In 06-23-2015
0 8
0
8
serwin
I'm looking to add cold storage to my Splunk 6.2.2 indexer clustering setup and just wanted to verify my process was ...
by serwin Explorer in Getting Data In 06-23-2015
0 1
0
1
MemoreX42
Hello experts, I am using the TCP input "channel" in order to get data into splunk (inputs.conf): [tcp://558] conne...
by MemoreX42 Explorer in Getting Data In 06-23-2015
1 2
1
2
nce054
I'm trying to create a new index called 'winevents_endpoint'. I've added this index to the Search Head, Indexer, and ...
by nce054 Path Finder in Getting Data In 06-23-2015
1 10
1
10
srinathd
Hi, how to find nth line data in an event. for example: I have to get 7th line data and needs to correlate with the ...
by srinathd Contributor in Getting Data In 06-23-2015
0 2
0
2
johnwl
I use username: admin and password: changeme to log in to my Splunk universal forwarder. I am trying to forward logs...
by johnwl Explorer in Getting Data In 06-22-2015
0 7
0
7
judenaidoo
According to my understanding, WMI as a pull agent is available on Windows' deployment of Splunk only. What are the...
by judenaidoo New Member in Getting Data In 06-22-2015
0 2
0
2
SwatiApte
Hi, I am using DBConnect to fetch two timestamps from an Oracle database table, let's call them TS1 and TS2, having ...
by SwatiApte Path Finder in Getting Data In 06-22-2015
0 15
0
15
kulamani
When I start installation process, it copies files and at the end point. it starts a roll back action and gives an er...
by kulamani Engager in Getting Data In 06-22-2015
0 1
0
1
johnc_ncc
Hi, I am using Splunk Light for Windows, and I have imported some IIS Logs files, but the timezone is out by an hour...
by johnc_ncc New Member in Getting Data In 06-22-2015
0 1
0
1
deepthi5
Hi Team, I have a couple of logs to be monitored daily from a directory called LOG. The log name is error log.0, err...
by deepthi5 Path Finder in Getting Data In 06-22-2015
0 1
0
1
nce054
I am currently trying to use my Marimba data gathered from the Endpoint tuner in Splunk. On my Universal Forwarder, I...
by nce054 Path Finder in Getting Data In 06-22-2015
0 5
0
5
lsolberg
Hi In this setup, we have servers for each universal-forwarder -> forwarder -> indexer -> searchhead. I am testing ...
by lsolberg Path Finder in Getting Data In 06-21-2015
3 1
3
1
thejohn
I had to reinstall my universal forwarder on windows server and splunk stopped showing new messages. So deleted all m...
by thejohn Path Finder in Getting Data In 06-21-2015
0 4
0
4
Cuyose
Splunk documentation is incorrect, as it states you should be able to do something like this : [monitor:///ebs/*/var...
by Cuyose Builder in Getting Data In 06-21-2015
0 1
0
1
mikehodges01
I upgraded from 6.1.3 to 6.2.1 recently and noticed that some of my universal forwarders stopped sending certain logs...
by mikehodges01 Explorer in Getting Data In 06-21-2015
0 1
0
1
shannu1241
I have a log, which has two time fields, _time(Log indexed time)StartDate (Date time inside the log) When i select...
by shannu1241 New Member in Getting Data In 06-20-2015
0 1
0
1
SwatiApte
Hi, In our data source (an application log file), we have multiple datetime attributes (say update_time, order_time,...
by SwatiApte Path Finder in Getting Data In 06-19-2015
0 1
0
1
nce054
I'm gathering data from two machines, and depending on which one it comes from, it has a different index. Both univer...
by nce054 Path Finder in Getting Data In 06-19-2015
0 3
0
3
sseekamp
We are running a small GPFS cluster on AIX. I am seeing high CPU usage running a universal forwarder pointed at log f...
by sseekamp Explorer in Getting Data In 06-19-2015
3 5
3
5
_gkollias
I'm working on sending requests to Splunk's REST API for the first time and have a few questions after reading throug...
by _gkollias Builder in Getting Data In 06-19-2015
0 6
0
6
temperuser
I have a script that executes every 5 minutes. It extracts date and time with props.conf: EXTRACT-date = ^(?:[^\t\n]...
by temperuser Explorer in Getting Data In 06-19-2015
0 1
0
1
splunker12er
Splunk query to get , Actual retention set for an index Remaining days left to meet retention date Current Index_siz...
by splunker12er Motivator in Getting Data In 06-19-2015
0 1
0
1
AditiKulkarni
I have a timestamp in the format "19-06-2015 07:00:00 Europe/London". Is there a way to convert this timestamp to epo...
by AditiKulkarni New Member in Getting Data In 06-19-2015
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...