Getting Data In

Getting Data In
Community Activity
a212830
Hi, I noticed that our AD log inputs has a "start_from = oldest" entry. My question is, with this setting, if th...
by a212830 Champion in Getting Data In 07-07-2015
0 1
0
1
Lindaiyu
Hello, I write a xxx.sh in the /splunk/etc/apps/my_apps/bin and by the commande line ./xxx.sh to execute the c...
by Lindaiyu Path Finder in Getting Data In 07-07-2015
0 1
0
1
trravi
Is there any way to monitor employees' browsing data or urls by using Splunk?
by trravi New Member in Getting Data In 07-07-2015
0 2
0
2
wibay
I'd like to take various actions against real-time events from Splunk. What's considering the best practice for this...
by wibay New Member in Getting Data In 07-07-2015
0 1
0
1
minkyuk
Where do I go & how should I do it? I know what to change, [$sourcetype] MAX_EVENT = 100000 I would appreciate yo...
by minkyuk Explorer in Getting Data In 07-07-2015
0 7
0
7
borgy95
I have some very large lookup tables for known bad domains.(4m+ entries) the lookup has a field called 'kap_chk' wh...
by borgy95 Path Finder in Getting Data In 07-07-2015
0 3
0
3
kpsajin
Hi, I have cisco ASA and cisco ISE syslogs coming to splunk on udp1026 port. I would like to differentiate the sourc...
by kpsajin Explorer in Getting Data In 07-07-2015
0 9
0
9
barrysvee
Our application had a defect in a logging interceptor that led to a field being duplicated in an event but where both...
by barrysvee New Member in Getting Data In 07-07-2015
0 5
0
5
Splunkster45
In my inputs.conf file, I have an entry for a sourcetype that I want to change. Currently, it monitors the path: /op...
by Splunkster45 Communicator in Getting Data In 07-06-2015
0 4
0
4
altink
I have configured Windows logs input to a certain index Index_test_03, but very few data - tens - go there. Most of t...
by altink Builder in Getting Data In 07-06-2015
0 10
0
10
swatijha
Below is the log: qCode="SOME_CODE", qValue="[{"id":null,"dayStart":"08:00","dayEnd":"18:00","dayOfWeek":"2","day":...
by swatijha New Member in Getting Data In 07-06-2015
0 4
0
4
a212830
Hi, I'm stumped. I've been playing with the linebreaking trying to get the format properly, and it won't work. The f...
by a212830 Champion in Getting Data In 07-06-2015
0 15
0
15
davebo1896
Just noticed I have a duplicate GUID for two standalone, load balanced (via splunk conf, not F5) indexers. Can I just...
by davebo1896 Communicator in Getting Data In 07-06-2015
0 1
0
1
bnorthway
In my screenshot, you can see my events have duplicate fields. I am trying to figure out why this is occurring. The s...
by bnorthway Path Finder in Getting Data In 07-06-2015
3 3
3
3
syx093
I set up a small network using virtualbox and I am now having trouble forwarding data to the host. The laptop I am us...
by syx093 Communicator in Getting Data In 07-06-2015
0 1
0
1
mjones414
I have a shared search head used by different groups where those groups have set up their own indexers. They want to...
by mjones414 Contributor in Getting Data In 07-06-2015
0 2
0
2
jeromep83
Hi, I'm trying to stop forwarding _audit index. I put in my outputs.conf the following lines: [tcpout] forwardedind...
by jeromep83 Engager in Getting Data In 07-06-2015
0 1
0
1
borgy95
I want to add a field extracttion to props.conf that will extract a portion of the uri field to create a custom field...
by borgy95 Path Finder in Getting Data In 07-06-2015
0 2
0
2
suhprano
How can I configure splunk to index or accept the datestamp in the name of directories? The events only have time sta...
by suhprano Path Finder in Getting Data In 07-06-2015
0 1
0
1
skender27
Hi, I extracted from the default source field, in search-time, a new field called 'domain': | rex field=source "^(\/...
by skender27 Contributor in Getting Data In 07-06-2015
0 9
0
9
jeromep83
Hello, I use a Splunk heavy forwarder and I would like to send inputs to a remote a server. I have two channels on ...
by jeromep83 Engager in Getting Data In 07-05-2015
2 5
2
5
jtsplunk
I'm indexing a CSV that appears like the following in its raw form: Filenum,string 1,abc 2,defg 2,abc 3,xyz 3,abc 1,...
by jtsplunk Splunk Employee Splunk Employee in Getting Data In 07-05-2015
0 4
0
4
krusty
Hi, I'm trying to search a multiline event from a windows server. I need to find out which changes was made with a f...
by krusty Contributor in Getting Data In 07-05-2015
0 1
0
1
howyagoin
I get the feeling this is going to be a tough one to solve, but, I'm trying to aggregate results of a search based up...
by howyagoin Contributor in Getting Data In 07-05-2015
1 1
1
1
pshumate
The transform works and filters out the the matching line from going into the index but I still get these errors: WA...
by pshumate Explorer in Getting Data In 07-04-2015
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors