Getting Data In

Getting Data In
Community Activity
smanojkumar
Hi Splunkers!   I would like to extract detection_method value, "Access Protection"file_name="HKLM\SOFTWARE\MICROSOFT...
by smanojkumar Contributor in Getting Data In 10-06-2023
0 2
0
2
Hemant93
Help me out to ingest .act and .authlog file format in splunk.
by Hemant93 Loves-to-Learn Lots in Getting Data In 10-06-2023
0 1
0
1
mikefg
o365 addon has been running fine.Token expired on the Azure side, so I generated a new one.Updating the Splunk addon ...
by mikefg Communicator in Getting Data In 10-05-2023
0 1
0
1
kiranhar
Team, I need your assistance with the below task. I need to migrate Splunk sh-2 (Non ES instance) from Cent OS to RED...
by kiranhar Explorer in Getting Data In 10-05-2023
0 10
0
10
kattey
Hello, good dayI am very new to Splunk, i and my team want to work on a mini project using splunk cloud with the topi...
by kattey New Member in Getting Data In 10-05-2023
0 2
0
2
Choi_Hyun
Hello, everyone.I just ran into an issue where a stanza within apps\SplunkUniversalForwarder\local\inputs.conf on a f...
by Choi_Hyun Explorer in Getting Data In 10-04-2023
0 6
0
6
Casial06
0
3
Shakira1
Hi,I have this command: | mstats avg("value1) prestats=true WHERE "index"="my_index" span=10s BY host| timechart avg(...
by Shakira1 Explorer in Getting Data In 10-04-2023
0 7
0
7
benesch
Hi all,I successfully forward data from Windows using the commandmsiexec.exe /i splunkuniversalforwarder_x86.msi RECE...
by benesch Observer in Getting Data In 10-04-2023
0 1
0
1
_pravin
Hi Community, We have this wierd situation where one of the newest splunk installs (3 months old) went out of space -...
by _pravin Contributor in Getting Data In 10-03-2023
0 8
0
8
nina
Hello everyone, I'm working on a project ''Splunk Enterprise: An organization's go-to in detecting cyber threats''  p...
by nina Engager in Getting Data In 10-03-2023
0 3
0
3
yohhpark
test_id": "CHICKEN-0123456","last_test_date": "2023-09-04 12:34:00"   with such above file and todays date 09/25/2023...
by yohhpark Path Finder in Getting Data In 10-03-2023
0 8
0
8
ucorral
Hello guys!, I have a month trying to forward my logs from iMacs using the UF with the following format:   Resources,...
by ucorral Loves-to-Learn in Getting Data In 10-03-2023
0 12
0
12
athorat
We recently move to S2 and our initial retention was set to 6 months. A month after the migration we decided to reduc...
by athorat Communicator in Getting Data In 10-03-2023
0 1
0
1
danielbb
We wonder about using SmartStore. Does it make sense to use it for all data except hot and warm data? Even if we end ...
by danielbb Motivator in Getting Data In 10-03-2023
1 7
1
7
BoldKnowsNothin
Hello comrades,After my poor research, I found that only heavy forwarder supports props.conf, but it was like 5 or 6 ...
by BoldKnowsNothin Path Finder in Getting Data In 10-02-2023
0 12
0
12
yackle_official
HI Community,I have been tasked with getting AWS Cloudtrail logs into Splunk. I have spent some time not just reading...
by yackle_official New Member in Getting Data In 10-02-2023
0 0
0
0
Dallastek1
Im trying to break out the comma separated values in my results but im brain farting. I want to break out the specifi...
by Dallastek1 Path Finder in Getting Data In 10-02-2023
0 2
0
2
cmlombardo
I would like to understand better how transformations work, in terms of priority and data flow.Let's say I have 3 tra...
by cmlombardo Path Finder in Getting Data In 10-02-2023
0 6
0
6
cmlombardo
Hello there.I have IIS logs being ingested into Splunk.The sourcetype is currently set to "iis:test"props.conf:[iis:t...
by cmlombardo Path Finder in Getting Data In 10-02-2023
0 4
0
4
bosseres
Hello everyone! Do anybody know, is it possible to aggregate (bind) auditd events (I mean logs from audit/audit.log) ...
by bosseres Contributor in Getting Data In 10-02-2023
0 3
0
3
BoldKnowsNothin
Hello comrades, I'm just curios is there anyway to shorten frequent words?For example: <Data Name='IpAddress'>::ffff:...
by BoldKnowsNothin Path Finder in Getting Data In 10-02-2023
0 7
0
7
CyberCyber
HiI'm currently working on obtaining Windows Filtering Platform event logs to identify the user responsible for runni...
by CyberCyber New Member in Getting Data In 09-30-2023
0 1
0
1
just4testsplunk
I wonder if the activity of deleting audit events from Splunk cloud will be logged/tracked in Splunk internal logs, e...
by just4testsplunk New Member in Getting Data In 09-29-2023
0 6
0
6
Matthias_BY
Hi, i want to send out data with an forwarder to a splunk indexer hosted in the web like splunk storm. Is it possi...
by Matthias_BY Communicator in Getting Data In 09-29-2023
1 6
1
6
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...

What's New in Splunk Observability - November 2025

What's New We’re excited to announce the latest enhancements to Splunk Observability Cloud and ...

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...