Getting Data In

Getting Data In
Community Activity
UnivLyon2
I'm trying to create on my network a "syslog" server that would act as a hub to concentrate logs from various sources...
by UnivLyon2 Explorer in Getting Data In 02-18-2015
1 2
1
2
05500
Our environment Splunk version 4.2.2 Universal forwarder version 6.2.1 We have already used Splunk from a few years ...
by 05500 New Member in Getting Data In 02-18-2015
0 3
0
3
abhisawa
I have available json as following {<!-- --> "Foo1": {<!-- --> "Bar1": {<!-- --> "Key1": "Value1", "Key2...
by abhisawa Explorer in Getting Data In 02-17-2015
0 1
0
1
pmdba
We recently patched our operating system (Red Hat Enterprise Linux 6) and the Java JRE path changed. When we updated ...
by pmdba Builder in Getting Data In 02-17-2015
0 18
0
18
nspatel
Hi Everyone, I am trying to have Splunk Auto delete data older then a year. My /opt/splunk/etc/system/local/inputs....
by nspatel Explorer in Getting Data In 02-17-2015
2 3
2
3
stu6000
I am pulling data from several linux hosts, each host has several users, and i am collecting data from each users llo...
by stu6000 New Member in Getting Data In 02-16-2015
0 1
0
1
BP9906
07-16-2014 10:45:21.533 -0700 WARN LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exc...
by BP9906 Builder in Getting Data In 02-16-2015
2 6
2
6
joshd
Hello, I noticed with the latest version of the app "Splunk for Cisco IPS" that events from my IPS are being broken u...
by joshd Builder in Getting Data In 02-16-2015
0 5
0
5
MoniGreeth
Hi All, In splunk documentation it is mentioned as follows, "Data cloning To perform data cloning, specify multiple...
by MoniGreeth Engager in Getting Data In 02-16-2015
1 3
1
3
ic_101
Hi, I have set up a Splunk Heavy Forwarder (v6.1.1) that collects events from a number of Windows and Linux servers ...
by ic_101 Explorer in Getting Data In 02-16-2015
2 6
2
6
twhitbeck
I have a webapp running in Tomcat. I'm using Log4j for my logging, and whenever I load the .log file in Splunk it is ...
by twhitbeck Engager in Getting Data In 02-15-2015
3 2
3
2
fcastro86
Hello, I have the following path /foo/bar[1-n]/logs/ I have several bar folders (bar1,bar2 ... bar1337 ) and inside ...
by fcastro86 New Member in Getting Data In 02-15-2015
0 3
0
3
hlarimer
I have syslog data coming to a distributed environment. I am trying to send the data to a specific index based on a ...
by hlarimer Communicator in Getting Data In 02-14-2015
0 6
0
6
fsalamo
Does anyone know how to re-trigger the "Welcome to Splunk!" e-mail referenced in this documentation? http://docs.splu...
by fsalamo Explorer in Getting Data In 02-14-2015
0 2
0
2
hlarimer
When I add search time Extractions directly to /opt/splunk/etc/apps/search/local/props.conf they will be used at sear...
by hlarimer Communicator in Getting Data In 02-14-2015
0 1
0
1
Sqig
Hi. This is regarding Splunk 5.0.11 Universal Forwarder and Heavy Forwarder. We rebooted 2 Heavy Forwarders today (...
by Sqig Path Finder in Getting Data In 02-13-2015
0 2
0
2
cmlombardo
I am pulling my hair off on this one. I am trying to remove from the windows firewall logs all the IPv6 link local an...
by cmlombardo Path Finder in Getting Data In 02-13-2015
0 1
0
1
andersonwes
I have a directory with filenames like the ones below and want to blacklist the files in my data input where the file...
by andersonwes New Member in Getting Data In 02-13-2015
0 4
0
4
sjh65
After configuring splunkd to use SSL, with /etc/system/local/server.conf [sslConfig] enableSplunkdSSL &#61; true sslVe...
by sjh65 Explorer in Getting Data In 02-12-2015
0 2
0
2
chrisboy68
Hi, I have a multi line flat file where I want to ignore/drop specifc events. I'm using the Universial Forwarder, so...
by chrisboy68 Contributor in Getting Data In 02-12-2015
0 5
0
5
ww9rivers
I have Splunk Universal Forwarders on 4 Windows 2012R2 servers, monitoring the DHCP server logs with this stanza: [m...
by ww9rivers Contributor in Getting Data In 02-12-2015
0 1
0
1
julianglavey
Hi all, I am looking to try and figure out how to compose a query that has information I need in two distinct source...
by julianglavey New Member in Getting Data In 02-12-2015
0 2
0
2
sympatiko
Hi Splunkers, I just want to ask if it is required in indexes.conf to specify the thawedPath? Thanks, Eddel
by sympatiko Communicator in Getting Data In 02-11-2015
0 5
0
5
pjb2160
This is a strange one, I have a data source which has multiple values in two separate fields so I use the makemv and ...
by pjb2160 Path Finder in Getting Data In 02-11-2015
0 1
0
1
rlough
I have a query that looks like this index&#61;*ind* ((source&#61;*src1.log field&#61;NAME) OR (source&#61;*src1.log field&#61;STRING)) |...
by rlough Path Finder in Getting Data In 02-11-2015
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...