Getting Data In

Getting Data In
Community Activity
mikaelbje
Is there a way to see the originating forwarder for a specfic event? I haven't found any internal/metadata fields. Th...
by mikaelbje Motivator in Getting Data In 11-04-2014
0 2
0
2
steveirogers
My environment generates on average about 12GB of logs daily (out of a license for 20GB). The Splunk indexer is gene...
by steveirogers Communicator in Getting Data In 11-04-2014
0 3
0
3
akelly4
I'm loading a file via Data Inputs into Splunk on a daily basis. When I load the file the _time field is the current ...
by akelly4 Path Finder in Getting Data In 11-03-2014
2 3
2
3
jwalzerpitt
I would like to configure Splunk to monitor some log files in var/log and when i go to add data and select the direct...
by jwalzerpitt Influencer in Getting Data In 11-03-2014
0 2
0
2
t9445
Hello, we have what appears to be an incredibly weird scenario going on: We commonly override the serverName for dep...
by t9445 Path Finder in Getting Data In 11-03-2014
0 1
0
1
dorilevy
Hi, According to the document splunk should use empty string for non-matching lookup by default. Yet, when i set an ...
by dorilevy Path Finder in Getting Data In 11-03-2014
1 1
1
1
a212830
Hi, Is this value for the total size of the index apply to this specific server, within a cluster, or within my enti...
by a212830 Champion in Getting Data In 11-03-2014
1 1
1
1
lain179
I have a silly question. I found this from docs.splunk.com but how do I configure it so that Splunk can get event log...
by lain179 Communicator in Getting Data In 10-31-2014
1 4
1
4
jeanmatthieu
Hi, I'm running Splunk 6.1.4 and I send JSON documents through a TCP port. I have a JSON document as follow and no s...
by jeanmatthieu Explorer in Getting Data In 10-31-2014
0 1
0
1
viverma5
Hi, We are collecting Windows logs from a universal forwarder in a Windows Splunk Indexer. Now, I want to collect th...
by viverma5 Explorer in Getting Data In 10-31-2014
0 3
0
3
ltrand
I was wondering if anyone had a way to easily define a serverclass based on the UF version? We are managing our 5 to...
by ltrand Contributor in Getting Data In 10-31-2014
0 3
0
3
mokeefe
Using 5.0.2. I am receiving Windows Event Logs at the Indexer from Universal Forwarders on Windows servers. I want to...
by mokeefe New Member in Getting Data In 10-31-2014
0 5
0
5
hemanath_ofc
1 0/21/14 13:17:08.747 SERIAL ZPIMXTerminal.Send Start 10/21/14 13:17:08.747 SERIAL SerialComClass:****NOTICE: Seria...
by hemanath_ofc Explorer in Getting Data In 10-31-2014
0 1
0
1
mvaradarajam
How to remove double quotes from outputlookup csv file
by mvaradarajam Path Finder in Getting Data In 10-30-2014
0 1
0
1
mikelanghorst
Twice a year we have a set of servers used for testing our apps during DST time changes. About 2 months before we wi...
by mikelanghorst Motivator in Getting Data In 10-30-2014
0 6
0
6
laxmikants
till now we have been using putty tool to analyze logs locally in windows , but it is very tedious process to check a...
by laxmikants Engager in Getting Data In 10-30-2014
0 2
0
2
lakromani
I have data in the following format (Serv-U ftp log) [5] Sun 01Jun08 00:24:04 - (000555) Connected to 76.76.76.76 (L...
by lakromani Builder in Getting Data In 10-29-2014
1 5
1
5
gn694
We recently upgraded the Splunk Universal Forwarder to version 6.1.1 on our Domain Controllers. Splunk-winevtlog.exe...
by gn694 Communicator in Getting Data In 10-29-2014
0 2
0
2
NateStreet
How are other users utilizing Splunk to monitor privileged account usage in Windows/*nix environments? I'm looking fo...
by NateStreet New Member in Getting Data In 10-29-2014
0 1
0
1
caija
I am using Splunk (6.2) deployed on Windows 2008 R2. for some reason the configuration is failing with a "size limi...
by caija Engager in Getting Data In 10-29-2014
1 4
1
4
mrabbani
Can we take logs of memory.dmp into splunk in windows? If yes.. how it is possible.. source (%systemRoot%\memory.dmp)
by mrabbani New Member in Getting Data In 10-29-2014
0 1
0
1
jonas_daberkow
Dear Community, i would like to import a locally stored .mdb (MS Access) file into splunk. My first intention would ...
by jonas_daberkow New Member in Getting Data In 10-28-2014
0 1
0
1
mdessus_splunk
Hello, if you have powershell errors for try and catch keywords for the Citrix TA (or others), you need to upgrade t...
by mdessus_splunk Splunk Employee Splunk Employee in Getting Data In 10-28-2014
0 1
0
1
nitrogaute
BREAK_ONLY_BEFORE=\d{7} NO_BINARY_CHECK=1 SHOULD_LINEMERGE=true TIME_FORMAT=%3N TIME_PREFIX=\d{7} Trying to parse o...
by nitrogaute New Member in Getting Data In 10-28-2014
0 10
0
10
Jayadevanprabha
I have a heavy and complicated Enterprise messaging system splunked. The idea is to implement splunk query to logical...
by Jayadevanprabha New Member in Getting Data In 10-27-2014
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...