Getting Data In

Getting Data In
Community Activity
gekoner
I have created an outputs.conf on my Indexer. With the following stanza. [output] defaultGroup = indexerB [indexAnd...
by gekoner Communicator in Getting Data In 10-21-2014
0 1
0
1
smudge797
Splunk is not recognizing the timestamps in these logs. Some are picked up but others are grouped together into a si...
by smudge797 Path Finder in Getting Data In 10-21-2014
0 3
0
3
mehhos
Hi, I like to filter out "%ASA-4-106023" before sending log to splunk indexer, Below are my config: inputs.conf [m...
by mehhos Engager in Getting Data In 10-21-2014
0 2
0
2
psharkey
I have Splunk Universal Forwarders installed on my Windows Domain Controllers. Up until 5 weeks ago, sourcetype=Activ...
by psharkey Explorer in Getting Data In 10-21-2014
1 1
1
1
jodros
I know this is not a Splunk specific question, however I have asked a similar question in the past about tuning for U...
by jodros Builder in Getting Data In 10-21-2014
0 1
0
1
jmc82
I have a dashboard containing a checkbox with some values. These values are OR'd together in my search string. For ex...
by jmc82 Explorer in Getting Data In 10-21-2014
2 1
2
1
fernandoandre
After reading this and this I'm not sure about the use of persistent queues on Splunk. In particular, in one implem...
by fernandoandre Communicator in Getting Data In 10-21-2014
1 2
1
2
sjnorman
I am having issues setting up a UNIX universal forwarder to monitor IBM IHS http log files -- it does not appear to b...
by sjnorman Explorer in Getting Data In 10-20-2014
0 3
0
3
jbouch03
alt textI have a log file that writes everything in one line. I'm try to count the number of events in the logfile bu...
by jbouch03 Path Finder in Getting Data In 10-20-2014
0 3
0
3
ltrand
I was wondering if anyone has a good search that can help track the weekly upgrade progress for UF agents? With the ...
by ltrand Contributor in Getting Data In 10-20-2014
1 1
1
1
soniaraj13
Hi, I see duplicate data getting ingested when a file which was already ingested is being recreated upon a system fa...
by soniaraj13 New Member in Getting Data In 10-20-2014
0 1
0
1
David
I have a datasource that looks like this: { "results": { "serverone": { "time": 2, "results": 3...
by David Splunk Employee Splunk Employee in Getting Data In 10-19-2014
0 1
0
1
royimad
Hello Splunkies, I was wondering if splunk could monitor a logs sent by email to splunk server. if yes how this coul...
by royimad Builder in Getting Data In 10-18-2014
0 2
0
2
rsawant
I want to index the dynamic performance views that are available in SYS of Oracle Database on Splunk. These views inc...
by rsawant Explorer in Getting Data In 10-17-2014
1 5
1
5
redc
I'm running two Windows Splunk servers (combo search heads and indexers, v6.0.1). One is dedicated to our non-produc...
by redc Builder in Getting Data In 10-16-2014
0 2
0
2
Raghav2384
Experts, we have 100GB license and that data is being fed to Splunk. Out of that 100GB, 10% is what need to be retai...
by Raghav2384 Motivator in Getting Data In 10-16-2014
1 2
1
2
thejamesvolta
I have a .csv file containing a list of email addresses (approximately 35k addresses/rows). I'm trying to compare th...
by thejamesvolta Engager in Getting Data In 10-16-2014
3 3
3
3
b571194trbvmcom
Hey! i need a little help here, so i have two sourcetypes (bro_dns and sguild) and there is what i want to search f...
by b571194trbvmcom New Member in Getting Data In 10-16-2014
0 1
0
1
pronix
hello I want to sent in splunk this request and get aggregated data search index=_intenal earliest=-2h@h http_status=...
by pronix New Member in Getting Data In 10-16-2014
0 2
0
2
ycalpu
Hi all, when i do an inputcsv command, I see the data in the file I put on the splunk server. Since I want to see the...
by ycalpu New Member in Getting Data In 10-16-2014
0 2
0
2
seema2502
Hi Team, Where are the forwarded logs being saved in the indexer after getting indexed? As i know this is very known...
by seema2502 Explorer in Getting Data In 10-16-2014
0 3
0
3
seema2502
Hi Team, i want to know where my archived files are getting saved as in my indexes.conf file "coldToFrozenDir = ". c...
by seema2502 Explorer in Getting Data In 10-16-2014
1 3
1
3
phoenixdigital
So I have been reading the documentation on how to create modular inputs using the Python SDK here http://dev.splunk....
by phoenixdigital Builder in Getting Data In 10-15-2014
0 3
0
3
mrabbani
Suppose if indexer is down, how will data be kept in a universal forwarder and heavy forwarder? Is there any differen...
by mrabbani New Member in Getting Data In 10-15-2014
0 2
0
2
nanaruru12
Hi Im trying to use DB Connect Now I'm adding new external databases Database type is Oracle and i chose Transaction...
by nanaruru12 New Member in Getting Data In 10-15-2014
0 1
0
1
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors