Getting Data In

Getting Data In
Community Activity
bbegyperkspot
I have a Json formatted log. Splunk shows my fields just fine. If I click one of my fields to filter by that field,...
by bbegyperkspot Explorer in Getting Data In 10-27-2014
0 1
0
1
mahesh_ravji1
Hi There, We have an index which is approx. 250GB in size. After change in requirements we no longer require approx...
by mahesh_ravji1 Explorer in Getting Data In 10-27-2014
0 5
0
5
BrandSentiment
I would like to run a search of data in one index and update data in another index if the certain parameters are met....
by BrandSentiment Explorer in Getting Data In 10-27-2014
0 1
0
1
abhayneilam
lets say daily I recieve 5 files, and I am indexing 5 files and running my query to generate the report. Now, my requ...
by abhayneilam Contributor in Getting Data In 10-25-2014
1 9
1
9
jumah35
Hi, I'am working with a text file indexed in Splunk. Every 15 minutes this file is completely replaced. At this mome...
by jumah35 New Member in Getting Data In 10-25-2014
0 6
0
6
acidkewpie
Hi, is there anything pokeable from a load balancer over TCP to validate the availability of a TCP data input? I can...
by acidkewpie Path Finder in Getting Data In 10-24-2014
0 1
0
1
skirkpatrick
I have a timestamp that is not coming incorrectly. Splunk is reading the seconds portion of time in my event as minu...
by skirkpatrick New Member in Getting Data In 10-24-2014
0 1
0
1
my_splunk
Hi, i have events with microseconds in timestamp, for example 2013-02-13:22:09:43.687263. I see that in custom time s...
by my_splunk Path Finder in Getting Data In 10-24-2014
3 1
3
1
jeanmatthieu
Hi! I'm sending a JSON document to a TCP Data Input on my Splunk server. I noticed the magical field _time that all...
by jeanmatthieu Explorer in Getting Data In 10-24-2014
1 3
1
3
jcbfaulks
I'm not exactly sure what is going on but when I installed universal forwarder and the receiver my splunk is getting ...
by jcbfaulks Explorer in Getting Data In 10-24-2014
0 2
0
2
mtmoore
In Inputs.conf you can set an interval that a powershell script runs to collect data... but can you somehow set the f...
by mtmoore Explorer in Getting Data In 10-24-2014
2 3
2
3
chengyu
Hi, when I do the filtering windows log, I use the main program 6.1.4 then changed forwarder license, so Windows AD (...
by chengyu Path Finder in Getting Data In 10-24-2014
0 3
0
3
xdaxdb
I am not getting expected behavior when specifying inputs. All my logs are in a folder called "/syslog/" 1.3M -rw-r...
by xdaxdb Explorer in Getting Data In 10-23-2014
0 11
0
11
riodutchie
I'm working in an environment where we have the universal forwarder (5.0.5 - old I know) installed on all our systems...
by riodutchie Explorer in Getting Data In 10-23-2014
0 7
0
7
bbiandov
I noticed that a new install of splunkforwarder automatically monitors the following directories: Monitored Director...
by bbiandov Path Finder in Getting Data In 10-23-2014
1 2
1
2
ulrich_track
I have a log file with a timestamp at the beginning of an event in the format YYYY-MM-DD HH:MM:SS.mmm. The automatic ...
by ulrich_track Path Finder in Getting Data In 10-23-2014
0 2
0
2
rnr
Hi, I've looked though similar questions about log rotation and also the most related documentation topic here http:...
by rnr Path Finder in Getting Data In 10-23-2014
1 5
1
5
sonicZ
I am getting these errors, even though i think i have the timestamp parsed correctly based on other splunk answers. ...
by sonicZ Contributor in Getting Data In 10-22-2014
0 1
0
1
dgravesa1
0
2
Ant1D
Can SSL configuration be applied on Splunk Universal Forwarders? My understanding is that it was only available on Sp...
by Ant1D Motivator in Getting Data In 10-22-2014
1 4
1
4
BT_Neophyte
I've set up forwarding many times, but for some reason cannot get my auditd log to properly appear in Splunk. I'm ban...
by BT_Neophyte Explorer in Getting Data In 10-22-2014
0 2
0
2
srinathd
I want to get the time in this format 2009-Sep-30 from 20090930
by srinathd Contributor in Getting Data In 10-22-2014
0 1
0
1
khuongdp
I have these 2 group: [monitor:///pack/jboss/server/edu01_*/logs/server.log] sourcetype = server_log index = myindex...
by khuongdp New Member in Getting Data In 10-22-2014
0 2
0
2
gekoner
I have created an outputs.conf on my Indexer. With the following stanza. [output] defaultGroup = indexerB [indexAnd...
by gekoner Communicator in Getting Data In 10-21-2014
0 1
0
1
smudge797
Splunk is not recognizing the timestamps in these logs. Some are picked up but others are grouped together into a si...
by smudge797 Path Finder in Getting Data In 10-21-2014
0 3
0
3
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors