Getting Data In

Getting Data In
Community Activity
aelliott
I would like to split a field called "destination" and "original_source" into 2 fields, each is an ip:port or [ipv6]:...
by aelliott Motivator in Getting Data In 08-01-2014
1 4
1
4
jimjh
I have directory paths that look like /year=2014/month=6/day=4/hour=1/ However, using the following regex is subop...
by jimjh Path Finder in Getting Data In 08-01-2014
0 1
0
1
jimjh
How do I specify Ctrl-A (\u0001) as a field delimiter in props.conf? I tried [xxx] FIELD_DELIMITER=\x01 [xxx] FIEL...
by jimjh Path Finder in Getting Data In 08-01-2014
1 1
1
1
mattchapple
I'm struggling to get my Splunk 6.0.1 to recognise an epoch time for all events. I have specified a timestamp format ...
by mattchapple Explorer in Getting Data In 08-01-2014
1 6
1
6
abn
Hi, I am generating a report using data from database. I have a tabular format in my CSV. Is it possible via Splunk ...
by abn New Member in Getting Data In 08-01-2014
0 1
0
1
rune_hellem
Indexing a lot of SystemOut.log files from WebSphere I realize that all almost all log files uses the following time ...
by rune_hellem Contributor in Getting Data In 08-01-2014
3 3
3
3
axl88
Hi all, I was assigned to push a fix on forwarders since they are forwarding data with auto-naming on index and sourc...
by axl88 Communicator in Getting Data In 08-01-2014
1 4
1
4
chrismullen
Hi, I'm wondering if there is a way to prevent a sensitive key-value pair that exists in cs_Cookie from appearing in...
by chrismullen Explorer in Getting Data In 07-31-2014
1 5
1
5
menkurau
I have a lot of fields called EXTRA_FIELD_X and I am not sure why. I have not been able to find anything on Answers ...
by menkurau Path Finder in Getting Data In 07-31-2014
0 3
0
3
mireyaco
Hi, I have Splunk 5.0.5 installed on a Windows OS 2012 I have a windows 2008 64-bit with splunkforwarder-6.1.2-2130...
by mireyaco New Member in Getting Data In 07-31-2014
0 1
0
1
aelliott
When attempting to use the following suggestion on blacklisting 4662 events, I run into an error in splunkd.log http...
by aelliott Motivator in Getting Data In 07-31-2014
0 2
0
2
africates
Hi, I'm about to migrate whole splunk server from v. 4.2.1 on Windows 2003 32 bit to v.6.1.2 on Windows 2012 64 bits...
by africates Explorer in Getting Data In 07-31-2014
1 1
1
1
jodros
Our shop has four indexers with limited storage. This is due to the fact that we wanted fast disk for quicker search...
by jodros Builder in Getting Data In 07-31-2014
1 11
1
11
dharanpdeepak
Hello, Please could anyone advice me, how I can get two instance of Universal forwarders run from one Linux Box? I a...
by dharanpdeepak Explorer in Getting Data In 07-30-2014
0 1
0
1
themedina
Hello, My organization is looking into using Splunk as a central log server. I have successfully installed Splunk o...
by themedina New Member in Getting Data In 07-30-2014
0 1
0
1
celsohso
When should I use Report and when should I use Transform on the props.conf?
by celsohso Path Finder in Getting Data In 07-30-2014
2 3
2
3
plj3736
I'm getting data in syslog format with the host set to localhost. I know what server this is coming from but don't h...
by plj3736 New Member in Getting Data In 07-30-2014
0 5
0
5
robf
This search produces the most recent timestamp for every host for aa specific index | metadata type=hosts index=win...
by robf Path Finder in Getting Data In 07-30-2014
0 4
0
4
C_Sparn
Hello, I try to use inputlookup with a csv file to import two multi value fields in a search. The two fields are both...
by C_Sparn Communicator in Getting Data In 07-30-2014
1 4
1
4
jodros
I recently installed the newest UF on a server to test before rolling out to the rest of the environment. I am able ...
by jodros Builder in Getting Data In 07-30-2014
0 6
0
6
bjyoti
Hi All, I am a newbie to splunk. I have gone through a number of video tutorials on the net. Hi All, I would like t...
by bjyoti Engager in Getting Data In 07-30-2014
0 6
0
6
a212830
Hi, I have splunk reading from a farm of syslog servers. I don't control the syslog config, so I have to live with ...
by a212830 Champion in Getting Data In 07-29-2014
1 7
1
7
aferone
We are running into max concurrent searches issues, as our deployment is getting more and more used. Is the limit ba...
by aferone Builder in Getting Data In 07-29-2014
0 19
0
19
steveo69
Using the Universal Forwarder I need to monitor a folder, so I am editing the inputs.conf file. However, in Windows ...
by steveo69 Explorer in Getting Data In 07-29-2014
1 4
1
4
steve543
I am trying to prune some noise from my logs. Here are my props.conf and transforms.conf. Any Idea what I am missing...
by steve543 New Member in Getting Data In 07-29-2014
0 4
0
4
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...