Getting Data In

Getting Data In
Community Activity
newbiesplunk
Hi, When i inject app server logs with sourcetype=access_combined, the timing for the event timestamp seems to be inc...
by newbiesplunk Path Finder in Getting Data In 08-06-2014
0 1
0
1
dchodur
I have been looking all over answers and trying various things and not getting the to bottom of this issue. I have a ...
by dchodur Path Finder in Getting Data In 08-06-2014
1 3
1
3
steven10172
When importing data into splunk I would like to pull all the files from a specific directory besides special files th...
by steven10172 Explorer in Getting Data In 08-06-2014
0 4
0
4
skansi
Hi guys, I have a task at hand: I must upload an XML file and break the events, so that Splunk recognizes them. I am ...
by skansi Explorer in Getting Data In 08-06-2014
0 3
0
3
adayton20
Hello, I am new to Splunk and was curious as to if there is a way to search specifically what user was logged into a...
by adayton20 Contributor in Getting Data In 08-06-2014
0 4
0
4
philip_wong
I have PSV files in such format. Date is in 2nd column. Haven't spent much time to try different setting, but Splunk ...
by philip_wong Communicator in Getting Data In 08-06-2014
1 5
1
5
jadams7325
I'm running Splunk 6.1 as my indexer. I have a 6.1 universal forwarder setup on a windows box and I'm trying to filte...
by jadams7325 New Member in Getting Data In 08-05-2014
0 2
0
2
abrarfakhri
We have multiple version of IIS but looks like an older version is missing the last field (time_taken). We still nee...
by abrarfakhri Path Finder in Getting Data In 08-05-2014
0 2
0
2
jirakritwang
Hi. I use Splunk 6.1 free version, Can i config splunk for keep index or log 90 days and delete index or log older th...
by jirakritwang Engager in Getting Data In 08-05-2014
1 3
1
3
a212830
Hi, I'm having problems parsing the following lines, hoping someone can help me. Here's my props: ANNOTATE_PUNCT =...
by a212830 Champion in Getting Data In 08-05-2014
1 6
1
6
jbleich
I'm a new splunk user, so be kind  I have about 80% of my daily volume coming in what i believe to be un-needed inf...
by jbleich Path Finder in Getting Data In 08-05-2014
0 4
0
4
newbiesplunk
Hi, when i forward my input files (c:\data) from server A to Splunk Head at ServerB, the date format was correct for ...
by newbiesplunk Path Finder in Getting Data In 08-05-2014
0 6
0
6
shangshin
Hi, In Splunk 6, I can see the peers, search heads and index names from the master GUI. I am trying to find the eq...
by shangshin Builder in Getting Data In 08-05-2014
1 2
1
2
splunkn
How do I extract what are all the universal forwarders (deployment clients) contacting the deployment server?I want t...
by splunkn Communicator in Getting Data In 08-05-2014
0 5
0
5
kratikaj07
Is it possible to index excel spreadsheet data(.xls,.xlsx)without converting data into binary . Do we need to first c...
by kratikaj07 Explorer in Getting Data In 08-05-2014
1 3
1
3
spoorthyredi
All, We configured splunk to index data from a Oracle DataBase using Splunk DB Connect App . Our database tables an...
by spoorthyredi New Member in Getting Data In 08-04-2014
0 3
0
3
NK_1
C:\Program Files\Splunk\etc\system\local\props.conf contains [YYY] TIME_PREFIX = timestamp= SHOULD_LINEMERGE = fals...
by NK_1 Path Finder in Getting Data In 08-04-2014
0 1
0
1
tdewberry
I have this in my windows DC server with Universal Forwarder v 6.1.1. ..\Splunk_TA_Windows\local\inputs.conf file: ...
by tdewberry New Member in Getting Data In 08-04-2014
0 1
0
1
calvintkng
I've a csv file containing thousands of events, each event is only single line with date time stamp and several other...
by calvintkng New Member in Getting Data In 08-04-2014
0 7
0
7
bcusick
Hi, One of my forwarders is monitoring a directory where timestamped files populate every five minutes. The text ou...
by bcusick Communicator in Getting Data In 08-04-2014
0 4
0
4
adelucaa
We have a heavy forwarder set up on our log server. It is sending to rsyslog and then forwarding to the indexer. If...
by adelucaa New Member in Getting Data In 08-02-2014
0 2
0
2
splunkIT
I have setup the following inputs.conf stanza : [WinEventLog://Security] disabled=0 current_only=1 blacklist1=Eve...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 08-01-2014
0 2
0
2
dhavamanis
Can you please provide sample configuration for the below, We have multiple forwarding sources and they are using sys...
by dhavamanis Builder in Getting Data In 08-01-2014
0 5
0
5
aelliott
I would like to split a field called "destination" and "original_source" into 2 fields, each is an ip:port or [ipv6]:...
by aelliott Motivator in Getting Data In 08-01-2014
1 4
1
4
jimjh
I have directory paths that look like /year=2014/month=6/day=4/hour=1/ However, using the following regex is subop...
by jimjh Path Finder in Getting Data In 08-01-2014
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors