Getting Data In

Getting Data In
Community Activity
NK_1
C:\Program Files\Splunk\etc\system\local\props.conf contains [YYY] TIME_PREFIX = timestamp= SHOULD_LINEMERGE = fals...
by NK_1 Path Finder in Getting Data In 08-04-2014
0 1
0
1
tdewberry
I have this in my windows DC server with Universal Forwarder v 6.1.1. ..\Splunk_TA_Windows\local\inputs.conf file: ...
by tdewberry New Member in Getting Data In 08-04-2014
0 1
0
1
calvintkng
I've a csv file containing thousands of events, each event is only single line with date time stamp and several other...
by calvintkng New Member in Getting Data In 08-04-2014
0 7
0
7
bcusick
Hi, One of my forwarders is monitoring a directory where timestamped files populate every five minutes. The text ou...
by bcusick Communicator in Getting Data In 08-04-2014
0 4
0
4
adelucaa
We have a heavy forwarder set up on our log server. It is sending to rsyslog and then forwarding to the indexer. If...
by adelucaa New Member in Getting Data In 08-02-2014
0 2
0
2
splunkIT
I have setup the following inputs.conf stanza : [WinEventLog://Security] disabled=0 current_only=1 blacklist1=Eve...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 08-01-2014
0 2
0
2
dhavamanis
Can you please provide sample configuration for the below, We have multiple forwarding sources and they are using sys...
by dhavamanis Builder in Getting Data In 08-01-2014
0 5
0
5
aelliott
I would like to split a field called "destination" and "original_source" into 2 fields, each is an ip:port or [ipv6]:...
by aelliott Motivator in Getting Data In 08-01-2014
1 4
1
4
jimjh
I have directory paths that look like /year=2014/month=6/day=4/hour=1/ However, using the following regex is subop...
by jimjh Path Finder in Getting Data In 08-01-2014
0 1
0
1
jimjh
How do I specify Ctrl-A (\u0001) as a field delimiter in props.conf? I tried [xxx] FIELD_DELIMITER=\x01 [xxx] FIEL...
by jimjh Path Finder in Getting Data In 08-01-2014
1 1
1
1
mattchapple
I'm struggling to get my Splunk 6.0.1 to recognise an epoch time for all events. I have specified a timestamp format ...
by mattchapple Explorer in Getting Data In 08-01-2014
1 6
1
6
abn
Hi, I am generating a report using data from database. I have a tabular format in my CSV. Is it possible via Splunk ...
by abn New Member in Getting Data In 08-01-2014
0 1
0
1
rune_hellem
Indexing a lot of SystemOut.log files from WebSphere I realize that all almost all log files uses the following time ...
by rune_hellem Contributor in Getting Data In 08-01-2014
3 3
3
3
axl88
Hi all, I was assigned to push a fix on forwarders since they are forwarding data with auto-naming on index and sourc...
by axl88 Communicator in Getting Data In 08-01-2014
1 4
1
4
chrismullen
Hi, I'm wondering if there is a way to prevent a sensitive key-value pair that exists in cs_Cookie from appearing in...
by chrismullen Explorer in Getting Data In 07-31-2014
1 5
1
5
menkurau
I have a lot of fields called EXTRA_FIELD_X and I am not sure why. I have not been able to find anything on Answers ...
by menkurau Path Finder in Getting Data In 07-31-2014
0 3
0
3
mireyaco
Hi, I have Splunk 5.0.5 installed on a Windows OS 2012 I have a windows 2008 64-bit with splunkforwarder-6.1.2-2130...
by mireyaco New Member in Getting Data In 07-31-2014
0 1
0
1
aelliott
When attempting to use the following suggestion on blacklisting 4662 events, I run into an error in splunkd.log http...
by aelliott Motivator in Getting Data In 07-31-2014
0 2
0
2
africates
Hi, I'm about to migrate whole splunk server from v. 4.2.1 on Windows 2003 32 bit to v.6.1.2 on Windows 2012 64 bits...
by africates Explorer in Getting Data In 07-31-2014
1 1
1
1
jodros
Our shop has four indexers with limited storage. This is due to the fact that we wanted fast disk for quicker search...
by jodros Builder in Getting Data In 07-31-2014
1 11
1
11
dharanpdeepak
Hello, Please could anyone advice me, how I can get two instance of Universal forwarders run from one Linux Box? I a...
by dharanpdeepak Explorer in Getting Data In 07-30-2014
0 1
0
1
themedina
Hello, My organization is looking into using Splunk as a central log server. I have successfully installed Splunk o...
by themedina New Member in Getting Data In 07-30-2014
0 1
0
1
celsohso
When should I use Report and when should I use Transform on the props.conf?
by celsohso Path Finder in Getting Data In 07-30-2014
2 3
2
3
plj3736
I'm getting data in syslog format with the host set to localhost. I know what server this is coming from but don't h...
by plj3736 New Member in Getting Data In 07-30-2014
0 5
0
5
robf
This search produces the most recent timestamp for every host for aa specific index | metadata type=hosts index=win...
by robf Path Finder in Getting Data In 07-30-2014
0 4
0
4
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors