Getting Data In

Getting Data In
Community Activity
a212830
Hi, I'm having problems parsing the following lines, hoping someone can help me. Here's my props: ANNOTATE_PUNCT =...
by a212830 Champion in Getting Data In 08-05-2014
1 6
1
6
jbleich
I'm a new splunk user, so be kind  I have about 80% of my daily volume coming in what i believe to be un-needed inf...
by jbleich Path Finder in Getting Data In 08-05-2014
0 4
0
4
newbiesplunk
Hi, when i forward my input files (c:\data) from server A to Splunk Head at ServerB, the date format was correct for ...
by newbiesplunk Path Finder in Getting Data In 08-05-2014
0 6
0
6
shangshin
Hi, In Splunk 6, I can see the peers, search heads and index names from the master GUI. I am trying to find the eq...
by shangshin Builder in Getting Data In 08-05-2014
1 2
1
2
splunkn
How do I extract what are all the universal forwarders (deployment clients) contacting the deployment server?I want t...
by splunkn Communicator in Getting Data In 08-05-2014
0 5
0
5
kratikaj07
Is it possible to index excel spreadsheet data(.xls,.xlsx)without converting data into binary . Do we need to first c...
by kratikaj07 Explorer in Getting Data In 08-05-2014
1 3
1
3
spoorthyredi
All, We configured splunk to index data from a Oracle DataBase using Splunk DB Connect App . Our database tables an...
by spoorthyredi New Member in Getting Data In 08-04-2014
0 3
0
3
NK_1
C:\Program Files\Splunk\etc\system\local\props.conf contains [YYY] TIME_PREFIX = timestamp= SHOULD_LINEMERGE = fals...
by NK_1 Path Finder in Getting Data In 08-04-2014
0 1
0
1
tdewberry
I have this in my windows DC server with Universal Forwarder v 6.1.1. ..\Splunk_TA_Windows\local\inputs.conf file: ...
by tdewberry New Member in Getting Data In 08-04-2014
0 1
0
1
calvintkng
I've a csv file containing thousands of events, each event is only single line with date time stamp and several other...
by calvintkng New Member in Getting Data In 08-04-2014
0 7
0
7
bcusick
Hi, One of my forwarders is monitoring a directory where timestamped files populate every five minutes. The text ou...
by bcusick Communicator in Getting Data In 08-04-2014
0 4
0
4
adelucaa
We have a heavy forwarder set up on our log server. It is sending to rsyslog and then forwarding to the indexer. If...
by adelucaa New Member in Getting Data In 08-02-2014
0 2
0
2
splunkIT
I have setup the following inputs.conf stanza : [WinEventLog://Security] disabled=0 current_only=1 blacklist1=Eve...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 08-01-2014
0 2
0
2
dhavamanis
Can you please provide sample configuration for the below, We have multiple forwarding sources and they are using sys...
by dhavamanis Builder in Getting Data In 08-01-2014
0 5
0
5
aelliott
I would like to split a field called "destination" and "original_source" into 2 fields, each is an ip:port or [ipv6]:...
by aelliott Motivator in Getting Data In 08-01-2014
1 4
1
4
jimjh
I have directory paths that look like /year=2014/month=6/day=4/hour=1/ However, using the following regex is subop...
by jimjh Path Finder in Getting Data In 08-01-2014
0 1
0
1
jimjh
How do I specify Ctrl-A (\u0001) as a field delimiter in props.conf? I tried [xxx] FIELD_DELIMITER=\x01 [xxx] FIEL...
by jimjh Path Finder in Getting Data In 08-01-2014
1 1
1
1
mattchapple
I'm struggling to get my Splunk 6.0.1 to recognise an epoch time for all events. I have specified a timestamp format ...
by mattchapple Explorer in Getting Data In 08-01-2014
1 6
1
6
abn
Hi, I am generating a report using data from database. I have a tabular format in my CSV. Is it possible via Splunk ...
by abn New Member in Getting Data In 08-01-2014
0 1
0
1
rune_hellem
Indexing a lot of SystemOut.log files from WebSphere I realize that all almost all log files uses the following time ...
by rune_hellem Contributor in Getting Data In 08-01-2014
3 3
3
3
axl88
Hi all, I was assigned to push a fix on forwarders since they are forwarding data with auto-naming on index and sourc...
by axl88 Communicator in Getting Data In 08-01-2014
1 4
1
4
chrismullen
Hi, I'm wondering if there is a way to prevent a sensitive key-value pair that exists in cs_Cookie from appearing in...
by chrismullen Explorer in Getting Data In 07-31-2014
1 5
1
5
menkurau
I have a lot of fields called EXTRA_FIELD_X and I am not sure why. I have not been able to find anything on Answers ...
by menkurau Path Finder in Getting Data In 07-31-2014
0 3
0
3
mireyaco
Hi, I have Splunk 5.0.5 installed on a Windows OS 2012 I have a windows 2008 64-bit with splunkforwarder-6.1.2-2130...
by mireyaco New Member in Getting Data In 07-31-2014
0 1
0
1
aelliott
When attempting to use the following suggestion on blacklisting 4662 events, I run into an error in splunkd.log http...
by aelliott Motivator in Getting Data In 07-31-2014
0 2
0
2
Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...
Top Solution Authors