Getting Data In

Getting Data In
Community Activity
jedatt01
I have a modular input that collects data from a webservice. The events are not collected in realtime so to get the t...
by jedatt01 Builder in Getting Data In 04-01-2014
0 6
0
6
jlaverick1
Hi, I have some data extracted from a table in an SQL database which has 39 columns and uses a semicolon as a field ...
by jlaverick1 New Member in Getting Data In 04-01-2014
0 4
0
4
neiljpeterson
The forwarding from this directory was working previous to the clean. My understanding was this was supposed to clean...
by neiljpeterson Communicator in Getting Data In 04-01-2014
0 9
0
9
aelliott
I have a log file that is tab delimited. It has a field called "date" and a field called "time" next to each other. T...
by aelliott Motivator in Getting Data In 04-01-2014
0 11
0
11
danilom
Hello, I would like to sent to nullQueue some windows security events based on some regex. So I have defined: props....
by danilom Explorer in Getting Data In 04-01-2014
0 2
0
2
ncorby
I have set up a Data input in Splunk which allows me to search a series of CSV files conatined within this folder. Ea...
by ncorby New Member in Getting Data In 04-01-2014
0 4
0
4
SplunkCSIT
Due to some error, i had deleted the test123 indexes at indexer, restart the indexer, create the test123 again. But s...
by SplunkCSIT Communicator in Getting Data In 04-01-2014
0 5
0
5
nikhilmehra79
I am trying to do this: Universal Forwarder1--> TCP 9997 --> Universal Forwarder2--> TCP 9997 --> Indexer (Search Hea...
by nikhilmehra79 Path Finder in Getting Data In 04-01-2014
0 2
0
2
RichPierre
Good evening, I have a question: I have a sourcetype A with a field "ip" and a "name" I have a sourcetype B with a f...
by RichPierre Engager in Getting Data In 04-01-2014
0 4
0
4
athannie92
Hey I am trying to put data into my splunk using the TCP option and splunk is asking for my tcp port but I dont know ...
by athannie92 New Member in Getting Data In 04-01-2014
0 1
0
1
Face_it
I have been trying to grab results from a macro that i created. I think the problem is the backticks, even when i esc...
by Face_it New Member in Getting Data In 03-31-2014
0 2
0
2
ifeldshteyn
At random I am getting a strange heavy forwarder issue that no one seems to have received before (google comes up wit...
by ifeldshteyn Communicator in Getting Data In 03-31-2014
2 8
2
8
tararso
I have configured the index.conf homePath = C:\DB\index1\db thawedPath = C:\DB\index1\thaweddb frozenTimePeriodInSecs...
by tararso Explorer in Getting Data In 03-31-2014
0 1
0
1
Runals
I realized the other day we are no longer seeing instances of $decideonstartup in the host field for some of our logs...
by Runals Motivator in Getting Data In 03-31-2014
0 1
0
1
Erik_Swan
I have a large archive of old data i want to load while also loading new real-time data. What is the most efficient...
by Erik_Swan Splunk Employee Splunk Employee in Getting Data In 03-31-2014
2 5
2
5
craigmunro
Hi I have a load of warnings in splunkd.log like: 06-15-2011 09:02:23.860 +0100 WARN DateParserVerbose - A possibl...
by craigmunro Path Finder in Getting Data In 03-31-2014
0 6
0
6
templier
Hello, friends! We have: Splunk server (indexer) and computer with WinXP and UniversalForwarder. The task was to rem...
by templier Communicator in Getting Data In 03-31-2014
1 9
1
9
shangshin
Hi I am able to send log4j log data to splunk over tcp network but the data in splunk is not human readable.(see belo...
by shangshin Builder in Getting Data In 03-31-2014
2 1
2
1
helge
I am sending data to a TCP port I configured for input on the Splunk server. How should the (string) data be encoded ...
by helge Builder in Getting Data In 03-31-2014
0 1
0
1
SplunkCSIT
how come when i configured the data in the heavy forwarder, sometimes it will created in launcher folder /etc/apps/la...
by SplunkCSIT Communicator in Getting Data In 03-31-2014
0 3
0
3
t_nakayama
現在Splunk6.0.2に対して、curlコマンドで直接JSONデータを入力できないかと試しています。 TCP:10000をtcp-rawポートに設定しています。 curl -X POST -d 'json={"tag":"val...
by t_nakayama Engager in Getting Data In 03-30-2014
1 2
1
2
SplunkCSIT
Can we forward logs to two different indexer, if it a manual task such that to change at the inputs.conf and outputs....
by SplunkCSIT Communicator in Getting Data In 03-30-2014
0 4
0
4
thierryit
Hi, Running both Splunk server and Splunkforwarder on V6.0.2. Both machine (web server and Splunk server) have their...
by thierryit Path Finder in Getting Data In 03-29-2014
0 25
0
25
rmcdougal
I am attempting to override the sourcetype of an event that is coming in on UDP:516 based on the host address but I h...
by rmcdougal Path Finder in Getting Data In 03-29-2014
0 2
0
2
romitsn
I have the following entry in my $SPLUNK_HOME/etc/system/local/inputs.conf file -- [monitor:///appl/sharp/logs/*.fip...
by romitsn New Member in Getting Data In 03-28-2014
0 1
0
1
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...
Top Solution Authors