Getting Data In

Getting Data In
Community Activity
feltsb
I would like to import a tab delimited text file, where the first line of the file contains field names instead of fi...
by feltsb New Member in Getting Data In 04-03-2014
0 3
0
3
premg
Hi, We need to forward all events to indexer group_A and filtered events to indexer group_B. We are applying some t...
by premg Engager in Getting Data In 04-03-2014
0 4
0
4
Bill_B
Can a heavy forwarder be configured to queue event data and hold it until a specified time? Can some data be queued a...
by Bill_B Communicator in Getting Data In 04-02-2014
0 1
0
1
motobeats
I added Apache logs from 2 webservers to Splunk in two batches a week apart. Dropped the files in a folder that I hav...
by motobeats Path Finder in Getting Data In 04-02-2014
0 3
0
3
jszyba
I'm trying to monitor a log file to a splunk universal forwarder. For example the splunkd.log file. I've tried gettin...
by jszyba New Member in Getting Data In 04-02-2014
0 2
0
2
moohkhol
Today I have change configuration of forwarder and restarted it, after restart it is forwarding previous events as we...
by moohkhol New Member in Getting Data In 04-02-2014
0 2
0
2
gregwilliams
I am attempting to recover from a hard crash, through no fault of Splunk's. Is it possible to unzip /rawdata/journal...
by gregwilliams Path Finder in Getting Data In 04-02-2014
0 3
0
3
Parameshwara
[test_header] INDEXED_EXTRACTIONS = CSV HEADER_FIELD_LINE_NUMBER = 1 KV_MODE = none NO_BINARY_CHECK = 1 SHOULD_LINEME...
by Parameshwara Path Finder in Getting Data In 04-01-2014
0 10
0
10
jedatt01
I have a modular input that collects data from a webservice. The events are not collected in realtime so to get the t...
by jedatt01 Builder in Getting Data In 04-01-2014
0 6
0
6
jlaverick1
Hi, I have some data extracted from a table in an SQL database which has 39 columns and uses a semicolon as a field ...
by jlaverick1 New Member in Getting Data In 04-01-2014
0 4
0
4
neiljpeterson
The forwarding from this directory was working previous to the clean. My understanding was this was supposed to clean...
by neiljpeterson Communicator in Getting Data In 04-01-2014
0 9
0
9
aelliott
I have a log file that is tab delimited. It has a field called "date" and a field called "time" next to each other. T...
by aelliott Motivator in Getting Data In 04-01-2014
0 11
0
11
danilom
Hello, I would like to sent to nullQueue some windows security events based on some regex. So I have defined: props....
by danilom Explorer in Getting Data In 04-01-2014
0 2
0
2
ncorby
I have set up a Data input in Splunk which allows me to search a series of CSV files conatined within this folder. Ea...
by ncorby New Member in Getting Data In 04-01-2014
0 4
0
4
SplunkCSIT
Due to some error, i had deleted the test123 indexes at indexer, restart the indexer, create the test123 again. But s...
by SplunkCSIT Communicator in Getting Data In 04-01-2014
0 5
0
5
nikhilmehra79
I am trying to do this: Universal Forwarder1--> TCP 9997 --> Universal Forwarder2--> TCP 9997 --> Indexer (Search Hea...
by nikhilmehra79 Path Finder in Getting Data In 04-01-2014
0 2
0
2
RichPierre
Good evening, I have a question: I have a sourcetype A with a field "ip" and a "name" I have a sourcetype B with a f...
by RichPierre Engager in Getting Data In 04-01-2014
0 4
0
4
athannie92
Hey I am trying to put data into my splunk using the TCP option and splunk is asking for my tcp port but I dont know ...
by athannie92 New Member in Getting Data In 04-01-2014
0 1
0
1
Face_it
I have been trying to grab results from a macro that i created. I think the problem is the backticks, even when i esc...
by Face_it New Member in Getting Data In 03-31-2014
0 2
0
2
ifeldshteyn
At random I am getting a strange heavy forwarder issue that no one seems to have received before (google comes up wit...
by ifeldshteyn Communicator in Getting Data In 03-31-2014
2 8
2
8
tararso
I have configured the index.conf homePath = C:\DB\index1\db thawedPath = C:\DB\index1\thaweddb frozenTimePeriodInSecs...
by tararso Explorer in Getting Data In 03-31-2014
0 1
0
1
Runals
I realized the other day we are no longer seeing instances of $decideonstartup in the host field for some of our logs...
by Runals Motivator in Getting Data In 03-31-2014
0 1
0
1
Erik_Swan
I have a large archive of old data i want to load while also loading new real-time data. What is the most efficient...
by Erik_Swan Splunk Employee Splunk Employee in Getting Data In 03-31-2014
2 5
2
5
craigmunro
Hi I have a load of warnings in splunkd.log like: 06-15-2011 09:02:23.860 +0100 WARN DateParserVerbose - A possibl...
by craigmunro Path Finder in Getting Data In 03-31-2014
0 6
0
6
templier
Hello, friends! We have: Splunk server (indexer) and computer with WinXP and UniversalForwarder. The task was to rem...
by templier Communicator in Getting Data In 03-31-2014
1 9
1
9
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...