Getting Data In

Getting Data In
Community Activity
bwooden
Do I need to escape the | (pipe character) for a TIME_FORMAT in props.conf? Example Timestamp: 2014-02-07 || 5:3...
by bwooden Splunk Employee Splunk Employee in Getting Data In 02-07-2014
0 1
0
1
tsunamii
It appears that this issue still persists in DB Connect 1.1.2: http://docs.splunk.com/Documentation/DBX/1.1.2/Deploy...
by tsunamii Path Finder in Getting Data In 02-07-2014
0 3
0
3
bruceclarke
All, I'm curious, is there an easy way to find all duplicate logs and delete all but one of them? Thanks!
by bruceclarke Contributor in Getting Data In 02-07-2014
0 1
0
1
jimjohn
I have added a folder to read CSV files through data input >files and directory option. It seems that when I add a ne...
by jimjohn Path Finder in Getting Data In 02-07-2014
0 3
0
3
jimjohn
Hi How can i add current time to _time filed while reading data from CSV file. I have added below in Splunk\etc\syst...
by jimjohn Path Finder in Getting Data In 02-07-2014
1 2
1
2
Jiamin
Hi, I currently writing prop configure to validate my event Events Feb 03 13:22:23 Jessica-Ubuntu kernel: [ 7098....
by Jiamin New Member in Getting Data In 02-06-2014
0 2
0
2
a212830
Hi, I have a multi-line feed with two diffferent timestamp formats? How would I handle that? The formats are very ...
by a212830 Champion in Getting Data In 02-06-2014
0 5
0
5
rdownie
Is it possible to configure multiple Universal Forwarders to forward their data to another Universal Forwarder that w...
by rdownie Communicator in Getting Data In 02-06-2014
0 1
0
1
grahamkenville
We have a sourcetype for /var/log/messages that is logged in the local server time on almost every host. We have on...
by grahamkenville Engager in Getting Data In 02-06-2014
0 2
0
2
Torben_Volkmann
Hello, Is it possible to use a heavy forwarder as deployment server, too? I try to install 2 servers like this: http...
by Torben_Volkmann New Member in Getting Data In 02-06-2014
0 2
0
2
theouhuios
Hello I am trying to connect DB Connect to a MS SQL server and facing few issues with it. 2014-02-06 11:03:20.774 ...
by theouhuios Motivator in Getting Data In 02-06-2014
1 2
1
2
mbstein
We're new to clusters, so probably we made a stupid mistake or did not yet read an important chapter in the manual. ...
by mbstein Engager in Getting Data In 02-06-2014
0 1
0
1
SplunkBaby
Hi I want to add multiple CSV files to a folder and want spunk to read all the CSV files in that folder. Ie if i put ...
by SplunkBaby Explorer in Getting Data In 02-06-2014
0 1
0
1
darshan_singh01
Hi , While integrating Splunk (via S3 app) with AWS S3 ,we are finding the below error . A connection attempt faile...
by darshan_singh01 Path Finder in Getting Data In 02-06-2014
0 3
0
3
sibanandapani
We need to have a rest service to our saved searches, where we can pass the start time and end time and the name of t...
by sibanandapani New Member in Getting Data In 02-05-2014
0 4
0
4
trzcionek
How can I get event log from CIFS EMC with use powershell? When I use something like below, always Splunk indexes onl...
by trzcionek New Member in Getting Data In 02-05-2014
0 4
0
4
hiddenkirby
I can't seem to find the list of indexer nodes (search peers) through the rest api on the search head. any ideas? i...
by hiddenkirby Contributor in Getting Data In 02-05-2014
1 2
1
2
andrewkenth
Is there a way to find the source of a job that ran? For instance is it on a dashboard or is it a preconfigured repor...
by andrewkenth Communicator in Getting Data In 02-05-2014
0 1
0
1
maciep
I was hoping somebody could clarify something for me. With the "Splunk for Exchange" app, is Blackberry Enterprise S...
by maciep Champion in Getting Data In 02-05-2014
1 2
1
2
a212830
Hi, Can someone explain to me the difference between the light/universal/heavy forwarders? Where can I download the ...
by a212830 Champion in Getting Data In 02-05-2014
0 4
0
4
jamesvz84
Hello, I have a log where I need to treat each line as an event. I set up the sourcetype in props.conf for this to h...
by jamesvz84 Communicator in Getting Data In 02-05-2014
0 2
0
2
mtmoore
Our data's date field uses UTC for all data across the globe for this one set of data. This is fine. When a user ru...
by mtmoore Explorer in Getting Data In 02-05-2014
0 3
0
3
SplunkBaby
I have a splunk instance and I use splunk DB connect to read data from database. Is it possible to forward this data ...
by SplunkBaby Explorer in Getting Data In 02-05-2014
0 2
0
2
annebeate
Hi, I have a index which should only have data for the past 3 hours. I've set the frozenTimePeriodInSecs to 10800. I...
by annebeate Path Finder in Getting Data In 02-05-2014
0 3
0
3
rmorlen
I would like to get a total count of the number of scheduled searches and ad-hoc (UI based) searches that are run per...
by rmorlen Splunk Employee Splunk Employee in Getting Data In 02-04-2014
1 3
1
3
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling ...

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...
Top Solution Authors