Getting Data In

Getting Data In
Community Activity
matthewhaswell
Unfortunately our production Splunk was connected to a test system splunkforwarder by mistake and according to the Su...
by matthewhaswell Path Finder in Getting Data In 01-29-2014
0 3
0
3
himynamesdave
Hi all. I have built a simple scripted input that grabs XML data over http: #!/bin/bash curl http://www.a.com/EN.XM...
by himynamesdave Contributor in Getting Data In 01-29-2014
0 2
0
2
chimbudp
I have configured the inputs.conf to monitor the log file of NetFlow logic Since the log file is in unreadable format...
by chimbudp Contributor in Getting Data In 01-28-2014
1 2
1
2
Ricapar
I'll ask this question in two ways in hope I can convey my intentions properly: Generic Scenario When you log into ...
by Ricapar Communicator in Getting Data In 01-28-2014
0 4
0
4
chimbudp
I have a windows platform . Splunk universal forwarder is deployed to collect the logs from a Citrix Xen app server. ...
by chimbudp Contributor in Getting Data In 01-28-2014
0 1
0
1
rakesh_498115
Hi.. I have a created a regex called "ClientDetails" in props.conf and i need two more fields from this extracted fi...
by rakesh_498115 Motivator in Getting Data In 01-28-2014
0 1
0
1
yoho
My indexers and searchheads in my central datacentre are configured in UTC timestamp but I have universal/light forwa...
by yoho Contributor in Getting Data In 01-28-2014
2 3
2
3
FaceF18
I'm trying to set the sourcetype on some events I get based on their contents, and then I want to send each of those ...
by FaceF18 New Member in Getting Data In 01-27-2014
0 2
0
2
Kendo213
I need to index data from an appliance we have, however in the appliance you can only specify one syslog server. How...
by Kendo213 Communicator in Getting Data In 01-27-2014
0 1
0
1
dejager
Ok I am lost. I have a universal forwarder installed on a Win server I have the Splunk Web Interface (on separate ser...
by dejager Explorer in Getting Data In 01-27-2014
0 4
0
4
rrmavani
In our environment, We have Universal forwarder, Indexers and search head. We have different approximate 20-22 splunk...
by rrmavani Engager in Getting Data In 01-25-2014
0 10
0
10
rdownie
Is there a way to use a rex command with mode=sed against a specific field in a config file (props.conf)?? I understa...
by rdownie Communicator in Getting Data In 01-24-2014
0 1
0
1
ocallender
I have a .csv file with several fields. there are many date fields and text fields, but fields are long blobs of text...
by ocallender Explorer in Getting Data In 01-24-2014
0 2
0
2
_gkollias
I'd like to start forwarding data from a server which is now "unsupported". Normally, I would install a forwarder by...
by _gkollias Builder in Getting Data In 01-24-2014
0 5
0
5
hagjos43
My searchstring looks like this: index=123 sourctype=xyz EventCode=4624 | timechart span=1h count This gives me ...
by hagjos43 Contributor in Getting Data In 01-24-2014
0 2
0
2
mookiie2005
We have a script that splunk executes every minute on the minute...only problem is we do not have this scheduled as a...
by mookiie2005 Communicator in Getting Data In 01-24-2014
0 13
0
13
dolxor
Hello. I'm creating an Event Type like this; curl -k -u RESTUser:RESTPass https://localhost:8089/servicesNS/RESTUse...
by dolxor Path Finder in Getting Data In 01-24-2014
1 2
1
2
clyde772
Hey Gurus! I am processing F/W log such as below which I recieve through syslog server. 2010-06-29T20:48:26.742950+...
by clyde772 Communicator in Getting Data In 01-24-2014
2 11
2
11
di2esysadmin
An inputs.conf entry: [monitor:///opt/atlassian/.../*.log] sourcetype=atlassian crcSalt = SOURCE (pretend there...
by di2esysadmin Path Finder in Getting Data In 01-23-2014
0 1
0
1
fabiocaldas
I work with UniversalForwarders (136 servers) sending data to a Heavy Forwarder Cluster (3 servers) that forward data...
by fabiocaldas Contributor in Getting Data In 01-23-2014
0 4
0
4
leon24
Hi all, I have a log file with many rows. However, I tried to change the settings in /etc/system/local/props.conf M...
by leon24 Explorer in Getting Data In 01-23-2014
0 1
0
1
Gilgalidd
Hello, I trying to retrieve all login/off/fail on my inderxer from UniversalForwarder filtered by Heavy forwarder : ...
by Gilgalidd Path Finder in Getting Data In 01-22-2014
0 4
0
4
tacleal
I have not been able to find a solution although there are questions with the same/similar symptom. My log files are ...
by tacleal Engager in Getting Data In 01-22-2014
1 3
1
3
khhenderson
I have log files that I would like to get into Splunk but I'm having trouble due to the way the date and time are for...
by khhenderson Path Finder in Getting Data In 01-22-2014
1 5
1
5
crazyeva
timeformat is not desired, I tried SEDCMD to correct it(12-hour format with 'am','pm') props.conf of INDEXER: SEDCMD...
by crazyeva Contributor in Getting Data In 01-22-2014
2 4
2
4
Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...
Top Solution Authors