| We recently move to S2 and our initial retention was set to 6 months. A month after the migration we decided to reduc... by athorat Communicator in Getting Data In 10-03-2023 0 1 | 0 | 1 | ||
| We wonder about using SmartStore. Does it make sense to use it for all data except hot and warm data? Even if we end ... by danielbb Motivator in Getting Data In 10-03-2023 1 7 | 1 | 7 | ||
| Hello comrades,After my poor research, I found that only heavy forwarder supports props.conf, but it was like 5 or 6 ... by BoldKnowsNothin Path Finder in Getting Data In 10-02-2023 0 12 | 0 | 12 | ||
| HI Community,I have been tasked with getting AWS Cloudtrail logs into Splunk. I have spent some time not just reading... by yackle_official New Member in Getting Data In 10-02-2023 0 0 | 0 | 0 | ||
| Im trying to break out the comma separated values in my results but im brain farting. I want to break out the specifi... by Dallastek1 Path Finder in Getting Data In 10-02-2023 0 2 | 0 | 2 | ||
| I would like to understand better how transformations work, in terms of priority and data flow.Let's say I have 3 tra... by cmlombardo Path Finder in Getting Data In 10-02-2023 0 6 | 0 | 6 | ||
| Hello there.I have IIS logs being ingested into Splunk.The sourcetype is currently set to "iis:test"props.conf:[iis:t... by cmlombardo Path Finder in Getting Data In 10-02-2023 0 4 | 0 | 4 | ||
| Hello everyone! Do anybody know, is it possible to aggregate (bind) auditd events (I mean logs from audit/audit.log) ... by bosseres Contributor in Getting Data In 10-02-2023 0 3 | 0 | 3 | ||
| Hello comrades, I'm just curios is there anyway to shorten frequent words?For example: <Data Name='IpAddress'>::ffff:... by BoldKnowsNothin Path Finder in Getting Data In 10-02-2023 0 7 | 0 | 7 | ||
| HiI'm currently working on obtaining Windows Filtering Platform event logs to identify the user responsible for runni... by CyberCyber New Member in Getting Data In 09-30-2023 0 1 | 0 | 1 | ||
| I wonder if the activity of deleting audit events from Splunk cloud will be logged/tracked in Splunk internal logs, e... by just4testsplunk New Member in Getting Data In 09-29-2023 0 6 | 0 | 6 | ||
| Hi, i want to send out data with an forwarder to a splunk indexer hosted in the web like splunk storm. Is it possi... by Matthias_BY Communicator in Getting Data In 09-29-2023 1 6 | 1 | 6 | ||
| Hello,I was trying to explore all the null values in my index but is it not working as expected do we need any change... by smith_ Builder in Getting Data In 09-29-2023 0 5 | 0 | 5 | ||
| Hi,I had blacklisted C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe in inputs.conf of Deploymentserve... by smith_ Builder in Getting Data In 09-29-2023 0 3 | 0 | 3 | ||
| I recently upgraded or rather installed a Splunk UF version 9.1.1 which communicates back to Splunk Cloud but I seem ... by blazingblu New Member in Getting Data In 09-28-2023 0 3 | 0 | 3 | ||
| Hi All, Can any one pls share a regex for the below events to exclude(text in red). 1.<Event xmlns='http://schemas.mi... by smith_ Builder in Getting Data In 09-27-2023 0 11 | 0 | 11 | ||
| Hello everybody, i am wondering if anybody already do some Tableau System Monitoring with the Logs Tableau provided?... by splk Communicator in Getting Data In 09-27-2023 1 3 | 1 | 3 | ||
| Hello,looks like when we enable or disable app from deployment server (GUI for instance) then app.conf in deployment-... by splunkreal Influencer in Getting Data In 09-27-2023 0 0 | 0 | 0 | ||
| Good day, I'm trying to filter connection events from FMC eStreamer, i.e. I do not need Allowed connections in Splun... by halfreeman New Member in Getting Data In 09-27-2023 0 10 | 0 | 10 | ||
| I had a interview question that what is search sequence of knowledge object in splunk.Please helpme regarding this, by karthi2809 Builder in Getting Data In 09-27-2023 0 1 | 0 | 1 | ||
| Hi Friends, I want to know 2 things as mentioned below: What is the typical CPU & Memory consumption of Splunk Forw... by govinduk New Member in Getting Data In 09-27-2023 0 4 | 0 | 4 | ||
| I would like help with creating the following.Search when account was created and return a list of users who have not... by KDWilk Loves-to-Learn in Getting Data In 09-26-2023 0 1 | 0 | 1 | ||
| Hi Everyone,after i select the source type i am getting below error while using ingest actions. I had to update the p... by SS1 Path Finder in Getting Data In 09-26-2023 2 0 | 2 | 0 | ||
| Hello, recently I've added a new firewall as a source to the splunk solution at work but I can't figure why my LINE_B... by Berfomet96 Explorer in Getting Data In 09-26-2023 0 1 | 0 | 1 | ||
| Hi,in the official compatibility matrix there is no column for Indexer 8.0.x anymore as its no longer supported.https... by gebr Explorer in Getting Data In 09-26-2023 0 2 | 0 | 2 |