Getting Data In

Getting Data In
Community Activity
luv
Hi For whitelist:- I have following logs under my  directory D:/logs/abcUSEFUL.log D:/logs/xyzUSEFUL.log D:/logs/abc...
by luv Explorer in Getting Data In 11-19-2013
0 3
0
3
jgauthier
This might seem like a dorky question, but after searching answers and apps... I came up mostly empty. Are there any...
by jgauthier Contributor in Getting Data In 11-19-2013
0 1
0
1
nl_cape
I'm trying to index JVM garbage collection logs. I'm having trouble getting the event delimiting to work, however. Be...
by nl_cape Explorer in Getting Data In 11-19-2013
0 2
0
2
srajanbabu
How to change the format of the input data to our need before indexing in splunk. My original lof is in the format. S...
by srajanbabu Explorer in Getting Data In 11-19-2013
1 5
1
5
ppurokit
Hi All, I have a very basic doubt with respect to all the *.conf files. I have transforms.conf , props.conf and al...
by ppurokit Path Finder in Getting Data In 11-19-2013
0 2
0
2
shankarbandaru
Hi, I am new to Splunk and just trying to add data to it. I have a Raspberry Pi connected with temperature sensors a...
by shankarbandaru Engager in Getting Data In 11-18-2013
1 1
1
1
somesoni2
Hi, I am trying to setup forwarding on my Splunk instance and need information about the following stanza in etc/sys...
by Revered Legend in Getting Data In 11-18-2013
0 1
0
1
jgautreau
Hi, When i input data from files & directories in splunk, is there a way to ignore the first row (column headers) in ...
by jgautreau Explorer in Getting Data In 11-18-2013
1 4
1
4
abhayneilam
Hi, I have an index called "XYZ" and in it i have a file called "abc.txt" and I am taking the help of a configuratio...
by abhayneilam Contributor in Getting Data In 11-18-2013
0 4
0
4
andykiely
I am using a host segment to set a 'hostname' (we have multiple hosts on one box) as set out below: [monitor://c:\lo...
by andykiely Path Finder in Getting Data In 11-18-2013
0 6
0
6
tyronetv
Sample log line date part: Nov 16 22:48:36 props.conf on indexer TIME_PREFIX = ^ TIME_FORMAT = %b %e %H:%M:%S MA...
by tyronetv Communicator in Getting Data In 11-18-2013
0 1
0
1
flucman
I am having issues filtering data into nullQueue. I have a log where the only lines I want indexed have the string "...
by flucman Explorer in Getting Data In 11-18-2013
0 3
0
3
rbw78
Hello I have issue to make work the Cisco IPS app under splunk. I made it works the first time indexing correctly t...
by rbw78 Communicator in Getting Data In 11-18-2013
2 6
2
6
sunrise
WMIポーリングで取得したWindowsイベントログをSEDCMD属性で置換したいのですが、 下記のprops.confを設定してもうまく置換されません。 何か対応方法ございますでしょうか。 <props.conf> [WMI:W...
by sunrise Contributor in Getting Data In 11-18-2013
0 3
0
3
a212830
Hi, How would I setup a monitor in inputs.conf that looks for files that begin with "system-" and will process every...
by a212830 Champion in Getting Data In 11-16-2013
0 2
0
2
rmorlen
I have an inputs.conf file that had a monitor statement like: [monitor:///*_ECM/A/doc/abc.log] Files are NOT being ...
by rmorlen Splunk Employee Splunk Employee in Getting Data In 11-15-2013
0 5
0
5
mjones414
I've written a little python one-liner that basically calls showmount -a with an argv array at the end and my goal is...
by mjones414 Contributor in Getting Data In 11-15-2013
0 1
0
1
echalex
Hi, We are having some DNS issues in our infrastructure. Apparently the name servers our splunk hosts are using are ...
by echalex Builder in Getting Data In 11-15-2013
0 4
0
4
jrich523
I get the following error: ERROR BucketMover - aborting move because recursive copy from src='C:\Program Files\Splun...
by jrich523 Path Finder in Getting Data In 11-15-2013
0 1
0
1
luv
10:32:21,453 INFO [2212] abcdxyz <-| 10:32:21,112 INFO [2212] abcdxyz | 10:32:22,409 INFO [1121] abcdxyz | 10:32:...
by luv Explorer in Getting Data In 11-15-2013
0 12
0
12
leonrtx
I want to display all mail to and from a client, with the subject, relayed host and status in one dashboard. The das...
by leonrtx Explorer in Getting Data In 11-15-2013
0 8
0
8
tprzelom
props.conf: [pan_event] TRANSFORMS-traffic = traffic_source transforms.conf: [traffic_source] REGEX = (,TRAFFIC,) FO...
by tprzelom Path Finder in Getting Data In 11-15-2013
1 8
1
8
a212830
Hi, Is there a way to setup inputs.conf so that a default sourcetype (and it's associated props) will be used, unles...
by a212830 Champion in Getting Data In 11-15-2013
0 4
0
4
himynamesdave
I have a static JSON file (240k lines) I would like to index. Here's a the format: {"name":"fuel_level","value":88.2...
by himynamesdave Contributor in Getting Data In 11-15-2013
0 3
0
3
ruisantos
I'm trying to remove some of the events that should be forwarded to the frontend. From a configuration perspective ev...
by ruisantos Path Finder in Getting Data In 11-15-2013
0 2
0
2
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...
Top Solution Authors