Getting Data In

Getting Data In
Community Activity
a212830
Hi, How would I route raw data via tcp to an external system (based upon sourcetype or host), but also index that da...
by a212830 Champion in Getting Data In 09-11-2013
0 1
0
1
tonyArad
Is it possible to use Splunk as a data storage server and build an application that will send the data contained by S...
by tonyArad Engager in Getting Data In 09-11-2013
0 4
0
4
mcm10285
Does splunk read $SPLUNKHOME/etc/apps/search/lookups in a special manner? I placed a csv file in that directory of a...
by mcm10285 Communicator in Getting Data In 09-10-2013
0 6
0
6
aaronpmcconnell
I'm trying to output an alert via syslog to our Orion server. Any suggestions on how to do that?
by aaronpmcconnell New Member in Getting Data In 09-10-2013
0 3
0
3
hartfoml
I am collecting syslog using syslog-ng. the events collected in the file are showing GMT. When I setup a file monit...
by hartfoml Motivator in Getting Data In 09-10-2013
0 3
0
3
mtamayo79
Hi, I,am having problem with the configuration inputs.conf file, I'm monitoring remote computer with universal forw...
by mtamayo79 Engager in Getting Data In 09-10-2013
2 4
2
4
fabiocaldas
I create a toplogy with one Splunk Indexer using a Master Enterprise License, and 2 HeavyForwarders using Slave Licen...
by fabiocaldas Contributor in Getting Data In 09-10-2013
0 6
0
6
ryanholland
I would like to be able to provide a timestamp and have splunk return the log nearest/before the timestamp and neares...
by ryanholland Explorer in Getting Data In 09-10-2013
0 3
0
3
mike_cmxx
Hi, I'm currently performing an evaluation on Splunk, so I am very new at this. I have a few questions concerning tim...
by mike_cmxx New Member in Getting Data In 09-09-2013
0 3
0
3
InteractM
I have a dedicated syslog server running on CentOS6 (rsyslog) which gathers all logs from other servers/devices (stor...
by InteractM Explorer in Getting Data In 09-09-2013
1 4
1
4
pcjunkie
In Server 2008 and above the Windows Event Log has a general tab and a details tab. Splunk is great at polling and in...
by pcjunkie Explorer in Getting Data In 09-09-2013
1 3
1
3
cloud_cloud
How to send filtered system log errors only to syslog and NOT index that data? My current configuration send to sysl...
by cloud_cloud Explorer in Getting Data In 09-09-2013
0 3
0
3
johnwyane
Hi, I met one log file that have two timestamps on different field. The first one is the exported time by program o...
by johnwyane New Member in Getting Data In 09-09-2013
0 3
0
3
xvxt006
We have the events in the below format and i was thinking i would see the fields without any extraction. But that did...
by xvxt006 Contributor in Getting Data In 09-09-2013
0 3
0
3
mj9999
I am using splunk-5.0.4-172409-x64 for Windows and can't get the time zone to offset from GMT to CDT. I have changed ...
by mj9999 New Member in Getting Data In 09-08-2013
0 4
0
4
MHibbin
Hey, Just wondered if anyone has seen this issue in their environment? I noticed, by chance, that our license usage...
by MHibbin Influencer in Getting Data In 09-08-2013
0 2
0
2
wanted819
Hi, I have installed splunk in centos and it is working fine. And i have installed the universal forwarder in anothe...
by wanted819 Engager in Getting Data In 09-08-2013
0 1
0
1
amanteja
Here is the situation We have a splunk forwarder installed (from rpm), but never started in an Amazon AMIWhat we wan...
by amanteja Path Finder in Getting Data In 09-07-2013
1 1
1
1
mark_law
I have this in transforms.conf to match a specific subset of syslog events I'm interested in. [setparsing] REGEX = ...
by mark_law Engager in Getting Data In 09-06-2013
0 2
0
2
trumpjk
I have systems that forward logs via syslog-ng to my splunk server. Systems are in different TZ's mix of EDT and GMT ...
by trumpjk Explorer in Getting Data In 09-06-2013
0 1
0
1
richnavis
Hi All, I ran into an issue where certain searches seem to caused scripted alert actions to fail. In trying to figu...
by richnavis Contributor in Getting Data In 09-06-2013
0 5
0
5
wbordeau
Hello, I have an issue in which my searches are suddenly offset by one field. In other words, the Action field now c...
by wbordeau Explorer in Getting Data In 09-06-2013
0 2
0
2
smile_4u_2
I am new to Splunk and am attempting to forward Splunk WMIEventLog:Security to syslog_ng with a backend MYSQL. This ...
by smile_4u_2 New Member in Getting Data In 09-06-2013
0 2
0
2
rtadams89
If I perform a search for: index=myindex | table field1, field2, field3 and then use the "Actions" menu to "Export...
by rtadams89 Contributor in Getting Data In 09-06-2013
1 4
1
4
tobiasvollrath
Hi, in our system we have same universal forwarders, one indexer and a third-party system that expect only events in ...
by tobiasvollrath Explorer in Getting Data In 09-06-2013
1 2
1
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...