Getting Data In

Getting Data In
Community Activity
nathanlhopkins
I'd like to index files in /DIR/autosys/logs as below; Linux equivalent: cd /DIR/autosys/logs ls app*ua1*START_MT* ...
by nathanlhopkins Path Finder in Getting Data In 05-22-2013
1 5
1
5
hartfoml
I have a folder that a user puts files in on a semi regular bases. I monitor the folder for new files and put the it...
by hartfoml Motivator in Getting Data In 05-22-2013
0 2
0
2
elaine0102
Hi, I have successfuly extracted a timestamp. However, I need Splunk to recognised it as the event timestamp. Please...
by elaine0102 Explorer in Getting Data In 05-22-2013
0 11
0
11
linu1988
Hello, i would like to forward only my program related data from e.g. Program A: error occurred at step 6!! How can ...
by linu1988 Champion in Getting Data In 05-22-2013
0 3
0
3
pisc
WMIでのWindowsイベントログ取得について教えてください。 [データ入力] - [リモートイベントログの収集]から設定をしていますが、 対象マシンのIPアドレスを入力し、[ログのサーチ]ボタンをクリックすると、以下のエラーが発...
by pisc Explorer in Getting Data In 05-21-2013
0 5
0
5
ludoz13
Hello all, I have somme issue with my universal forwarder and I would like to monitor the logs file of my forwader (...
by ludoz13 Path Finder in Getting Data In 05-21-2013
2 2
2
2
feedmagnet
Hello, I am test driving splunkstorm and I am very new to the ecosystem. Here is what I am trying to do: I have web...
by feedmagnet New Member in Getting Data In 05-21-2013
0 3
0
3
aaronkorn
Splunk continues to throw an error about the ignoreOlderThan flag on a windows UF. Any ideas? Checking conf fi...
by aaronkorn Splunk Employee Splunk Employee in Getting Data In 05-21-2013
0 5
0
5
eritzman
OK - I'm a NUB here and experimenting with SPLUNK. I have some log files that are saved in a TAB/Columned format. [ex...
by eritzman New Member in Getting Data In 05-21-2013
0 2
0
2
aaronkorn
Hello, We are looking at using the universal forwarder to collect remote windows data from event logs from approx 11...
by aaronkorn Splunk Employee Splunk Employee in Getting Data In 05-21-2013
0 4
0
4
pwjones89
I am attempting to overwrite the timestamp Splunk has assigned to each event, with a field which holds an events mont...
by pwjones89 Engager in Getting Data In 05-21-2013
1 3
1
3
unixbox
Does anyone know if there is already an app or project that will allow me to import all my linkedin data into splunk?...
by unixbox Engager in Getting Data In 05-21-2013
2 1
2
1
a212830
Hi, I have an inputs.conf that is picking up a file that I want blacklisted. The file name is summary_1.diag. I thou...
by a212830 Champion in Getting Data In 05-21-2013
0 1
0
1
alexl1
hello, I am trying nullQueue but I think it discards the entire event, is there a syntax that just discards lines bu...
by alexl1 Path Finder in Getting Data In 05-20-2013
2 3
2
3
marellasunil
Hi, I would like ti calculate number of events between time in my search. There are 2 status, exceed & within in my ...
by marellasunil Communicator in Getting Data In 05-20-2013
0 2
0
2
a212830
Hi, Is there a way to track disk usage per day for indexes?
by a212830 Champion in Getting Data In 05-20-2013
0 9
0
9
halr9000
I have a log file that looks like the below. Events are denoted by a messages tag, with each having a timestamp tag. ...
by halr9000 Motivator in Getting Data In 05-20-2013
1 2
1
2
ryastrebov
Hello! I have Splunk installed on Linux and FTP which are placed logs. I mount FTP-folder on Splunk's Linux computer...
by ryastrebov Communicator in Getting Data In 05-20-2013
0 6
0
6
nickcode
My deployment is: 1 Forwarder + 2 Indexers + 1 Search head. I have specified a monitor in the forwarder and the forwa...
by nickcode Explorer in Getting Data In 05-20-2013
0 1
0
1
nickcode
How to specify different indexes for storing data of different source(sourcetype)? The data is coming from remote for...
by nickcode Explorer in Getting Data In 05-20-2013
0 6
0
6
Dark_Ichigo
I am currently in process of migrating an index from the indexes.conf configuration file in one app to another app wi...
by Dark_Ichigo Builder in Getting Data In 05-19-2013
0 2
0
2
giraffe
The CLI command "add tcp ..." does not allow one to set the sourcename of the input source that it creates. How can...
by giraffe Explorer in Getting Data In 05-19-2013
0 2
0
2
mfrost8
We have 2 production auto-load balanced indexers that are currently getting all of our production data. Both runnin...
by mfrost8 Builder in Getting Data In 05-19-2013
0 5
0
5
cramasta
I see in the docs for inputs.conf that a monitor with /foo/m*r/bar will match /foo/bar Can someone explain why th...
by cramasta Builder in Getting Data In 05-18-2013
3 3
3
3
mflamerich
We have some log files that we monitor as heartbeat for some daemon processes. These files contain a large level of ...
by mflamerich Explorer in Getting Data In 05-18-2013
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...