Getting Data In

Getting Data In
Community Activity
wagnerbianchi
Hello Folks, This time I would like to have the difference between two timestamps, but, considering all the logs in ...
by wagnerbianchi Splunk Employee Splunk Employee in Getting Data In 06-11-2013
0 3
0
3
splunkroberts
Have not had luck with this yet. I am looking at all of my "blocked" traffic in the firewall logs and hope to weed o...
by splunkroberts New Member in Getting Data In 06-10-2013
0 2
0
2
loudsong
I noticed that in Splunk 5.0.3, transforms.conf has a new section called [accepted_keys]. Does anyone have an example...
by loudsong Explorer in Getting Data In 06-10-2013
1 5
1
5
bmignosa_splunk
After upgrading to Splunk 5.0.3, upon startup, I noticed the following messages: Undocumented key used in transforms...
by bmignosa_splunk Splunk Employee Splunk Employee in Getting Data In 06-10-2013
2 1
2
1
a212830
Hi, I'm getting a lot of "File descriptor cache is full (100), trimming..." messages on a couple of my windows serve...
by a212830 Champion in Getting Data In 06-10-2013
1 1
1
1
jawehren
How do I phrase a search to give me all the machines sending data and their OS type?
by jawehren Engager in Getting Data In 06-10-2013
0 3
0
3
dbuchanan46
The issue I'm having is with an index and real time reporting that uses that index. We currently use Rabbit MQ to s...
by dbuchanan46 New Member in Getting Data In 06-07-2013
0 1
0
1
mathdewulf
I installed Splunk on my laptop and wanted to receive the logs from 2 other desktops. So on these desktops I installe...
by mathdewulf New Member in Getting Data In 06-07-2013
0 2
0
2
dhs_harry08
hi, I have this source showing in the splunk source=/opt/splunk/var/spool/splunk/singlehost.sample.sav But when I...
by dhs_harry08 Path Finder in Getting Data In 06-07-2013
0 5
0
5
imoskal
Hi. With some network devices to the server Splunk receives syslog-events. Time on these devices is set to GMT. Event...
by imoskal Engager in Getting Data In 06-07-2013
0 2
0
2
wouterr
Hi, I seem to be incapable of figuring out what regex to provide in the TIME_PREFIX for my source type in order to r...
by wouterr Explorer in Getting Data In 06-06-2013
0 2
0
2
Greg_LeBlanc
Have created a custom Perl script, added it to commands.conf - it finds the script just fine. The script outputs the ...
by Greg_LeBlanc Path Finder in Getting Data In 06-06-2013
0 5
0
5
John_neville
I have configured Splunk to capture syslog data on UDP:514 of my router but do not see any log data being captured, n...
by John_neville New Member in Getting Data In 06-06-2013
0 2
0
2
trkalva
i have a huge log file with events, i need to keep around 20-30 events and discard the rest. I have used a stanza in ...
by trkalva Engager in Getting Data In 06-05-2013
0 1
0
1
leecaf
I'm indexing a bunch of CSV files provided by an external vendor over ftp ( mapped or synched to my local drive ) the...
by leecaf Explorer in Getting Data In 06-05-2013
0 1
0
1
mathdewulf
I've installed the universal forwarder on a windows client to forward the data to my central log collecter which is a...
by mathdewulf New Member in Getting Data In 06-05-2013
0 6
0
6
juniormint
A file I am monitoring looks something like the following [timestamp] index=layer1 message="123456" [timestamp] inde...
by juniormint Communicator in Getting Data In 06-05-2013
0 1
0
1
Gutenburg
I'm considering a Splunk cluster setup, where the Search Heads and Indexers (Peers) will be managed using mounted kno...
by Gutenburg New Member in Getting Data In 06-05-2013
0 1
0
1
amitj
since are trying to separate out splunk forwarder config ("inputs.conf") according to indexer. we defined forwarder c...
by amitj New Member in Getting Data In 06-05-2013
0 6
0
6
testingteam
I using the following command to retrieve a particular macro search result. curl -k -u admin:admin https://:8089/ser...
by testingteam Engager in Getting Data In 06-05-2013
0 2
0
2
anna_kendrik
How can I set my monitor in inputs.conf so that both of these directories are monitored- 1./var/lib/usr 2. /var/lib/n...
by anna_kendrik Engager in Getting Data In 06-04-2013
0 1
0
1
andykiely
I'm setting up the Exchange App, data is received in the correct indexes however I'm not seeing data in all the dashb...
by andykiely Path Finder in Getting Data In 06-04-2013
0 1
0
1
sbsbb
I've realised that there is no default Date format, so every date is in timestamp format, and so not readable for the...
by sbsbb Builder in Getting Data In 06-03-2013
0 2
0
2
rmavery
We have three (Windows 2008 R2) domain controllers sending events to a single Splunk collector. We need to reduce ou...
by rmavery Explorer in Getting Data In 06-03-2013
2 3
2
3
FRoth
I try to parse out the timestamp of this line: Jun 3 17:39:09 svlog.myserver.net svdcdev 04/29/2013 09:14:37 AM L...
by FRoth Contributor in Getting Data In 06-03-2013
0 1
0
1
Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...
Top Solution Authors