Getting Data In

Getting Data In
Community Activity
a212830
Hi, I have an inputs.conf that is picking up a file that I want blacklisted. The file name is summary_1.diag. I thou...
by a212830 Champion in Getting Data In 05-21-2013
0 1
0
1
alexl1
hello, I am trying nullQueue but I think it discards the entire event, is there a syntax that just discards lines bu...
by alexl1 Path Finder in Getting Data In 05-20-2013
2 3
2
3
marellasunil
Hi, I would like ti calculate number of events between time in my search. There are 2 status, exceed & within in my ...
by marellasunil Communicator in Getting Data In 05-20-2013
0 2
0
2
a212830
Hi, Is there a way to track disk usage per day for indexes?
by a212830 Champion in Getting Data In 05-20-2013
0 9
0
9
halr9000
I have a log file that looks like the below. Events are denoted by a messages tag, with each having a timestamp tag. ...
by halr9000 Motivator in Getting Data In 05-20-2013
1 2
1
2
ryastrebov
Hello! I have Splunk installed on Linux and FTP which are placed logs. I mount FTP-folder on Splunk's Linux computer...
by ryastrebov Communicator in Getting Data In 05-20-2013
0 6
0
6
nickcode
My deployment is: 1 Forwarder + 2 Indexers + 1 Search head. I have specified a monitor in the forwarder and the forwa...
by nickcode Explorer in Getting Data In 05-20-2013
0 1
0
1
nickcode
How to specify different indexes for storing data of different source(sourcetype)? The data is coming from remote for...
by nickcode Explorer in Getting Data In 05-20-2013
0 6
0
6
Dark_Ichigo
I am currently in process of migrating an index from the indexes.conf configuration file in one app to another app wi...
by Dark_Ichigo Builder in Getting Data In 05-19-2013
0 2
0
2
giraffe
The CLI command "add tcp ..." does not allow one to set the sourcename of the input source that it creates. How can...
by giraffe Explorer in Getting Data In 05-19-2013
0 2
0
2
mfrost8
We have 2 production auto-load balanced indexers that are currently getting all of our production data. Both runnin...
by mfrost8 Builder in Getting Data In 05-19-2013
0 5
0
5
cramasta
I see in the docs for inputs.conf that a monitor with /foo/m*r/bar will match /foo/bar Can someone explain why th...
by cramasta Builder in Getting Data In 05-18-2013
3 3
3
3
mflamerich
We have some log files that we monitor as heartbeat for some daemon processes. These files contain a large level of ...
by mflamerich Explorer in Getting Data In 05-18-2013
0 3
0
3
monzy
i would like to report on the events submitted via the rest API by user. i have multiple users that submit data to sp...
by monzy Communicator in Getting Data In 05-17-2013
0 1
0
1
nickabal
I have a table that shows the usernames logging into to my various servers. I want to compare these results to a list...
by nickabal New Member in Getting Data In 05-17-2013
0 1
0
1
nickcode
My deployment is: 1 Forwarder + 2 Indexers + 1 Search head. My data are distributed in 2 indexers, and I only install...
by nickcode Explorer in Getting Data In 05-17-2013
0 2
0
2
MarMoh
Hi All, Currently there is just one stand alone splunk server running for the entire company, we decided to change t...
by MarMoh Path Finder in Getting Data In 05-17-2013
0 1
0
1
flo_cognosec
Hi I might get things wrong, but for now I have the following problem / setup forwarder with some files in some di...
by flo_cognosec Communicator in Getting Data In 05-17-2013
0 10
0
10
cramasta
I have a question about how priority's work in a single props.conf file. If i have the two stanzas below and I index...
by cramasta Builder in Getting Data In 05-16-2013
0 5
0
5
rjordan00
I'm evaluating Splunk for our syslog needs. One of our final requirements is to have the ability to forward syslog me...
by rjordan00 Engager in Getting Data In 05-16-2013
2 4
2
4
foomanjee
Hello, I have what may or may not be a bit of a unique issue regarding extracted fields. We've got a few webservers ...
by foomanjee Explorer in Getting Data In 05-16-2013
1 4
1
4
Ant1D
Hi, I have set up a Splunk environment in which several applications will be sending data to a collection of indexer...
by Ant1D Motivator in Getting Data In 05-16-2013
0 4
0
4
fongkh76
Hi, I am new to Splunk and have just configured a universal forwarder on a remote windows server in order to forward...
by fongkh76 New Member in Getting Data In 05-16-2013
0 8
0
8
Kai191
I would like to know what is the command filter out repeat source port if I wanna analyse my log based on number of p...
by Kai191 New Member in Getting Data In 05-15-2013
0 2
0
2
Alan_Bradley
Is there an internal log message that will tell me when Splunk has finished indexing a file?
by Alan_Bradley Path Finder in Getting Data In 05-15-2013
10 6
10
6
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors