Getting Data In

Getting Data In
Community Activity
abhayneilam
Hi, I have configured my props.conf and mentioned the "sourcetype" but later I dont see that sourcetype listed in th...
by abhayneilam Contributor in Getting Data In 04-05-2013
0 6
0
6
borisalves
I have a line that prints 2/20/13 6:45:45.000 PM [2013-02-20 18:45:45] FATAL so that is ok, but what i really wa...
by borisalves Path Finder in Getting Data In 04-05-2013
0 8
0
8
mikelanghorst
After setting a rather simple props entry for sourcetype [sharepoint] for our log to break events only after datestam...
by mikelanghorst Motivator in Getting Data In 04-04-2013
1 1
1
1
twkan
Hello all, I have a series of logs that looks like this: 200312,111523 -> this means 20 March 2012, 11:15:23 am 20...
by twkan Splunk Employee Splunk Employee in Getting Data In 04-04-2013
0 1
0
1
the_wolverine
and its not working. Why? I can tell by viewing the event in Splunk that my WMI events have the following metadata:...
by the_wolverine Champion in Getting Data In 04-04-2013
1 5
1
5
lpolo
The following URI returns the metadata information related to a saved search named "test" found in application "searc...
by lpolo Motivator in Getting Data In 04-04-2013
0 5
0
5
soimeng
my transform.conf [setnull] REGEX = . DEST_KEY = queue FORMAT = nullQueue [setparsing] REGEX =(?msi)^EventCode=4663...
by soimeng Explorer in Getting Data In 04-04-2013
0 3
0
3
dart
If I have a SEDCMD that is removing data, can I get the length of data removed, eg: ### RAW EVENT 12:01:01 Recieved ...
by dart Splunk Employee Splunk Employee in Getting Data In 04-04-2013
2 1
2
1
rechteklebe
Hi, i would like to use one of my universal forwarder as a second indexer. Please help me how to do it. In the seco...
by rechteklebe Path Finder in Getting Data In 04-04-2013
0 1
0
1
nooo
Hello, We're planning on forwarding our ASA logs to Splunk for log correlation etc, but do not want every event to b...
by nooo New Member in Getting Data In 04-03-2013
0 1
0
1
mcculloh
Trying to start a local install of the free splunk server on a red hat machine running linux 2.6.32. I am getting err...
by mcculloh New Member in Getting Data In 04-03-2013
0 3
0
3
j666gak
Hi, I'm having a bit of a headache. I am trying to index an XML file however I want the event date to be the date th...
by j666gak Communicator in Getting Data In 04-03-2013
0 4
0
4
AaronMoorcroft
Hi guys Please see below for an example of the event log I'm referring to. In a nut shell we send some logs off to...
by AaronMoorcroft Communicator in Getting Data In 04-03-2013
1 2
1
2
boverhof
Initially I used the python script to create a log handler to send out JSON formatted log message, but I notice that ...
by boverhof New Member in Getting Data In 04-03-2013
0 1
0
1
p_basanth
I want to monitor windows event logs and the below is the entries of inputs.conf file. But i am not able to view the ...
by p_basanth New Member in Getting Data In 04-02-2013
0 1
0
1
sethrife
As an example, suppose I'm trying to count the number of concurrent HTTP sessions. Events look something like the fol...
by sethrife New Member in Getting Data In 04-02-2013
0 1
0
1
hartfoml
I have one heavy weight forwarder that is collecting from over 600 Universal Forwarder. I have syslog-ng installed o...
by hartfoml Motivator in Getting Data In 04-02-2013
0 4
0
4
a212830
Hi, I want db connect to grab data at 1:00 am every day. I tried the following, and it gets spit out with an error: ...
by a212830 Champion in Getting Data In 04-02-2013
0 1
0
1
pansplunktest
Hi, I using the external data source named: firewall and I want to ignore the data "Apr 2 16:06:15 firewall de...
by pansplunktest New Member in Getting Data In 04-02-2013
0 2
0
2
sonicZ
Basically i am trying this deployment windows hosts: Installed the Windows TA app/configured inputs.conf with proper...
by sonicZ Contributor in Getting Data In 04-01-2013
0 2
0
2
bigtyma
I have a scripted file input that is tailing a log file, unfortunately events are not being broken out correctly. I w...
by bigtyma Communicator in Getting Data In 04-01-2013
0 3
0
3
evan_scheessele
I have a set of events, each a JSON object, separated from each other as one-per-line (SHOULD_LINEMERGE = false), but...
by evan_scheessele Explorer in Getting Data In 04-01-2013
1 3
1
3
sbyrd98
How do I throw an alert if a log file has NOT been written to within a certain amount of time? Say within 10 minutes.
by sbyrd98 New Member in Getting Data In 04-01-2013
0 1
0
1
Kai191
I have my search command as source="C:\Users\L30814\Desktop\1713.log" http | top 10 DestinationIP. What is the addit...
by Kai191 New Member in Getting Data In 04-01-2013
0 3
0
3
nileshbairagi
Hello, I am a splunk user and need help/ suggestion to use splunk in specific scenario. I need to use splunk in mult...
by nileshbairagi New Member in Getting Data In 03-31-2013
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...