Getting Data In

Getting Data In
Community Activity
a212830
Hi, How would I parse a file that has two linebreaking formats? The first is when the line begins and ends with ast...
by a212830 Champion in Getting Data In 03-17-2013
0 3
0
3
Sriram
I need to build a dashboard to parse the json data and show it more like Tree Structure.What is the best way, I can b...
by Sriram Communicator in Getting Data In 03-15-2013
1 1
1
1
a212830
Hi, How would I tell splunk to monitor a specific file through a set of subdirectories? Would I set a wildcard in th...
by a212830 Champion in Getting Data In 03-15-2013
0 1
0
1
arntm
We have several customers with Splunk. Is it possible to integrate more than 1 Splunk instance i ServiceNow?
by arntm New Member in Getting Data In 03-15-2013
0 2
0
2
jeffmartintx
The Exchange Server application we use, up until last weekend, was reporting data that appears to be an accurate refl...
by jeffmartintx New Member in Getting Data In 03-15-2013
0 1
0
1
twstanley
We have a universal forwarder on linux that seems to get 'stuck' reading one of the two high event log files being re...
by twstanley New Member in Getting Data In 03-15-2013
0 3
0
3
catch_mili
Unable to start splunk forwarder service, below error returns. checking mgmt port [8089]: already bound ERROR: The m...
by catch_mili Explorer in Getting Data In 03-15-2013
0 6
0
6
madmoravian
I've got an event log from a sql server that I'm trying to import. When I view the file in a text editor, everything...
by madmoravian New Member in Getting Data In 03-14-2013
0 1
0
1
wlsplunker
Hi all, I have an XML log file that looks something like this. <matrix> <datasource> <name>ABC</name> <...
by wlsplunker New Member in Getting Data In 03-14-2013
0 3
0
3
danurag
Hi Everybody, I am getting the following error message while trying to save remote performance counters for MSMQ ser...
by danurag Explorer in Getting Data In 03-14-2013
0 3
0
3
a212830
Should a props.conf even exist on universal forwarders? Is all that work (including timestamp and line-breaking) done...
by a212830 Champion in Getting Data In 03-14-2013
0 2
0
2
Adam_Sealey
I've been trying to do a search time field extraction, using the EXTRACT- stanza in props.conf. From the props.con...
by Adam_Sealey Explorer in Getting Data In 03-14-2013
0 2
0
2
monzy
i added my Adium chat logs to be monitored by splunk. i see multiple repeats for any given log event. i verified the ...
by monzy Communicator in Getting Data In 03-14-2013
1 6
1
6
dcparker
Hi all, I am working on putting my deployment server code in an external location, like GitHub. This part is working...
by dcparker Path Finder in Getting Data In 03-14-2013
0 2
0
2
ddholstadz
I use the following commands on my light forwarders to add an index and set new files to use it. /opt/splunkforwa...
by ddholstadz Explorer in Getting Data In 03-14-2013
0 2
0
2
mehmettecer
Both of my servers are Linux OS and I am using latest Splunk 4.2. I can forward from UF to Splunk to index, but ever...
by mehmettecer Explorer in Getting Data In 03-14-2013
1 5
1
5
dengjin
./splunk add monitor col1 what's the col1?
by dengjin New Member in Getting Data In 03-13-2013
0 1
0
1
marcpatron
I am trying to index the local windows eventlogs, but there appears to be an issue reading the "Security" eventlog, a...
by marcpatron Explorer in Getting Data In 03-13-2013
0 4
0
4
mike7860
Hi all: I would like to know how do we delete logs from an indexer after 90 days in splunk. Some answers durected me...
by mike7860 Explorer in Getting Data In 03-13-2013
1 1
1
1
jared_anderson
I have active directory sending logs to my Splunk server via a Universal forwarder. I want to create alerts for when ...
by jared_anderson Path Finder in Getting Data In 03-13-2013
0 7
0
7
lpolo
I have this log event: 2013-02-01 17:23:46,877 query id=a0e22777-2aaf-4486-9a56-fd1dae24bb82{ "start" : 1, "retu...
by lpolo Motivator in Getting Data In 03-13-2013
0 4
0
4
cpetterborg
I have some searches that, when I list them in Manager, don't have anything but Run and Clone under Actions. There is...
by SplunkTrust SplunkTrust in Getting Data In 03-12-2013
0 3
0
3
donald_xero
We're trying to push event data from a heavy forwarder to our central indexer over a VPN with a fairly high RTT (~180...
by donald_xero Explorer in Getting Data In 03-12-2013
0 4
0
4
sloshburch
My universal fowarders are not hashing the sslPassword file stored at the etc/system location after restart. Instead...
by sloshburch Ultra Champion in Getting Data In 03-12-2013
0 3
0
3
tdrisdelle
Is there any way to use the CLI to configure the blacklist (in inputs.conf) file? The docs seem to indicate no... bu...
by tdrisdelle Engager in Getting Data In 03-12-2013
1 2
1
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...