Getting Data In

Getting Data In
Community Activity
madmoravian
I've got an event log from a sql server that I'm trying to import. When I view the file in a text editor, everything...
by madmoravian New Member in Getting Data In 03-14-2013
0 1
0
1
wlsplunker
Hi all, I have an XML log file that looks something like this. <matrix> <datasource> <name>ABC</name> <...
by wlsplunker New Member in Getting Data In 03-14-2013
0 3
0
3
danurag
Hi Everybody, I am getting the following error message while trying to save remote performance counters for MSMQ ser...
by danurag Explorer in Getting Data In 03-14-2013
0 3
0
3
a212830
Should a props.conf even exist on universal forwarders? Is all that work (including timestamp and line-breaking) done...
by a212830 Champion in Getting Data In 03-14-2013
0 2
0
2
Adam_Sealey
I've been trying to do a search time field extraction, using the EXTRACT- stanza in props.conf. From the props.con...
by Adam_Sealey Explorer in Getting Data In 03-14-2013
0 2
0
2
monzy
i added my Adium chat logs to be monitored by splunk. i see multiple repeats for any given log event. i verified the ...
by monzy Communicator in Getting Data In 03-14-2013
1 6
1
6
dcparker
Hi all, I am working on putting my deployment server code in an external location, like GitHub. This part is working...
by dcparker Path Finder in Getting Data In 03-14-2013
0 2
0
2
ddholstadz
I use the following commands on my light forwarders to add an index and set new files to use it. /opt/splunkforwa...
by ddholstadz Explorer in Getting Data In 03-14-2013
0 2
0
2
mehmettecer
Both of my servers are Linux OS and I am using latest Splunk 4.2. I can forward from UF to Splunk to index, but ever...
by mehmettecer Explorer in Getting Data In 03-14-2013
1 5
1
5
dengjin
./splunk add monitor col1 what's the col1?
by dengjin New Member in Getting Data In 03-13-2013
0 1
0
1
marcpatron
I am trying to index the local windows eventlogs, but there appears to be an issue reading the "Security" eventlog, a...
by marcpatron Explorer in Getting Data In 03-13-2013
0 4
0
4
mike7860
Hi all: I would like to know how do we delete logs from an indexer after 90 days in splunk. Some answers durected me...
by mike7860 Explorer in Getting Data In 03-13-2013
1 1
1
1
jared_anderson
I have active directory sending logs to my Splunk server via a Universal forwarder. I want to create alerts for when ...
by jared_anderson Path Finder in Getting Data In 03-13-2013
0 7
0
7
lpolo
I have this log event: 2013-02-01 17:23:46,877 query id=a0e22777-2aaf-4486-9a56-fd1dae24bb82{ "start" : 1, "retu...
by lpolo Motivator in Getting Data In 03-13-2013
0 4
0
4
cpetterborg
I have some searches that, when I list them in Manager, don't have anything but Run and Clone under Actions. There is...
by SplunkTrust SplunkTrust in Getting Data In 03-12-2013
0 3
0
3
donald_xero
We're trying to push event data from a heavy forwarder to our central indexer over a VPN with a fairly high RTT (~180...
by donald_xero Explorer in Getting Data In 03-12-2013
0 4
0
4
sloshburch
My universal fowarders are not hashing the sslPassword file stored at the etc/system location after restart. Instead...
by sloshburch Ultra Champion in Getting Data In 03-12-2013
0 3
0
3
tdrisdelle
Is there any way to use the CLI to configure the blacklist (in inputs.conf) file? The docs seem to indicate no... bu...
by tdrisdelle Engager in Getting Data In 03-12-2013
1 2
1
2
ephemeric
Hello all, Forgive my hasty question, it's late and my articulation has dwindled along with my brain capacity... We...
by ephemeric Contributor in Getting Data In 03-12-2013
0 11
0
11
vragosta
I have the following alert created in Splunk to alert me when the number of firewall drops exceeds 30 within a specif...
by vragosta Path Finder in Getting Data In 03-12-2013
0 2
0
2
ephemeric
Greetz, When a heavy forwarder is indexing and forwarding, does it keep track of what is indexed at what point and w...
by ephemeric Contributor in Getting Data In 03-12-2013
1 3
1
3
sunrise
Universal Forwarder(以下、UF)を利用してWindowsイベントログを収集する際、 current_onlyオプションによって以下の挙動になるかと思います。 <current_only=0の場合> UFはホスト内...
by sunrise Contributor in Getting Data In 03-12-2013
1 3
1
3
jbreu
I am having trouble getting the IIS logs and Message Tracking logs to show up Splunk. I am able getting some Exchange...
by jbreu Explorer in Getting Data In 03-12-2013
0 3
0
3
lzhang_soliton
Hi, I have been storing two types of log in the same directory. One is ANSI, another is Unicode. I use different def...
by lzhang_soliton Path Finder in Getting Data In 03-12-2013
0 2
0
2
Dark_Ichigo
Will this limit this forwarding speed to the Indexer? [thruput] maxKBps = <integer> * If specified and not z...
by Dark_Ichigo Builder in Getting Data In 03-11-2013
0 2
0
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors