Getting Data In

Getting Data In
Community Activity
only4luca
Hi All, Trying to filter on Win Sec events, dropping events that don't have particular eventids and Account Name con...
by only4luca New Member in Getting Data In 02-22-2013
0 4
0
4
smolcj
Hi, scenario: a log uploader application helps in uploading logs to a directory. let it be splunkdata/timeofupload/yo...
by smolcj Builder in Getting Data In 02-22-2013
0 6
0
6
vaibhavagg2006
Hi Splunk experts, I am using regex transform to mask data in splunk. But splunk only masks first occurence of string...
by vaibhavagg2006 Communicator in Getting Data In 02-22-2013
0 5
0
5
echalex
Hi, I'm trying to set timestamp recognition for a sourcetype, in order to avoid recognising timestamp in the event's...
by echalex Builder in Getting Data In 02-22-2013
0 3
0
3
yannK
I just turned on a splunk forwarder with the active directory monitoring on my AD server. Since the windows logs WinE...
by yannK Splunk Employee Splunk Employee in Getting Data In 02-21-2013
3 1
3
1
ShaneNewman
I need to come up with a way to monitor files via UNC (I know this is not the preferred way) for ~140 servers that ar...
by ShaneNewman Motivator in Getting Data In 02-21-2013
0 1
0
1
bckq
I have currently one Splunk server who works as indexer and searcher. I want to add second server which will be a mir...
by bckq Path Finder in Getting Data In 02-20-2013
0 5
0
5
ssankeneni
Is it possible to deploy an app from the Splunk master node /master-app/cluster/local to all the peer nodes ?
by ssankeneni Communicator in Getting Data In 02-20-2013
2 4
2
4
rohitgupta
I have a requirement where in order for the remote machine to send data over the TCP connection to Splunk, it needs S...
by rohitgupta New Member in Getting Data In 02-20-2013
0 1
0
1
popo80
Hello, I'm new in splunk. Splunk with syslog works correct now. I try test netflow from cisco asa. I set netflow int...
by popo80 New Member in Getting Data In 02-20-2013
0 1
0
1
yannK
This is a common issue with the syslog sourceytype. By default it behave differently from the other inputs, the host ...
by yannK Splunk Employee Splunk Employee in Getting Data In 02-20-2013
2 1
2
1
chimbudp
Using [monitor://path] Stanza i need to monitor a folder which contains binary data. When i set the props.conf as, [...
by chimbudp Contributor in Getting Data In 02-20-2013
0 3
0
3
chimbudp
I would like to monitor assembly folder in windows. Path :- C: \Windows \assembly I have set the inputs.conf in Univ...
by chimbudp Contributor in Getting Data In 02-20-2013
0 8
0
8
doreno
Hi, Ive been playing with the SEDCMD in my props.conf to anonymize CC data in a log. Originally I tried this: [...
by doreno Explorer in Getting Data In 02-19-2013
0 11
0
11
pdash
I want to index only specific fields like error status in an event and discard the rest. How do I set splunk to do th...
by pdash Path Finder in Getting Data In 02-19-2013
0 3
0
3
vragosta
I know that you can control the Universal Forwarder to grab historical event logs from Windows using "current_only = ...
by vragosta Path Finder in Getting Data In 02-19-2013
0 2
0
2
dchodur
Anyone know why 5.0.1 UFs are reporting data in with host name of $decideonstartup. Looks like this setting was added...
by dchodur Path Finder in Getting Data In 02-19-2013
1 6
1
6
chimbudp
I need to monitor the Assembly folder in Windows Server : [monitor://C:\Windows\assembly] index=Assembly_monitor th...
by chimbudp Contributor in Getting Data In 02-19-2013
0 4
0
4
NK_1
Is there any way to distinguish the various priorities/levels of syslogged messages when viewed from Splunk? I don't ...
by NK_1 Path Finder in Getting Data In 02-19-2013
0 3
0
3
KA_splunk
Hey folks, Long time Splunk fan here. Initially when we started using Splunk, our queries were simple, and so search...
by KA_splunk Explorer in Getting Data In 02-19-2013
2 11
2
11
tsunamii
I am using a Universal Forwarder to monitor the following directories and files, but somehow it is not routing it to ...
by tsunamii Path Finder in Getting Data In 02-19-2013
0 2
0
2
aart_bos
I've "configured" the Splunk for Cisco IPS application, but I'm getting the following back from the scripted input: ...
by aart_bos Loves-to-Learn in Getting Data In 02-18-2013
0 1
0
1
mship
I have an alert on my windows 2008R2 indexer that calls sendsnmptrap.cmd (see link to script below). My question is i...
by mship Path Finder in Getting Data In 02-18-2013
0 1
0
1
PaVedme
Why time zone in Splunk 5.0.2 for Moscow (Russia) is +3? Must be +4!
by PaVedme Engager in Getting Data In 02-18-2013
1 1
1
1
matthewcanty
Hi Everyone. Perfmon logging used to work for me by placing what should have been in perfmon.conf into inputs.conf. ...
by matthewcanty Communicator in Getting Data In 02-18-2013
0 6
0
6
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors