Getting Data In

Getting Data In
Community Activity
awurster
hi guys - i have a stand-alone splunk server that i'm trying to size appropriately. we have a fixed 3TB volume to ...
by awurster Contributor in Getting Data In 11-02-2012
0 6
0
6
tyronetv
Have a set of directories that act as "holding" or "pending" directories for file transfer. Essentially we transfer ...
by tyronetv Communicator in Getting Data In 11-02-2012
0 4
0
4
splunkpoornima
hi all, In splunk 4.3.3 if we clone the the views the copy of that XML is getting replicated. but if we want to cl...
by splunkpoornima Communicator in Getting Data In 11-02-2012
0 3
0
3
lpolo
I have a log file that is a text file. Splunk does not monitor this file because it finds it as a binary file. The f...
by lpolo Motivator in Getting Data In 11-02-2012
2 7
2
7
erstexas
I am trying to stop indexing any SNMP traffic on UDP ports 161 and 162 and they are still coming in even though I do ...
by erstexas Path Finder in Getting Data In 11-02-2012
0 2
0
2
Itisfun33
In Splunk 4.1.5 we are attempting to estimate our storage requirements per input, with the ultimate purpose of splitt...
by Itisfun33 New Member in Getting Data In 11-01-2012
0 1
0
1
Branden
I have Splunk crawling a /logs directory, which is where it receives most of its data. (/logs is populated via syslog...
by Branden Builder in Getting Data In 11-01-2012
2 2
2
2
paul_hignutt
When I try to add my indexer to the configuration of my linux box where I have installed the universal forwarder, it ...
by paul_hignutt Engager in Getting Data In 10-31-2012
0 1
0
1
Dark_Ichigo
Why cant I choose a source type of an index instead of the whole index to move my index data from the specific source...
by Dark_Ichigo Builder in Getting Data In 10-31-2012
1 3
1
3
Dark_Ichigo
Im having issues and I know its related to props.conf, but I have over 100 regexes and I dont want to test each one, ...
by Dark_Ichigo Builder in Getting Data In 10-31-2012
0 2
0
2
responsys_cm
The Splunk 5 release notes say the fschange monitor is being deprecated? Why is Splunk dropping one of the better se...
by responsys_cm Builder in Getting Data In 10-31-2012
1 1
1
1
barne_dn
I have old sources that were indexed in splunk. I'm trying to delete them but the | delete command is very slow and i...
by barne_dn Explorer in Getting Data In 10-31-2012
0 1
0
1
anoopambli
I am facing problem with adding a remote file on a windows server. Keep getting 'File path does not exist' error mess...
by anoopambli Communicator in Getting Data In 10-31-2012
0 5
0
5
ac931274
Hello there, I am using the nlog logging framework for my C# applications. Does anybody know of a logging target sp...
by ac931274 Explorer in Getting Data In 10-31-2012
1 4
1
4
smolcj
hi, my log contains several users and i have to create a text report or a table listing the starting and ending time ...
by smolcj Builder in Getting Data In 10-31-2012
0 2
0
2
kml_uvce
I am sending data from forwarder to indexer to Heavy forwarder to syslog, in sylog I am getting Heavy forwarder host...
by kml_uvce Builder in Getting Data In 10-31-2012
0 1
0
1
mrflibbleuk
Hi, We currently have a number of servers that have the universal forwarder installed and set to forward to an Enter...
by mrflibbleuk New Member in Getting Data In 10-30-2012
0 4
0
4
splunkIT
Our enviroment consist of splunk light forwarder > intermediate forwarder > indexer. I'm trying to index the .sdf l...
by splunkIT Splunk Employee Splunk Employee in Getting Data In 10-30-2012
1 6
1
6
BP9906
I added this to my inputs.conf: [monitor://C:\WINDOWS\system32\LogFiles\W3SVC*\] disabled = false followTail = 0 rec...
by BP9906 Builder in Getting Data In 10-30-2012
0 2
0
2
naydenk
Hello I am having a difficult time getting Splunk to recognize fields from my IIS 7.5 logs. I know that there are man...
by naydenk Path Finder in Getting Data In 10-30-2012
0 4
0
4
jfraiberg
I am having issues with the following macros - [macros/conf-change] access = read : [ * ], write : [ admin, power ]...
by jfraiberg Communicator in Getting Data In 10-30-2012
0 2
0
2
vallurupalli
what is the best way to get the data in using curl http://myhost/mylog.log
by vallurupalli New Member in Getting Data In 10-30-2012
0 1
0
1
fernandoandre
My question is, can a Heavy Forwarder perform remote WMI data collection or this feature requires an Indexer? I have...
by fernandoandre Communicator in Getting Data In 10-30-2012
0 3
0
3
echalex
Hi, As I'm installing TA's on windows hosts, I see that the PerformanceMonitor source is specified as [script://$SP...
by echalex Builder in Getting Data In 10-30-2012
0 2
0
2
splunkpoornima
Hi all, while adding the input data to the splunk at final stage it has some three options as, 1.)Continuously inde...
by splunkpoornima Communicator in Getting Data In 10-29-2012
0 4
0
4
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...