Getting Data In

Getting Data In
Community Activity
tincupchalice
So I tried pattern as \d{18} for events looking like: 1351623403000225565 Type=VARIABLE, blah blah 13516234030002255...
by tincupchalice Path Finder in Getting Data In 11-08-2012
0 4
0
4
rmckerchar
Hi guys, I'm trying to define a search to spot Active Directory domain controllers which have not (and possibly neve...
by rmckerchar New Member in Getting Data In 11-08-2012
0 3
0
3
ezajac
I haven’t set this type of input before. I have logs available over http from a URL like below. The typical user view...
by ezajac Path Finder in Getting Data In 11-08-2012
0 1
0
1
perlish
There're 300G disk space in my server, how can I delete or archive old data in splunk ? Thank you !
by perlish Communicator in Getting Data In 11-08-2012
0 1
0
1
104K
Hi I have series of two key-value pairs (timestamp and some other key) on one json file, which looks like below: {"...
by 104K Engager in Getting Data In 11-08-2012
3 2
3
2
halperkins
I have a field called size that takes the form: 1 2 3 4 I want to find someway to evaluate size so that is sums all...
by halperkins New Member in Getting Data In 11-07-2012
0 1
0
1
aschoen
I am trying to forward input from a universal forwarder to a regular Splunk installation on my desktop. The universa...
by aschoen New Member in Getting Data In 11-07-2012
0 1
0
1
SramanJ
Hello, I am a new user to splunk and logging in general. So, appreciate your patience if my questions are fairly sim...
by SramanJ Engager in Getting Data In 11-07-2012
6 1
6
1
aandrew
Hi, is anyone out there having a Slow search and missed alerts on Search head. we have installed search head on 64 bi...
by aandrew New Member in Getting Data In 11-07-2012
0 9
0
9
Ricapar
We have a very large environment.. and with Splunk charging by the GB/day, we obviously have an interest in controlli...
by Ricapar Communicator in Getting Data In 11-07-2012
0 4
0
4
bread555
One of my sources coming from a universal forwarder needs to have have it's truncate option set to 0. I have edited ...
by bread555 Explorer in Getting Data In 11-07-2012
1 2
1
2
sruthy
Hi, I am new to splunk and when i add datainputs i was not known about the timestamp issue and later i explored it. w...
by sruthy Explorer in Getting Data In 11-07-2012
1 1
1
1
pdherndon
I have configured approx. 100 access points to send syslog events to both Splunk and to a kiwi syslog server I have s...
by pdherndon New Member in Getting Data In 11-06-2012
0 8
0
8
the_wolverine
I've heard that Splunk recommends monitoring of rolled log files (eg. file.log.1, file.log.2, etc) under certain sit...
by the_wolverine Champion in Getting Data In 11-06-2012
0 3
0
3
mrgibbon
Hey Guys, Im trying to come up with some searches for our HR department. We sometimes have to present them with evide...
by mrgibbon Contributor in Getting Data In 11-06-2012
0 5
0
5
n_greder
Hello, i would like to add a monitor for EventLog:Security. This EventLog contains many entries, and if i add it dir...
by n_greder New Member in Getting Data In 11-06-2012
0 3
0
3
tjensen
Hello, I search a way to get realtime logs from DMZ-Zone into a Trusted Network, where the Indexer is located. A Fo...
by tjensen Explorer in Getting Data In 11-06-2012
0 4
0
4
deyeo
instead of storing the cisco firewall logs into "summary" index. i would like to store in a index called "firewall". ...
by deyeo Path Finder in Getting Data In 11-05-2012
0 1
0
1
CerielTjuh
Hello there, I have currently deployed Splunk in our network using SplunkLightForwarders and one central indexing se...
by CerielTjuh Path Finder in Getting Data In 11-05-2012
1 14
1
14
barne_dn
Hi Everyone, I have windows security event filter setup and working on my indexer. However I want to filter on three...
by barne_dn Explorer in Getting Data In 11-05-2012
0 3
0
3
abhayneilam
Hi, I have a file which contains the below content: abhay|vikram|singh|26|kolkata murari|kumar|singh|28|mumbai I wa...
by abhayneilam Contributor in Getting Data In 11-05-2012
0 9
0
9
kml_uvce
I am forwarding data from indexer to heavy forwarder How I can append host name in event (_raw) in indxer that will ...
by kml_uvce Builder in Getting Data In 11-05-2012
0 4
0
4
matthewparry
Hi, I have JSON data being indexed from a syslog file i.e Nov 2 23:04:47 host1 /usr/local/bin/audit.rb[24503]: { "...
by matthewparry Path Finder in Getting Data In 11-04-2012
0 1
0
1
abhayneilam
Hi, I have a data as : abhay|vikram|singh|26|kolkata murari|kumar|singh|28|mumbai and in my transfoms.conf I hav...
by abhayneilam Contributor in Getting Data In 11-04-2012
0 1
0
1
inerdgrl
Good Day, I first tried to use the Cisco Security Suite in anticipation of getting more Cisco devices but realized t...
by inerdgrl New Member in Getting Data In 11-04-2012
0 1
0
1
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...
Top Solution Authors