Getting Data In

Getting Data In
Community Activity
jfraiberg
I tried the following and it did not work - http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwarddatato...
by jfraiberg Communicator in Getting Data In 10-11-2012
0 5
0
5
khyoung7410
Hi I want to search several host include in indexes. last 24hour index name is a_1, a_2, a_3.... how to search? thank...
by khyoung7410 Communicator in Getting Data In 10-11-2012
0 3
0
3
mikeyw
Hi, I've inherited a splunk server that was setup to receive to vmkwarning files from around 20 ESX hosts. Recently...
by mikeyw New Member in Getting Data In 10-11-2012
0 3
0
3
yannK
I saw this in transforms.conf : should if be nullQueue or nullqueue ? [send_to_nullqueue] DEST_KEY = queue REGEX ...
by yannK Splunk Employee Splunk Employee in Getting Data In 10-10-2012
2 2
2
2
Lucas_K
I have a situation in which it would seem that for .dat files inside an archive I can not make it honor the settings ...
by Lucas_K Motivator in Getting Data In 10-09-2012
0 1
0
1
infomedix
Hello, I'm having trouble extracting the following timestamp for one source, is there someone here that can recommend...
by infomedix New Member in Getting Data In 10-09-2012
0 5
0
5
ssankeneni
Can any one please let me know the best way to update the opt/splunkforwarder/etc/system/local/inputs.conf of univers...
by ssankeneni Communicator in Getting Data In 10-09-2012
0 5
0
5
abhayneilam
Hi, Can any body tell me how to import all the files of a particular directory in splunk at one go ? next time if I ...
by abhayneilam Contributor in Getting Data In 10-09-2012
0 16
0
16
mataharry
For some inputs on a forwarder, I want to send the same data to the same indexer, but duplicate it in 2 indexes (they...
by mataharry Communicator in Getting Data In 10-09-2012
1 2
1
2
ssankeneni
The Data forwarded by universal forwarder is not making to the indexer. There is no clue on splunkd.log file even. It...
by ssankeneni Communicator in Getting Data In 10-09-2012
0 4
0
4
DerekB
All of my .conf files are setup correctly yet I still can't get any WinEventLog information via WMI into my indexer. ...
by DerekB Splunk Employee Splunk Employee in Getting Data In 10-09-2012
4 1
4
1
nick085
Will the following work: [fschange:C:\Program Files\progam|D:\File\group] Should replace "|" with "OR",or should i ...
by nick085 Engager in Getting Data In 10-09-2012
1 1
1
1
rturk
Hi All, I am currently designing a deployment with two Splunk "pods" in different data centres, each with two Indexe...
by rturk Builder in Getting Data In 10-09-2012
0 2
0
2
ryan461
I'm wondering if there are other locations than inputs.conf, props.conf that a sourcetype might be named/assigned. I ...
by ryan461 Explorer in Getting Data In 10-09-2012
0 5
0
5
sieutruc
Hello, I have one heavy forwarder that receives data from some forwarders. After that, it indexes all those data, bu...
by sieutruc Contributor in Getting Data In 10-09-2012
0 4
0
4
Edub
A network socket process went bug-eyed today creating more than 7 million /var/log/messages events in 15min. The ind...
by Edub Explorer in Getting Data In 10-09-2012
5 3
5
3
lsolberg
We have a splitted environment where we are using another tool to take care of typical monitoring like cpu, disk, mem...
by lsolberg Path Finder in Getting Data In 10-09-2012
0 4
0
4
Tridi123
i am importing data into splunk by using Continuously index data from a file or directory this Splunk instance can a...
by Tridi123 New Member in Getting Data In 10-08-2012
0 1
0
1
mehal
Hello Folks, I have a csv file which has timestamp divided among various fields. (Initial 4 columns are shown) year,...
by mehal New Member in Getting Data In 10-08-2012
0 4
0
4
vickypandya
Hello, I have been using REST for basic searching and getting results from saved searches from splunk via splunk SDK...
by vickypandya Engager in Getting Data In 10-08-2012
1 1
1
1
atreece
I have a bunch of logs from a program that regularly updates local files with changes in network files, and I would l...
by atreece Path Finder in Getting Data In 10-08-2012
0 3
0
3
brantramey
We are having an issue getting fields to work with this one application. If we move the props.conf to the etc/system...
by brantramey Explorer in Getting Data In 10-08-2012
0 2
0
2
bauer_devop
Which version of the universal forwarder - http://www.splunk.com/download/universalforwarder - do I use for Gentoo? I...
by bauer_devop New Member in Getting Data In 10-08-2012
0 1
0
1
SplunkUser5888
Hey guys, Noob here; I wanted to know what you thought would be the best setup to use the monitor function in inputs...
by SplunkUser5888 Path Finder in Getting Data In 10-08-2012
0 3
0
3
edchow
I want to correct the linebreaking for my secure.txt file. Do I need to configure props.conf at the searchhead, inde...
by edchow Explorer in Getting Data In 10-07-2012
1 1
1
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...