Getting Data In

Getting Data In
Community Activity
gportnoy
Having this intermittent problem with UF on multiple servers where it occasionally fails to start up the WinEventLog ...
by gportnoy Explorer in Getting Data In 06-17-2023
0 3
0
3
shubham87
Hi All, We are collecting different logs from same source on different UDP ports on Heavy forwarder. Heavy forwarder ...
by shubham87 Explorer in Getting Data In 06-17-2023
0 11
0
11
_olivier_
Hi,   I wana keep only logs Not containing the word "chatbot". This word is present in the _raw data I'm using the me...
by _olivier_ Path Finder in Getting Data In 06-17-2023
0 7
0
7
splunkingguy
The app write log entries to a log file, say /var/theapp/thelogfile.log.The app is configured to roll the log file on...
by splunkingguy Explorer in Getting Data In 06-16-2023
0 6
0
6
jkalbert
I wish to remove unneeded text from Windows event logs before they are indexed. Specifically, Windows event 4624 cont...
by jkalbert Explorer in Getting Data In 06-16-2023
0 2
0
2
naagaraj
Hi, I am trying to pull event logs from remote machines using universal forwarders. I have done the configuration in ...
by naagaraj Engager in Getting Data In 06-16-2023
0 2
0
2
apolloops
We are using Splunk Enterprise server to send logs to be indexed. The monitor config is stored in '/opt/splunk/etc/sy...
by apolloops Observer in Getting Data In 06-16-2023
0 1
0
1
TouteSplunk
Hi! What are some common causes of failures to restart the Splunk Universal Forwarder in windows?Thank you!
by TouteSplunk Engager in Getting Data In 06-15-2023
0 2
0
2
Seawheels51
Greetings community expertsSearch results for JSON data received via curl and Rest API from AWS are five times the ac...
by Seawheels51 Path Finder in Getting Data In 06-15-2023
0 0
0
0
Lwoods
Hello, I have a few Linux devices that are located within the DMZ.  My 3 Splunk servers (Search Head, Indexer, Deploy...
by Lwoods Path Finder in Getting Data In 06-15-2023
0 4
0
4
Flower
Hi, I'm trying to set a source_type for CSV files that contains headers, and the fields are extracted fine.The proble...
by Flower Loves-to-Learn Lots in Getting Data In 06-15-2023
0 0
0
0
DanAlexander
Hello community, I am having an issue creating appropriate SEDCMD to reduce the size of specific Win events. I am try...
by DanAlexander Communicator in Getting Data In 06-15-2023
0 16
0
16
maayan
Hi,following ticket: https://community.splunk.com/t5/Splunk-Search/Join-all-objects-with-specific-object-within-the-s...
by maayan Path Finder in Getting Data In 06-15-2023
0 0
0
0
DanAlexander
Hello, community, I need help reducing Events containing 4688 and ParentProcessName=*splunkd.exe There is an excerpt ...
by DanAlexander Communicator in Getting Data In 06-14-2023
0 3
0
3
waJesu
I have created a lookup table for the blocked dns/url. I want to see if there are anywhere in my logs or in my enviro...
by waJesu Path Finder in Getting Data In 06-14-2023
0 3
0
3
Seawheels51
Greetings expertsBig picture: using Bash script and curl to download Rest API/JSON  from an AWS instance. The beginni...
by Seawheels51 Path Finder in Getting Data In 06-14-2023
0 0
0
0
DanAlexander
Hello, community,I am having a problem understanding why the WinEventLog sourcetype cannot be accepted as other sourc...
by DanAlexander Communicator in Getting Data In 06-14-2023
0 7
0
7
LearningGuy
How do I perform lookup multiple field but append the missing value.   ThanksFor example:Table A:Name        Role    ...
by LearningGuy Motivator in Getting Data In 06-14-2023
0 7
0
7
sini
Hi all, Having a strange issue. splunk add oneshot suddenly stops working. I have tried to re-read a file using  splu...
by sini Explorer in Getting Data In 06-14-2023
0 1
0
1
Lwoods
Hello, I've completed the following: 1. Installed Linux forwarder.  2. Assigned ownership and permissions to splunk u...
by Lwoods Path Finder in Getting Data In 06-14-2023
0 1
0
1
DanAlexander
Hello clever people, Would anyone be able to help me build a regex that would work on a SPL level e.g something like ...
by DanAlexander Communicator in Getting Data In 06-13-2023
0 11
0
11
ericzabowski
Hello! Been using the universal forwarder for years connecting to a heavy forwarder currently forwarding to splunk cl...
by ericzabowski Engager in Getting Data In 06-13-2023
0 1
0
1
Eshwar
Hi Community, We have installed Universal forwarder on windows 2019 server and were able to get the data into Splunk....
by Eshwar Engager in Getting Data In 06-13-2023
0 4
0
4
dhuynh
Hi everyone, For one of our client we are sending in json log data via log4j2 to the splunk cloud HEC token. we are u...
by dhuynh Loves-to-Learn Everything in Getting Data In 06-13-2023
0 2
0
2
Jambo
Hi,I am completely new to Splunk and I'm forwarding directly from FortiAnalyzer to Splunk on TCP1514. I have configur...
by Jambo Loves-to-Learn in Getting Data In 06-13-2023
0 0
0
0
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...