Getting Data In

Getting Data In
Community Activity
Michael
I have a very simple search/chart to look for failed logons on my domain: EventCode=4625 Account_Name="*" | timechar...
by Michael Contributor in Getting Data In 04-25-2012
1 3
1
3
lpolo
I have a set of log events that contain the following Key value pair "source" : "integer". Therefore, splunk is repor...
by lpolo Motivator in Getting Data In 04-25-2012
0 4
0
4
rmcdougal
I have data being sent in by universal forwarders on port 9908 that I would like put into a custom index. This is ho...
by rmcdougal Path Finder in Getting Data In 04-24-2012
0 1
0
1
rgcurry
I have just added two new logs to be monitored on one of my servers but the data is not coming back for those files. ...
by rgcurry Contributor in Getting Data In 04-24-2012
0 4
0
4
reed_kelly
We have a number of heavy forwarders sending cooked data to our indexers. We can get the total KBs sent by each forwa...
by reed_kelly Contributor in Getting Data In 04-24-2012
0 10
0
10
tonopahtaos
Let us say you have following lines in your props.conf file: [WinEventLog:Security] REPORT-common = user-account-ch...
by tonopahtaos Path Finder in Getting Data In 04-24-2012
0 6
0
6
cphair
Hello, I have Splunk on some Windows VMs that run on ESX hosts. For each guest, the ESX hosts generate customized p...
by cphair Builder in Getting Data In 04-24-2012
0 1
0
1
rgcurry
I was tracking down a problem with a group of Forwarders reporting the parsingqueue was blocked. To resolve that, I h...
by rgcurry Contributor in Getting Data In 04-24-2012
1 4
1
4
gerald_huddlest
I have a number of IIS logs being splunked across a number of servers but an struggling to work out how to present th...
by gerald_huddlest Path Finder in Getting Data In 04-24-2012
0 1
0
1
rmcdougal
I am attempting to drop WinEventLog:Security EventCode's at the Indexer and I am not having any success. I have read...
by rmcdougal Path Finder in Getting Data In 04-24-2012
1 5
1
5
attgjh1
What is the difference data type and data source. When I used the manager to add a data type (and proceeding with "...
by attgjh1 Communicator in Getting Data In 04-22-2012
1 4
1
4
let_eat_bee
I've stucked on a couple of issues on Splunk since there was changes in timezone shift in my country. The main probl...
by let_eat_bee New Member in Getting Data In 04-22-2012
0 6
0
6
pkeller
http://docs.splunk.com/Documentation/Splunk/latest/Data/overridedefaulthostassignments I've been trying to set up wh...
by pkeller Contributor in Getting Data In 04-21-2012
0 3
0
3
asarolkar
I have a subsearch like this: sourcetype="syslog" SERIAL=* | eval SERIAL_NUM=SERIAL | lookup FileLookup SERIAL_NUM ...
by asarolkar Builder in Getting Data In 04-21-2012
0 3
0
3
jodros
There are several servers with universal forwarders loaded that are sending logs to our Splunk environment. These se...
by jodros Builder in Getting Data In 04-20-2012
0 1
0
1
alexethier
I have a python script that read data from the stdin, convert the input and output human readable text to the stdout....
by alexethier Engager in Getting Data In 04-20-2012
1 3
1
3
maverick
If I enable fschange input on my Splunk Universal Forwarder, will it work the same as on a regular forwarder?
by maverick Splunk Employee Splunk Employee in Getting Data In 04-20-2012
0 4
0
4
menkurau
I have a stream (udp 518) of syslog coming in from two different syslog servers. I thought that I would be able to s...
by menkurau Path Finder in Getting Data In 04-20-2012
0 1
0
1
my_splunk
I have installed splunk on windows 2008 to analyze iis log file. I want to avoid to index log entries with 401 http s...
by my_splunk Path Finder in Getting Data In 04-20-2012
0 3
0
3
mmikrouli
Hi! I am a newbie to Splunk. I have an application on a linux server that produces logs in log4j format. I want to re...
by mmikrouli New Member in Getting Data In 04-20-2012
0 2
0
2
nikhilagrawal
I have a situation. I have defined the source type under Deployment server- deployment app>local>prop.conf> as [so...
by nikhilagrawal Path Finder in Getting Data In 04-20-2012
0 3
0
3
tevgey23
Can Splunk deployment server detect a container ID in a virtual environment, which was created... say by openvz, and ...
by tevgey23 Explorer in Getting Data In 04-20-2012
0 2
0
2
tevgey23
Is it possible to create different classes of servers so when the forwarder checks in, it get a specific configuratio...
by tevgey23 Explorer in Getting Data In 04-19-2012
0 1
0
1
mznikkip
I've read the documentation on how to send SNMP traps to other systems, however, I'm confused. How does traphosts.pl ...
by mznikkip Engager in Getting Data In 04-19-2012
0 8
0
8
mikehughes
I'm trying to find a way to analyse iTunes log files - I'm pretty sure Splunk can help me here, have got some data in...
by mikehughes New Member in Getting Data In 04-19-2012
0 1
0
1
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...
Top Solution Authors