Getting Data In

Getting Data In
Community Activity
gowen
I'm trying to monitor files on a Windows server and it isn't working. I've placed a few stanzas like this into etc/d...
by gowen Path Finder in Getting Data In 04-13-2012
2 7
2
7
I-Man
We are a 90% Windows environment. Since we upgraded to 4.3.1, the WMI log format has changed ever so slightly. While ...
by I-Man Communicator in Getting Data In 04-13-2012
0 1
0
1
jeff
I have the following stansas deployed to lightweight forwarders running Windows: props.conf [WinEventLog:Security] ...
by jeff Contributor in Getting Data In 04-13-2012
0 6
0
6
sahil_singh
Hi, How can one get the host and source IP addresses in the event logs instead of hostname in either places. It is c...
by sahil_singh Explorer in Getting Data In 04-13-2012
0 7
0
7
echalex
Hi, Is there any way of creating indexes on several indexers centrally? For a fairly small indexer-farm, it isn't mu...
by echalex Builder in Getting Data In 04-12-2012
0 2
0
2
khyoung7410
hi universalforwarder receives and send the syslog data to do? If possible, how do?
by khyoung7410 Communicator in Getting Data In 04-12-2012
0 2
0
2
Brian_Osburn
I have a request from a user who wants to get some stats from the Exchange App around specific users. Namely they're...
by Brian_Osburn Builder in Getting Data In 04-12-2012
3 2
3
2
jbirchall1
Is it possible to set up forwarders to index data on the path of the file and a portion of the file name automaticall...
by jbirchall1 New Member in Getting Data In 04-12-2012
0 2
0
2
eugenekogan
As far as I can tell, setting maxVolumeDataSizeMB does not trigger bucket moves and has no impact at all. Does anyone...
by eugenekogan Explorer in Getting Data In 04-12-2012
0 6
0
6
tchristian
When I try to install any app from the zipped file, I get an error like: There was an error processing the upload. L...
by tchristian New Member in Getting Data In 04-12-2012
0 3
0
3
Glenn
Hi, I am using a props/transforms TRANSFORM to add the source (log file) name to the _raw log event line. props.con...
by Glenn Builder in Getting Data In 04-12-2012
0 1
0
1
kenchisho
Hi guys, I have installed Splunk 4.3 on a MAC OSX 10.7. I am trying to index data with non utf encoding. I have tri...
by kenchisho Path Finder in Getting Data In 04-12-2012
0 3
0
3
echalex
Hi, I'm having a weird problem with recognizing timestamps. The actual timestamp looks like this: [2012-04-11 11:24:...
by echalex Builder in Getting Data In 04-12-2012
0 4
0
4
wbfoxii
I have a Universal Forwarder looking at a directory holding our proxy logs. New logs are dumped into the directory e...
by wbfoxii Communicator in Getting Data In 04-12-2012
1 3
1
3
sarah89
please I need help , I deployed a universal forward by following tutorial "distributed deployement manual" The un...
by sarah89 Path Finder in Getting Data In 04-12-2012
1 16
1
16
JPValadas
Hi again, I got one question in filtering and routing to indexer. i got my props like this: pros.conf [WinEven...
by JPValadas Explorer in Getting Data In 04-12-2012
0 9
0
9
sconnors
In our environment (mid-size enterprise with remote sites) we have our primary indexer on dedicated hardware. All dat...
by sconnors Engager in Getting Data In 04-12-2012
0 5
0
5
johnamcafee
We need to index content that may contain in-line gzip (or other compression) content. We do not need to search on th...
by johnamcafee New Member in Getting Data In 04-11-2012
0 1
0
1
Mick
I wanted to see how Splunk would index my data, so I configured it to index a few files into a 'test' index. Now tha...
by Mick Splunk Employee Splunk Employee in Getting Data In 04-11-2012
3 6
3
6
Jason
I'm looking at a Splunk instance right now that is getting 99+% of its data as one particular sourcetype, from two he...
by Jason Motivator in Getting Data In 04-11-2012
1 5
1
5
mataharry
Hi I have a license pool for X Gb per day, and I blow it every almost every single day. How to selectively reduce m...
by mataharry Communicator in Getting Data In 04-11-2012
1 3
1
3
cvajs
v4.3 sles 11.1 can you explain for me this transform [csafields] REGEX = ^[^\|]+\|([^\|]+)\|([^\|]+)\|([^\|]+)\|([^...
by cvajs Contributor in Getting Data In 04-11-2012
0 8
0
8
ma_anand1984
My log goes like this. I want all contents between "BeginEvent" and "EndEvent" as a single event. Any help? Will grea...
by ma_anand1984 Contributor in Getting Data In 04-11-2012
0 4
0
4
echalex
Hi, I'm just setting up a deployment server and created a simple app to test it. The app was installed fine on my un...
by echalex Builder in Getting Data In 04-11-2012
0 5
0
5
nkitmitto
All day, I've been watching the amount of events indexed in Splunk go up and down. It stays in the 1.8-1.9 billion e...
by nkitmitto Explorer in Getting Data In 04-10-2012
1 1
1
1
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...
Top Solution Authors