Getting Data In

Getting Data In
Community Activity
ubko
I have events in a file with fields separated by "|" (e.g. blah|blah|20120406|095040|blah|blah). Can I use this to ...
by ubko Explorer in Getting Data In 04-06-2012
0 4
0
4
nkitmitto
We're using Syslog-ng in our environment and have a forwarder setup on syslog-ng to forward the logs to Splunk. But ...
by nkitmitto Explorer in Getting Data In 04-06-2012
1 4
1
4
tgiles
Hi, All. I'm trying to parse trend micro logs on a windows system using a heavy forwarder. Running into issues getti...
by tgiles Path Finder in Getting Data In 04-06-2012
1 3
1
3
jgauthier
I recently upgraded from 4.2 to 4.3. Since then, I cannot delete from a remote command line. sourcetype="dontcare" ...
by jgauthier Contributor in Getting Data In 04-06-2012
0 2
0
2
johanbraeken
Hi, I've installed a Universal Forwarder and it is forwarding Windows events fine to the Splunk server. Hoever, all...
by johanbraeken New Member in Getting Data In 04-06-2012
0 2
0
2
nterry
I was reading the docs for inputs.conf and noticed that there are host _regex and host _segment attributes to the mon...
by nterry Path Finder in Getting Data In 04-06-2012
0 2
0
2
jdunlea_splunk
Im indexing a CSV file and i have SHOULD_LINEMERGE set to "false" so it will break after each new line. However per ...
by jdunlea_splunk Splunk Employee Splunk Employee in Getting Data In 04-06-2012
0 1
0
1
johnsmith78
Hi I read all I could find in the docs and in splunkbase but I'm still struggling with that simple problem: I need t...
by johnsmith78 Engager in Getting Data In 04-05-2012
1 1
1
1
jdunlea_splunk
I want to know the following in relation to the REST API: Can we hit endpoints on UFs and LWFs?What is the REST endp...
by jdunlea_splunk Splunk Employee Splunk Employee in Getting Data In 04-05-2012
0 2
0
2
fnsbsd
I need to configure a universal forwarder to remotely collect WMI information (eventlogs) from various Windows hosts,...
by fnsbsd New Member in Getting Data In 04-05-2012
0 1
0
1
supersleepwalke
I have logs with two timestamps, one in UTC, one in local. I'm trying to index based on the second, because the first...
by supersleepwalke Communicator in Getting Data In 04-04-2012
2 10
2
10
Justin_Grant
We're investigating how to best help customers who are using both Splunk and other operations management/monitoring t...
by Justin_Grant Contributor in Getting Data In 04-04-2012
5 9
5
9
cvajs
v4.3.1 on sles 11.1 i have some data that was incorrectly indexed, the host name assignment got messed up. is there ...
by cvajs Contributor in Getting Data In 04-04-2012
1 5
1
5
sventura15
Hi, I would like to forward only successful and failed Windows login attempts from my Windows 2008 Server to my RHEL...
by sventura15 Explorer in Getting Data In 04-04-2012
1 22
1
22
Wushu
For the purpose of this problem lets say I have one index, in this index I receive syslog events - one such event has...
by Wushu Explorer in Getting Data In 04-04-2012
0 1
0
1
fresned
I have 6 directories that I'm indexing from /tom/ /linda/ /joe/ /time/ /jil/ /sue/ Each of the directories has a n...
by fresned Path Finder in Getting Data In 04-04-2012
0 1
0
1
carmackd
Since the Windows Event Viewer archives and generates a new log at 20MB (its maximum capacity), is there a risk that ...
by carmackd Communicator in Getting Data In 04-03-2012
0 2
0
2
cvajs
v4.3.1 on sles linux i have a source which is a file in a dynamic path and the source is configured to use segment #4...
by cvajs Contributor in Getting Data In 04-03-2012
0 8
0
8
IgorB
In new 4.3 instance running on Win2008 R2, external commands (e.g. sendemail) have started failing with errors like ...
by IgorB Path Finder in Getting Data In 04-03-2012
1 4
1
4
cvajs
v4.3.1 on sles 11.1 the standard whitelist for data source /var/log will produce dupe indexing because by default on...
by cvajs Contributor in Getting Data In 04-03-2012
2 5
2
5
sarah89
hello i want to get data from my juniper firwall , i set a configuration of juniper and i mention the port and the i...
by sarah89 Path Finder in Getting Data In 04-03-2012
0 10
0
10
Dark_Ichigo
I have indexed a file that contains a number of blank event s with a timestamp, my goal is to remove those blank/Empt...
by Dark_Ichigo Builder in Getting Data In 04-02-2012
0 1
0
1
gskorski
I have an issue with the Palo Alto apps. It seems that the transforms doesn't work. I can see my Palo Alto logs in th...
by gskorski Explorer in Getting Data In 04-02-2012
1 5
1
5
boris
From this line in the splunkd.log it appears the forwarder and receiver are connected? /opt/splunkforwarder/var/log/...
by boris Path Finder in Getting Data In 04-02-2012
4 1
4
1
sarah89
hello i want to extract logs of the firewall juniper ;, so i select remote event log collectiosn i insert the ip a...
by sarah89 Path Finder in Getting Data In 04-02-2012
0 3
0
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...
Top Solution Authors