Getting Data In

Getting Data In
Community Activity
napo
My log format is below: 10.10.143.18 - "-" [21/Feb/2012:00:05:39 +0900] "POST /default/2881.ajax HTTP/1.1" 200 115538...
by napo Engager in Getting Data In 02-24-2012
0 4
0
4
greg
Splunk 4.3 is installed locally on my Windows computer where time zone is set correctly. I have timestamps formatted...
by greg Communicator in Getting Data In 02-24-2012
0 4
0
4
opsec
Is there a SPLUNK forwarder or agent to collect logs from Microsoft SCOM ACS database? If so, it the solution filly s...
by opsec New Member in Getting Data In 02-23-2012
0 1
0
1
beaumaris
We are using a 4.2.1 UF node to monitor a directory that contains web access log files, and send those files to an in...
by beaumaris Communicator in Getting Data In 02-23-2012
0 2
0
2
johnboldt
I am trying to configure Splunk to properly split events from a data source. Here's what an event looks like: ------...
by johnboldt Explorer in Getting Data In 02-23-2012
0 1
0
1
vaibhavbeohar
Hi, I have installed splunk in one server machine and able to get the data but when i try to get the data from remot...
by vaibhavbeohar Path Finder in Getting Data In 02-23-2012
0 2
0
2
raki
Hi I have taken SNMP data into splunk through a CSV conversion of polled data. The sample data looks as below 1.cg...
by raki New Member in Getting Data In 02-23-2012
0 1
0
1
timmy13
I would like to send some events from a source to one index, and the rest to another. Can someone point me to a link...
by timmy13 Communicator in Getting Data In 02-22-2012
0 13
0
13
Sheela
I have a Splunk indexer which hasn't been indexing logs from the past 3-4 days. I'm trying to troubleshoot and have g...
by Sheela Path Finder in Getting Data In 02-22-2012
1 2
1
2
tven
my goal is to eliminate the following event from being indexed as it is killing our license. Could not ungzip\. Hear...
by tven Explorer in Getting Data In 02-21-2012
1 1
1
1
aferone
We would like to retain data in our indexes by time only. Is this possible? I think I am doing it correctly for our...
by aferone Builder in Getting Data In 02-21-2012
0 3
0
3
kinkdotcom
I have an alert set up that surfaces suspicious activity by ip addresses which triggers an extremely simple shell scr...
by kinkdotcom New Member in Getting Data In 02-21-2012
0 1
0
1
grahamkenville
We have a number of MS SQL Server clusters with the Splunk Universal Forwarder installed. We would like to index th...
by grahamkenville Engager in Getting Data In 02-21-2012
0 1
0
1
kml_uvce
I have an output lifesize_cdr: INFO 24,16,8CC 9-107-Photon,172.20.129.30,,,,2012-02-07 16:22:21,2012-02-07 16:22:21,...
by kml_uvce Builder in Getting Data In 02-21-2012
0 5
0
5
ohl
Is there any way to change the scale on the message meter in the Exchange app? We normally generate about 10k emails...
by ohl New Member in Getting Data In 02-21-2012
0 1
0
1
ssingh5
Hi, I have configured following parameters for testing the log Archiving for one of my index named "os". But it is n...
by ssingh5 Path Finder in Getting Data In 02-21-2012
0 4
0
4
raki
I have a Cisco ACS serving radius requests for VPN users. The syslog is configured for splunk and is able to receive ...
by raki New Member in Getting Data In 02-21-2012
0 4
0
4
yrosario
We would like more information on how to setup splunk alert emails with smtp exchange 2007. If there are any suggesti...
by yrosario Engager in Getting Data In 02-21-2012
0 3
0
3
astepanov
Hi all, Splunk adds one hour to timestamp, when indexing logs. Example of my logs: [ 21/Feb/2012 1:05:32.306 PM]...
by astepanov Explorer in Getting Data In 02-21-2012
0 7
0
7
Splunker
Folks, Running Splunk v4.3 and trying to understand this phenomenon. In transforms.conf, something like this: [tran...
by Splunker Communicator in Getting Data In 02-18-2012
0 2
0
2
RalphT
By source type or file, I changed the line breaking setting but it never takes effect. On my local test system it wor...
by RalphT New Member in Getting Data In 02-18-2012
0 1
0
1
leiniao
Requirment Drop events before they get sent to the splunk indexer. Want to just send the lines with "Authenticatio...
by leiniao Explorer in Getting Data In 02-17-2012
1 3
1
3
chris
A universal forwarder asks me to start splunk when i try to use the cli. Has anyone else experienced this or similar ...
by chris Motivator in Getting Data In 02-17-2012
2 2
2
2
Glenn
I need to be able to add some information from the Splunk metadata (host and source) into the raw log. I'm looking at...
by Glenn Builder in Getting Data In 02-17-2012
2 4
2
4
jchensor
I was wondering if you can assign a search-time extracted field one value and then later, in a stanza that will be pr...
by jchensor Communicator in Getting Data In 02-16-2012
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...