Getting Data In

Getting Data In
Community Activity
lpolo
Can a phyton script modify a log event on the fly in a universal forwarder? For example: file.log: timestamp <id=x...
by lpolo Motivator in Getting Data In 03-29-2012
0 1
0
1
inglisn
I have an event that starts something like this: 2012-03-20 06:07:00.000,BLANK,11.12.13.14,,,IP,Linux hostname 2.6.1...
by inglisn Path Finder in Getting Data In 03-29-2012
0 2
0
2
misteryuku
I would like to create a new field extraction through props.config for search app. For example i want to retrieve a c...
by misteryuku Communicator in Getting Data In 03-29-2012
0 9
0
9
misteryuku
Can i access the Splunk's configuration files throught the Splunk's REST API?
by misteryuku Communicator in Getting Data In 03-28-2012
0 1
0
1
freephoneid
My log snippet is as shown below: productid=12 email=abc@gg.com productid=13 email=pqr@aa.com productid=14 email=xyz...
by freephoneid Path Finder in Getting Data In 03-28-2012
0 5
0
5
mloven
Hi all. I've got a 4.3 universal forwarder pointing to a 4.3 indexer, both on CentOS. The forwarder is monitoring a...
by mloven Path Finder in Getting Data In 03-28-2012
1 5
1
5
erga00
Has anyone run into this? I've opened a case with Support but I thought I'd ask here as well. None of the Windows in...
by erga00 Path Finder in Getting Data In 03-27-2012
0 2
0
2
Derek
I have a universal forwarder (4.2.2) setup that sends text logs, event logs and WMI counters. When the data gets ind...
by Derek Path Finder in Getting Data In 03-27-2012
0 3
0
3
matthewcanty
I'm new to Splunk - as in this morning - but have been shown around it a few times. I've just downloaded the free ver...
by matthewcanty Communicator in Getting Data In 03-27-2012
0 2
0
2
ilanz
Hi, my setup is two nodes, each has a Splunk Universal Forwarder which reads a logs directory and sends those logs to...
by ilanz New Member in Getting Data In 03-27-2012
0 2
0
2
the_wolverine
I have XML in the following format that just refuses to break where I want it to -- <Object Type="Microsoft.Exchang...
by the_wolverine Champion in Getting Data In 03-26-2012
1 4
1
4
the_wolverine
I need a syntax example for host_regex to pull the hostname out of a share like the following: [monitor://\\norcal_s...
by the_wolverine Champion in Getting Data In 03-26-2012
0 1
0
1
awilkoski
I am using splunk as our syslog server. I am new to splunk and everything about it. Currently the data coming in is f...
by awilkoski Engager in Getting Data In 03-26-2012
1 2
1
2
seanp
I was wondering if someone could validate an answer for me. I have installed the Universal Forwarder on a domain con...
by seanp Path Finder in Getting Data In 03-26-2012
0 1
0
1
boris
I want to install splunkforwarder_packagename.deb. What is the packagename I should use (or where can I see a list o...
by boris Path Finder in Getting Data In 03-23-2012
0 1
0
1
carasso
How can I get my Splunk events to use Star Trek "Stardate" time? A stardate is a date in the fictional system of t...
by carasso Splunk Employee Splunk Employee in Getting Data In 03-23-2012
10 1
10
1
JasonCzerak
Has anyone figured out how to monitor /dev/console?
by JasonCzerak Explorer in Getting Data In 03-23-2012
1 1
1
1
misteryuku
Whenever i want to create new events via REST receivers endpoint, can i create new fields and set their values for th...
by misteryuku Communicator in Getting Data In 03-22-2012
0 16
0
16
elusive
I go to "Manager » Data inputs » WMI data collections » Add New" and enter the host name under "Select target host". ...
by elusive Splunk Employee Splunk Employee in Getting Data In 03-22-2012
1 2
1
2
boris
I am new to Splunk. What do the indexed fields timeendpos and timestartpos represent? Since one report the company ...
by boris Path Finder in Getting Data In 03-22-2012
0 1
0
1
phoenixdigital
I have a FTP data collector which pulls in files from an FTP server and dumps them into a directory monitored by Splu...
by phoenixdigital Builder in Getting Data In 03-22-2012
0 7
0
7
msarro
I am just starting to dabble with the splunk API. I am following the examples shown in the splunk documentation. The ...
by msarro Builder in Getting Data In 03-22-2012
1 5
1
5
mslvrstn
I thought this would be easy to do, but I didn't see any way to to this in inputs.conf.spec I have a cluster of mach...
by mslvrstn Communicator in Getting Data In 03-22-2012
0 11
0
11
briguy
Hi all - I'm looking for some advice on managing different combinations of inputs based on server type. For example, ...
by briguy Engager in Getting Data In 03-22-2012
1 2
1
2
sgarvin55
I want to assign ALL sources the sourcetype my_logs_555, and then use the Priority parameter in props.conf to apply a...
by sgarvin55 Splunk Employee Splunk Employee in Getting Data In 03-21-2012
1 1
1
1
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...
Top Solution Authors