| Hi, I am trying to use a lookup to whitelist/exclude some values from search results such as process_name. But whene... by adespino Explorer in Getting Data In 06-20-2023 0 3 | 0 | 3 | ||
| Hi Team, How to install UF via GPO?Any specific command line to run the file .msi that use our username and password... by ask Engager in Getting Data In 06-20-2023 0 5 | 0 | 5 | ||
| Hi, I'm experiencing an issue where logs with EventCode=4625 from Windows systems (an account failed to log on) are n... by splk_user Path Finder in Getting Data In 06-20-2023 0 10 | 0 | 10 | ||
| Hi There,I am attempting to ingest data from the WindowsUpdateLog using the Splunk Windows TA. I have attached a scre... by jamie1 Communicator in Getting Data In 06-20-2023 0 1 | 0 | 1 | ||
| Hi Team, I'm onboarding custom winevents to Splunk [WinEventLog://Microsoft-Windows-TerminalServices-RemoteConnection... by vikramauto New Member in Getting Data In 06-20-2023 0 2 | 0 | 2 | ||
| Hi, I am new to splunk and trying to upload data for practising. I amd using the data from the the below link. https:... by suvi1611 New Member in Getting Data In 06-19-2023 0 2 | 0 | 2 | ||
| I am ingesting data into Splunk Cloud using Cribl (not directly via GCP Add On) and using Google Cloud TA on the sear... by juulengineer Engager in Getting Data In 06-19-2023 0 0 | 0 | 0 | ||
| Hitimestamp of data that send via logstash change when store in splunk index. what is the reason? index="influx2splun... by indeed_2000 Motivator in Getting Data In 06-19-2023 0 7 | 0 | 7 | ||
| Hi, I'm trying to set 2 rules in my workload management pool - search_type=adhoc AND runtime>1m -> Move search to alt... by saleshai Explorer in Getting Data In 06-18-2023 0 2 | 0 | 2 | ||
| Hi I'm trying to use spath to break doen json log, but it duplicates these two fields "time" and "@timestamp" when I ... by indeed_2000 Motivator in Getting Data In 06-18-2023 0 1 | 0 | 1 | ||
| Having this intermittent problem with UF on multiple servers where it occasionally fails to start up the WinEventLog ... by gportnoy Explorer in Getting Data In 06-17-2023 0 3 | 0 | 3 | ||
| Hi All, We are collecting different logs from same source on different UDP ports on Heavy forwarder. Heavy forwarder ... by shubham87 Explorer in Getting Data In 06-17-2023 0 11 | 0 | 11 | ||
| Hi, I wana keep only logs Not containing the word "chatbot". This word is present in the _raw data I'm using the me... by _olivier_ Path Finder in Getting Data In 06-17-2023 0 7 | 0 | 7 | ||
| The app write log entries to a log file, say /var/theapp/thelogfile.log.The app is configured to roll the log file on... by splunkingguy Explorer in Getting Data In 06-16-2023 0 6 | 0 | 6 | ||
| I wish to remove unneeded text from Windows event logs before they are indexed. Specifically, Windows event 4624 cont... by jkalbert Explorer in Getting Data In 06-16-2023 0 2 | 0 | 2 | ||
| Hi, I am trying to pull event logs from remote machines using universal forwarders. I have done the configuration in ... by naagaraj Engager in Getting Data In 06-16-2023 0 2 | 0 | 2 | ||
| We are using Splunk Enterprise server to send logs to be indexed. The monitor config is stored in '/opt/splunk/etc/sy... by apolloops Observer in Getting Data In 06-16-2023 0 1 | 0 | 1 | ||
| Hi! What are some common causes of failures to restart the Splunk Universal Forwarder in windows?Thank you! by TouteSplunk Engager in Getting Data In 06-15-2023 0 2 | 0 | 2 | ||
| Greetings community expertsSearch results for JSON data received via curl and Rest API from AWS are five times the ac... by Seawheels51 Path Finder in Getting Data In 06-15-2023 0 0 | 0 | 0 | ||
| Hello, I have a few Linux devices that are located within the DMZ. My 3 Splunk servers (Search Head, Indexer, Deploy... by Lwoods Path Finder in Getting Data In 06-15-2023 0 4 | 0 | 4 | ||
| Hi, I'm trying to set a source_type for CSV files that contains headers, and the fields are extracted fine.The proble... by Flower Loves-to-Learn Lots in Getting Data In 06-15-2023 0 0 | 0 | 0 | ||
| Hello community, I am having an issue creating appropriate SEDCMD to reduce the size of specific Win events. I am try... by DanAlexander Communicator in Getting Data In 06-15-2023 0 16 | 0 | 16 | ||
| Hi,following ticket: https://community.splunk.com/t5/Splunk-Search/Join-all-objects-with-specific-object-within-the-s... by maayan Path Finder in Getting Data In 06-15-2023 0 0 | 0 | 0 | ||
| Hello, community, I need help reducing Events containing 4688 and ParentProcessName=*splunkd.exe There is an excerpt ... by DanAlexander Communicator in Getting Data In 06-14-2023 0 3 | 0 | 3 | ||
| I have created a lookup table for the blocked dns/url. I want to see if there are anywhere in my logs or in my enviro... by waJesu Path Finder in Getting Data In 06-14-2023 0 3 | 0 | 3 |