Getting Data In

Getting Data In
Community Activity
TouteSplunk
Hi! What are some common causes of failures to restart the Splunk Universal Forwarder in windows?Thank you!
by TouteSplunk Engager in Getting Data In 06-15-2023
0 2
0
2
Seawheels51
Greetings community expertsSearch results for JSON data received via curl and Rest API from AWS are five times the ac...
by Seawheels51 Path Finder in Getting Data In 06-15-2023
0 0
0
0
Lwoods
Hello, I have a few Linux devices that are located within the DMZ.  My 3 Splunk servers (Search Head, Indexer, Deploy...
by Lwoods Path Finder in Getting Data In 06-15-2023
0 4
0
4
Flower
Hi, I'm trying to set a source_type for CSV files that contains headers, and the fields are extracted fine.The proble...
by Flower Loves-to-Learn Lots in Getting Data In 06-15-2023
0 0
0
0
DanAlexander
Hello community, I am having an issue creating appropriate SEDCMD to reduce the size of specific Win events. I am try...
by DanAlexander Communicator in Getting Data In 06-15-2023
0 16
0
16
maayan
Hi,following ticket: https://community.splunk.com/t5/Splunk-Search/Join-all-objects-with-specific-object-within-the-s...
by maayan Path Finder in Getting Data In 06-15-2023
0 0
0
0
DanAlexander
Hello, community, I need help reducing Events containing 4688 and ParentProcessName=*splunkd.exe There is an excerpt ...
by DanAlexander Communicator in Getting Data In 06-14-2023
0 3
0
3
waJesu
I have created a lookup table for the blocked dns/url. I want to see if there are anywhere in my logs or in my enviro...
by waJesu Path Finder in Getting Data In 06-14-2023
0 3
0
3
Seawheels51
Greetings expertsBig picture: using Bash script and curl to download Rest API/JSON  from an AWS instance. The beginni...
by Seawheels51 Path Finder in Getting Data In 06-14-2023
0 0
0
0
DanAlexander
Hello, community,I am having a problem understanding why the WinEventLog sourcetype cannot be accepted as other sourc...
by DanAlexander Communicator in Getting Data In 06-14-2023
0 7
0
7
LearningGuy
How do I perform lookup multiple field but append the missing value.   ThanksFor example:Table A:Name        Role    ...
by LearningGuy Motivator in Getting Data In 06-14-2023
0 7
0
7
sini
Hi all, Having a strange issue. splunk add oneshot suddenly stops working. I have tried to re-read a file using  splu...
by sini Explorer in Getting Data In 06-14-2023
0 1
0
1
Lwoods
Hello, I've completed the following: 1. Installed Linux forwarder.  2. Assigned ownership and permissions to splunk u...
by Lwoods Path Finder in Getting Data In 06-14-2023
0 1
0
1
DanAlexander
Hello clever people, Would anyone be able to help me build a regex that would work on a SPL level e.g something like ...
by DanAlexander Communicator in Getting Data In 06-13-2023
0 11
0
11
ericzabowski
Hello! Been using the universal forwarder for years connecting to a heavy forwarder currently forwarding to splunk cl...
by ericzabowski Engager in Getting Data In 06-13-2023
0 1
0
1
Eshwar
Hi Community, We have installed Universal forwarder on windows 2019 server and were able to get the data into Splunk....
by Eshwar Engager in Getting Data In 06-13-2023
0 4
0
4
dhuynh
Hi everyone, For one of our client we are sending in json log data via log4j2 to the splunk cloud HEC token. we are u...
by dhuynh Loves-to-Learn Everything in Getting Data In 06-13-2023
0 2
0
2
Jambo
Hi,I am completely new to Splunk and I'm forwarding directly from FortiAnalyzer to Splunk on TCP1514. I have configur...
by Jambo Loves-to-Learn in Getting Data In 06-13-2023
0 0
0
0
tilburn
We are currently using SFG to transfer files, sending fie movement and info data to DB tables, and then using Splunk ...
by tilburn Observer in Getting Data In 06-13-2023
0 2
0
2
haoban
I'm using a bash script to call Cisco ESA API and I get the following JSON events. sourcetype="cisco:esa:api:by:...
by haoban Path Finder in Getting Data In 06-12-2023
0 3
0
3
zapping575
I have a particularly challenging log format and would appreciate any inputs on how to tackle this problem. Problem L...
by zapping575 Communicator in Getting Data In 06-12-2023
0 4
0
4
sarit_s
Hello I have some kind of data that I want to filter to different index and in the future i would like to stop this i...
by sarit_s Communicator in Getting Data In 06-12-2023
0 1
0
1
sekhar463
Hi All i have a log source in the server timezone is in CST and logs are coming into the server as UTC time zone logs...
by sekhar463 Path Finder in Getting Data In 06-11-2023
0 12
0
12
Srini
Hi All, Could someone please provide steps to configure Active MQ logs into Splunk in the existing environment. Thank...
by Srini Engager in Getting Data In 06-11-2023
0 0
0
0
sagar_shubham23
Hi Team, I have created a props for line breaking. I have tested it using a process of Add Data and Set sourcetype an...
by sagar_shubham23 Explorer in Getting Data In 06-10-2023
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors