Getting Data In

Getting Data In
Community Activity
fk319
I have several servers sending WinEventLogs to my server. I have not control of the remote servers, so I would like ...
by fk319 Builder in Getting Data In 09-18-2011
1 2
1
2
Branden
I'm trying to get a blacklist in my inputs.conf to work correctly, but it's just not happening. It seems so simple......
by Branden Builder in Getting Data In 09-16-2011
0 5
0
5
triptrops
I need help on my Splunk server. I cannot see the host the splunk server. here is what my setup went: 1) install ful...
by triptrops Explorer in Getting Data In 09-14-2011
0 3
0
3
sonam
I'm working with Splunk setup to copy and index disk logs from remote servers using scheduled rsync transfer. The r...
by sonam Explorer in Getting Data In 09-14-2011
0 4
0
4
mmattek
ok, we have a field defined (user), and for another sourcetype I have the extracts already occurring for appUser and ...
by mmattek Path Finder in Getting Data In 09-14-2011
0 10
0
10
oreni
Hello, I was trying to set a new lookup table, and locate props.conf and transforms.conf, but wasn't able to find t...
by oreni Explorer in Getting Data In 09-14-2011
0 1
0
1
laurentjehu
Hi, I'm testing Splunk to monitoring the log of an application. The logs are generated with log4j. When I configure ...
by laurentjehu Engager in Getting Data In 09-14-2011
0 1
0
1
jordans
ERROR ExecProcessor - Ignoring: "\\C:\Program Files\Splunk\etc\apps\test\bin\intodns.py" This new scripted input I ...
by jordans Path Finder in Getting Data In 09-13-2011
0 2
0
2
fox
Running 4.2.1, we are monitoring many csv files that differ on listed fields. We have splunk configured to dynamicall...
by fox Path Finder in Getting Data In 09-13-2011
0 2
0
2
mataharry
Hi I am trying to have splunk monitoring a log file. But splunk indexed it once, and since is skipping it every time...
by mataharry Communicator in Getting Data In 09-13-2011
3 3
3
3
maverick
Currently, I'm using WMI to pull WinEvents from 17 Windows running on VMs. They are each the exact same and were buil...
by maverick Splunk Employee Splunk Employee in Getting Data In 09-12-2011
0 3
0
3
maverick
I am feeding a log event into Splunk that has a julian date and a time that consists of seconds since midnight: 245...
by maverick Splunk Employee Splunk Employee in Getting Data In 09-12-2011
2 4
2
4
giovere
I'm trying to make indexes retire after 60 seconds, here is how my indexes.conf looks like: [default] frozenTimePeri...
by giovere Path Finder in Getting Data In 09-12-2011
0 4
0
4
I_am_Jeff
We have several NetApps that require log retention. Getting log events to Splunk appears to be an odd configuration....
by I_am_Jeff Communicator in Getting Data In 09-09-2011
0 2
0
2
jaoui
If i am setting up a heavy forwarder to monitor directories and tag indexes, do i need to create an indexes.conf on i...
by jaoui Path Finder in Getting Data In 09-09-2011
0 1
0
1
jaoui
If i am setting up a heavy forwarder to monitor directories and tag indexes, do i need to create an indexes.conf on i...
by jaoui Path Finder in Getting Data In 09-08-2011
0 4
0
4
gnovak
I have a bunch of logs I've added to splunk and created sourcetypes for these logs. These logs are updated once a wee...
by gnovak Builder in Getting Data In 09-08-2011
0 1
0
1
gnovak
I have a bunch of logs I've added to splunk and created sourcetypes for these logs. These logs are updated once a we...
by gnovak Builder in Getting Data In 09-07-2011
0 2
0
2
lutel
Hello All, We are looking for the possiblity of having local authentication for part of the users, and RADIUS authen...
by lutel Explorer in Getting Data In 09-07-2011
0 1
0
1
pstamati
Hi all!. I'm new with Splunk. I´m trying to exclude some events from being indexed but I really don´t know where to s...
by pstamati Path Finder in Getting Data In 09-07-2011
3 8
3
8
RVDowning
Newbie here with an issue. Running Splunk 4.2.2 indexer on Linux and universal forwarders 4.2.2 on Windows 7 machine...
by RVDowning Contributor in Getting Data In 09-07-2011
1 6
1
6
mataharry
I installed 4.2 splunk, and made it a forwarder (not lightweight or universal forwarder) Because I want to do some fi...
by mataharry Communicator in Getting Data In 09-07-2011
3 7
3
7
giovere
I'm trying to change sinkhole directory and configure it so that it will delete files only after 5 days or so. Is the...
by giovere Path Finder in Getting Data In 09-07-2011
1 5
1
5
remy06
I have been monitoring a log file via file monitor input.I disabled the monitoring temporary for a few days but when ...
by remy06 Contributor in Getting Data In 09-07-2011
0 3
0
3
alexander_lucas
If I define this in .../local/indexes.conf [default] coldToFrozenDir = $SPLUNK_DB/frozenArchive Will Splunk roll ...
by alexander_lucas Explorer in Getting Data In 09-06-2011
1 3
1
3
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors