Getting Data In

Getting Data In
Community Activity
sab057
I have a strange problem. When I install the universal forwarder on my log server and perform a netstat -l I do not ...
by sab057 Explorer in Getting Data In 07-15-2011
2 4
2
4
byronschwab
I have been reading link:Splunk 4.2 Universal Forwarder *nix Why does a universal forwarder need the entire *nix app...
by byronschwab Engager in Getting Data In 07-15-2011
0 1
0
1
msantoro1
I am trying to write a custom search module in python that will check the host field of event data in a comprehensive...
by msantoro1 Explorer in Getting Data In 07-14-2011
0 4
0
4
_z_
Not new to Splunk, but new to 4.2.2. I had setup a forwarder and manually entered specific paths to monitor: /p01/fo...
by _z_ Explorer in Getting Data In 07-14-2011
1 7
1
7
I-Man
Hello all, We have Nessus running on a Linux server which also has a Splunk Heavy Forwarder 4.1.8. We have the Nessu...
by I-Man Communicator in Getting Data In 07-14-2011
1 2
1
2
tcutts
Most of our systems use rsyslog for logging, and log their events over UDP to a central splunk server. This works fi...
by tcutts New Member in Getting Data In 07-13-2011
0 2
0
2
gchkhikvadzecar
hello I need help. for masking text in .log file with splunk forwarder i have 16 numbers like 1111-2222-3333-4444 I ...
by gchkhikvadzecar Engager in Getting Data In 07-13-2011
1 1
1
1
imbuto
Hi, I saw several posts about this problem, but none with a valid answer. My problem is that I have a running Splunk...
by imbuto New Member in Getting Data In 07-13-2011
0 1
0
1
_z_
I have a 'dev/tst' db host.. but have dev app indexer and tst app indexer. Is there a way to configure a single forwa...
by _z_ Explorer in Getting Data In 07-12-2011
1 2
1
2
Cagey
I have several groupwise servers running forwarders to a single index server. For the most part the data is arriving...
by Cagey Engager in Getting Data In 07-12-2011
1 1
1
1
infosec_skrc
Hi all, I've studied that Splunk is capable of retenting the original logs feed in to it, also audit the changes if ...
by infosec_skrc Explorer in Getting Data In 07-12-2011
0 2
0
2
Vladimir
Hi, I have a forwarder which collects WMI (cpu, disk, processes, memory) from ~150 servers (win2008R2, win2003). In ...
by Vladimir Path Finder in Getting Data In 07-12-2011
0 1
0
1
Sqig
Hi. I have done a good amount of reading on this, and it seems to be a popular subject both in the documentation and...
by Sqig Path Finder in Getting Data In 07-11-2011
0 4
0
4
sconover
For testing purposes, I would really really like to force splunk to poll files in a monitor:// directory structure (a...
by sconover Engager in Getting Data In 07-11-2011
1 3
1
3
dbarbon
Hi I want to investigate about not responding application. 20 PC has this application installed but only 3 or 4 of th...
by dbarbon Engager in Getting Data In 07-11-2011
1 2
1
2
Nieucel
Hello, I connect a bat script as input data to my Splunk instance. This script reads a folder of websphere log files...
by Nieucel Engager in Getting Data In 07-11-2011
0 2
0
2
howyagoin
I've got some Active Directory logs which are CSV that I'm trying to split apart into appropriate fields. The header...
by howyagoin Contributor in Getting Data In 07-10-2011
0 2
0
2
MickSheppard
I'm trying to get Splunk to index the output from the Connect:Enterprise cmulist command. I run the command periodica...
by MickSheppard Path Finder in Getting Data In 07-08-2011
0 2
0
2
balbano
Hi guys, Trying to make a custom blacklist for one of my input monitor points that excludes certain directories and...
by balbano Contributor in Getting Data In 07-06-2011
0 1
0
1
gekoner
Is there a timezone classification for = TZ/Arizona?
by gekoner Communicator in Getting Data In 07-06-2011
0 2
0
2
smahtha
Two questions: Does Splunk forwarder maintain some kind of log files (or for that matter anything) which might keep ...
by smahtha Engager in Getting Data In 07-06-2011
0 1
0
1
rahiparikh
Hi, I wish to tag basic information in source data before I send it to Indexer. I wish to tag the host, sourcetype a...
by rahiparikh Explorer in Getting Data In 07-06-2011
0 1
0
1
hmsjclee
Hi, We're currently experimenting with having Splunk directly index our Syslog-NG logs. However, we seem to have lo...
by hmsjclee Engager in Getting Data In 07-06-2011
5 6
5
6
tasdienes
I have splunk running on windows. I want to monitor the /etc directory on a linux server with fschange. Is that pos...
by tasdienes Engager in Getting Data In 07-06-2011
0 2
0
2
pj
We have a fairly large Splunk environment with several 1000 hosts reporting in. Within our business we have requireme...
by pj Contributor in Getting Data In 07-06-2011
2 8
2
8
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...
Top Solution Authors