Admin Other

Admin Other
Category Activity
nawazns5038
Hi, I want to create a role and import capabilities or index permissions . Suppose , I have role A which has indexe...
by nawazns5038 Builder in Security 12-04-2018
0 4
0
4
Paolo_Prigione
I know that since 4.1 summary indexing does not count against license anymore. However, what if I have multiple summa...
by Paolo_Prigione Builder in Installation 12-04-2018
2 4
2
4
FrankVl
While ingesting a data source that comes in over syslog with a basic structure of syslog header key="value",key="valu...
by FrankVl Ultra Champion in Knowledge Management 12-04-2018
0 1
0
1
coreyf311
6 node SHC. SHC complains with this error from time to time. KV Store has changed status to failed. _id field value...
by coreyf311 Path Finder in Installation 12-04-2018
0 2
0
2
fb_chris
Hello, I would like to optimize my queries — how can I measure the time it takes to execute them? I understand that ...
by fb_chris Engager in Knowledge Management 12-04-2018
0 2
0
2
lybinhlap
Dear everyone, Have a good day ahead. I am having the following issue that need your advice. Recently, I have deploy...
by lybinhlap New Member in Knowledge Management 12-03-2018
0 2
0
2
d389133
Hi All, I'm struggling to get an eval macro working using conditionals (either case or if statement). No matter wha...
by d389133 Explorer in Knowledge Management 12-03-2018
0 2
0
2
aelliott
Since installing Enterprise Security, Splunk-optimize crashes all the time on my machine. I've tested this on another...
by aelliott Motivator in Installation 12-03-2018
1 12
1
12
net1993
Hi Is there some place in Splunk Docs where I can find the definition of the field status in _internal log , source ...
by net1993 Path Finder in Installation 12-03-2018
1 1
1
1
rbal_splunk
We have read documentation and planning as per documentation, we are looking for feedback for common recommendation ...
by rbal_splunk Splunk Employee Splunk Employee in Knowledge Management 12-02-2018
0 3
0
3
maheshsat
I have to remove a double inverted comma from a value. Query: | rex "(.Item=(?[^\,]+))"| rex "(.Reserved1=(?[^\,]+)...
by maheshsat Explorer in Security 12-02-2018
0 10
0
10
Trainsada
Setting mgmt to port: 9000 Failed to open splunk.secret 'C:\Program Files\Splunk\etc\auth\splunk.secret' file. Some p...
by Trainsada Engager in Installation 11-30-2018
0 3
0
3
danzemmels
I'm trying to configure having Splunk Light (free test drive version) push to the Splunk Cloud Service from our Red H...
by danzemmels New Member in Security 11-29-2018
0 2
0
2
batsonpm
I have two queries. One that pulls the login info and one that pulls the logout info. I’ve been banging my head on ge...
by batsonpm Path Finder in Installation 11-28-2018
0 1
0
1
dshah2
// Log in using a basic authorization header // Note: Do not call the Service.login method Service se...
by dshah2 Engager in Security 11-28-2018
2 3
2
3
ips_mandar
Hi, I have one role which has Restrict search terms as index=abc $table="azuredignostics" then how this user having...
by ips_mandar Builder in Security 11-28-2018
0 3
0
3
mj92
I set up my account on my device windows 10 in order to do the fundamentals course. Then when it came to installing s...
by mj92 New Member in Security 11-27-2018
0 0
0
0
Hemnaath
Hi All, Currently facing an issue in parsing the data and also the data is not conformed with CIM model. Environme...
by Hemnaath Motivator in Knowledge Management 11-27-2018
0 6
0
6
rbal_splunk
I am trying to migrate date from local storage to remote store and would like to understand best way to monitor the p...
by rbal_splunk Splunk Employee Splunk Employee in Knowledge Management 11-27-2018
0 2
0
2
sshahmoon
I have a table and I want to trim the values for one field, such that all characters from the first digits onwards ar...
by sshahmoon New Member in Security 11-27-2018
0 7
0
7
landen99
The following two searches yield very different results: ...|search NOT [...|rename field AS query] ...| rename quer...
by landen99 Motivator in Knowledge Management 11-27-2018
0 1
0
1
jip31
Hello I have XML logs and I want to extract all the text between these tags What is the better way to do this please...
by jip31 Motivator in Knowledge Management 11-26-2018
0 4
0
4
rholm01
Which folders under $SPLUNK_HOME/etc get written over during a Splunk Enterprise upgrade? I am able to find the files...
by rholm01 Explorer in Installation 11-26-2018
0 3
0
3
ips_mandar
Hi, I am using OMS add-on. I have one index with one host,source and source type. Now I want to limit access to sp...
by ips_mandar Builder in Security 11-26-2018
0 14
0
14
ali_alnajjar_ve
Hi Guys: Please who can give me a help !! I'm not able to start splunk. bash-4.1$ /opt/splunk/bin/splunk start Spl...
by ali_alnajjar_ve Explorer in Security 11-26-2018
1 10
1
10
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...
Top Karma Authors