Getting Data In

Why does "splunk train cmd classify" say "Parameters must be in the form '-parameter value'

mpatnode
Path Finder

I tried "splunk train sourcetype filename sourcename" and received the same error. Then I found this answer and got the following:

$ /opt/splunk/bin/splunk train cmd classify /home/mike/work/current/tests/last_2k3.log centrifydc Parameters must be in the form '-parameter value'

So back to the original question, do you pass the train command a sample log file, or something else?

Tags (2)
1 Solution

rroberts
Splunk Employee
Splunk Employee

Remove the word train in your command. Classify replaces train.

View solution in original post

rroberts
Splunk Employee
Splunk Employee

Remove the word train in your command. Classify replaces train.

mpatnode
Path Finder

Doh! Awsome. Thanks.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...