| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Hi,
  We are currently considering deploying a small Splunk Enterprise platform on AWS.
  Details:
  10G/d of ingesti...
        
         
           by 
           
                
                    
                        docid50693
                    
                
           
             
             
               New Member
             
           
           in
           Knowledge Management
           
           
              
               11-18-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hello,  I'm looking for any help/documentation regarding instrumenting applicating with Opentelemetry and sending dat...
        
         
           by 
           
                
                    
                        Vitaliy
                    
                
           
             
             
               Observer
             
           
           in
           Knowledge Management
           
           
              
               11-17-2020
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        What is the definition of the [Tag] is?What is the definition of the [Eventtype] is?What is the point of difference b...
        
         
           by 
           
                
                    
                        kedjjang
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               05-26-2015
             
           
         
        | 
		
		2
   | 
	  
	  10
	 | |||
| 
        Using both 8.0.1 and 8.0.6, I am unable to redeploy apps when attempting to deploy Splunk_ML_Toolkit with Splunk_SA_S...
        
         
           by 
           
                
                    
                        sylim_splunk
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Knowledge Management
           
           
              
               11-15-2020
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I want to create an Accelarated Data Model. For that I have created a Base Search which has a join command. However, ...
        
         
           by 
           
                
                    
                        santosh_sshanbh
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               11-13-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        tl:dr - questions I am looking to get answers for:1.  Is there a better way to do this?2. Is it possible to dynamical...
        
         
           by 
           
                
                    
                        david_keough
                    
                
           
             
             
               Explorer
             
           
           in
           Knowledge Management
           
           
              
               10-27-2020
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi,
  I'm going to tear down an old separate Splunk environment to consolidate on 1 platform.
  The main platform is ...
        
         
           by 
           
                
                    
                        jihape
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               11-08-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        I was going through the documents on Datamodel Acceleration. Can you please help me in confirming if my understanding...
        
         
           by 
           
                
                    
                        koshyk
                    
                
           
             
             
               Super Champion
             
           
           in
           Knowledge Management
           
           
              
               03-24-2016
             
           
         
        | 
		
		1
   | 
	  
	  5
	 | |||
| 
        All, 
  I have an index (index=config) where all I store are the sourcetype=config_file. I currently use the stock co...
        
         
           by 
           
                
                    
                        daniel333
                    
                
           
             
             
               Builder
             
           
           in
           Knowledge Management
           
           
              
               10-28-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        I want to set up a user friendly data catalogue for a large Splunk deployment.
  As I'm a newbie i'd welcome suggesti...
        
         
           by 
           
                
                    
                        mjltls
                    
                
           
             
             
               New Member
             
           
           in
           Knowledge Management
           
           
              
               10-20-2020
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I created a workflow action to perform a reverse IP lookup using the link method GET.  
  I would like to perform thi...
        
         
           by 
           
                
                    
                        CarbonCriterium
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-27-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hi all,
  I have this json file like below:
   
  
   rootfield: [[-] {[-] field 1: A field 2: [[-] value1 value2 ] }...
        
         
           by 
           
                
                    
                        Cbr1sg
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-27-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        We are trying to implement a security solution on splunk for a client that has multiple data sources on multiple coun...
        
         
           by 
           
                
                    
                        severt
                    
                
           
             
             
               Loves-to-Learn
             
           
           in
           Knowledge Management
           
           
              
               10-26-2020
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Could you please help understand the DEBUG option for CacheManager to instigate eviction?
   
   
        
         
           by 
           
                
                    
                        rbal_splunk
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Knowledge Management
           
           
              
               10-22-2020
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        REST endpoint /services/admin/cacheman shows wrong cm:bucket.status of buckets.  
  In cluster, we have 80TB of local...
        
         
           by 
           
                
                    
                        rbal_splunk
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Knowledge Management
           
           
              
               01-21-2019
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        We are currently trying to set up a reliable solution for moving data from Splunk to HDFS location. This is not for a...
        
         
           by 
           
                
                    
                        manu_mukundan2
                    
                
           
             
             
               Engager
             
           
           in
           Knowledge Management
           
           
              
               02-14-2020
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        I have a CSV data in following format and I have written props and transforms to extract the fields. Somehow, the ""S...
        
         
           by 
           
                
                    
                        pgadhari
                    
                
           
             
             
               Builder
             
           
           in
           Knowledge Management
           
           
              
               10-13-2020
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am new to splunk administration. may someone help with a query that gives both reporting and non-reporting devices ...
        
         
           by 
           
                
                    
                        waJesu
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-14-2020
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/MultisiteSmartStore
  This document says: "This deployment...
        
         
           by 
           
                
                    
                        krisrini
                    
                
           
             
             
               Engager
             
           
           in
           Knowledge Management
           
           
              
               10-14-2020
             
           
         
        | 
		
		1
   | 
	  
	  0
	 | |||
| 
        Evening Splunk community,
  My organization practices Blue / Green data-centers and requires us to switch production ...
        
         
           by 
           
                
                    
                        TheColorBlack
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-12-2020
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi 
   @gcusello ,
  I want to check if in our environment splunk receives data/logs into azure firewall. if it doesn...
        
         
           by 
           
                
                    
                        rahul2gupta
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-11-2020
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        One user want to share his private Alert Knowledge object in app with everyone. However when he tired to share he get...
        
         
           by 
           
                
                    
                        msplunk33
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-09-2020
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello
  I have a field extraction set to extract headers from .txt files. I added the props and transforms to the ind...
        
         
           by 
           
                
                    
                        tkw03
                    
                
           
             
             
               Communicator
             
           
           in
           Knowledge Management
           
           
              
               10-07-2020
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello
  I have data that comes in as .txt format. Its dropped into a folder that's monitored by Splunk. There is a cu...
        
         
           by 
           
                
                    
                        tkw03
                    
                
           
             
             
               Communicator
             
           
           in
           Knowledge Management
           
           
              
               10-06-2020
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi,
  I have a clustered environment (Search Head Cluster with 1 Forwarder,  3 SHs, and 2 Indexers).
  I have deploye...
        
         
           by 
           
                
                    
                        mbachhav
                    
                
           
             
             
               Path Finder
             
           
           in
           Knowledge Management
           
           
              
               10-01-2020
             
           
         
        | 
		
		0
   | 
	  
	  2
	 |