Knowledge Management

Knowledge Management
Community Activity
aecruzp
Good afternoon     By topics of analysis it is required to know when a sourcetype was created, I know that the confi...
by aecruzp Path Finder in Knowledge Management 01-23-2018
0 6
0
6
karthi2809
How to find count of empty values in splunk ? raw events: threadId = 2695;StartTime=2017.11.12.16.50.36.036;EndTime...
by karthi2809 Builder in Knowledge Management 01-22-2018
0 4
0
4
dsmc_adv
Hi all, I'm using icinga to monitor my servers and I would like to use the mongo plugin to monitor the kv store. The...
by dsmc_adv Path Finder in Knowledge Management 01-19-2018
3 1
3
1
dharveynswccd
In my environment I have an intermediate universal forwarder (syslog collector) which collects data from multiple sou...
by dharveynswccd Path Finder in Knowledge Management 01-19-2018
0 2
0
2
bwouters
Hi all I managed to generate a log file which I would need to use to display certain graphs. This logfile only incre...
by bwouters Path Finder in Knowledge Management 01-19-2018
0 9
0
9
tac24
Before adding results into summary index, I can mvexpand a multi-value field as expected; for checking mvexpand searc...
by tac24 New Member in Knowledge Management 01-19-2018
0 2
0
2
ddrillic
Our "best" internal client would like to start with summary indexes. Is there a good document out there for them?
by ddrillic Ultra Champion in Knowledge Management 01-18-2018
1 2
1
2
PatrickButterly
Im trying to make transaction more usable for the end user ans the summary index seems to be the best option availab...
by PatrickButterly Explorer in Knowledge Management 01-18-2018
0 3
0
3
organus
I'm trying to perform a preliminary connection to my KV Store collection through the API using the server/introspecti...
by organus Explorer in Knowledge Management 01-17-2018
0 2
0
2
mgagnaire
Hello, I am having a bit of an issue with the collect command. I'm trying to index an ldap search so i can use the d...
by mgagnaire Engager in Knowledge Management 01-16-2018
0 2
0
2
responsys_cm
I have a customer that is evaluating Splunk in a cloud provider. They are trying to evaluate the performance of bare...
by responsys_cm Builder in Knowledge Management 01-12-2018
0 0
0
0
djfang
Hi, I want to confirm where the KVStore reside on the Splunk Architecture stack. I know that there's a related Mongo...
by djfang Explorer in Knowledge Management 01-12-2018
0 5
0
5
kamlesh_vaghela
Hello Splunkers, My app has a static lookup my_lookup.csv with static data. This is my sample csv data which cause...
by SplunkTrust SplunkTrust in Knowledge Management 01-12-2018
2 3
2
3
pfabrizi
Can I use IF\ELSE in a PROPS.conf? What does the syntax look like. basically we want to do a if this eventid then do...
by pfabrizi Path Finder in Knowledge Management 01-12-2018
0 1
0
1
sadeezy
I want to create WindowsSystemFile_lookup in order to detect fake windows processes
by sadeezy New Member in Knowledge Management 01-09-2018
0 0
0
0
simpkins1958
I am trying to optimize searches that have large time spans (6+ months) with 10,000,000's of events. Which is more pe...
by simpkins1958 Contributor in Knowledge Management 01-04-2018
0 2
0
2
simpkins1958
Trying to understand the difference between Data Models and Datasets and when to use one vs. the other?
by simpkins1958 Contributor in Knowledge Management 01-04-2018
0 2
0
2
isachristophe
Hello Topic: I would like to create a new index with some extract fields which are not in my initial index Descr...
by isachristophe New Member in Knowledge Management 01-03-2018
0 5
0
5
MatMeredith
Having downgraded to Splunk Free, I can no longer see options when scheduling a search to configure summary indexing....
by MatMeredith Path Finder in Knowledge Management 12-29-2017
0 2
0
2
forbushbl
Is it possible to add the search ID for the currently running search to the search results? I have a report that po...
by forbushbl Engager in Knowledge Management 12-28-2017
0 2
0
2
joeldavideng
I created a data model called "Process_Creation" with a calculated field that represents the length of a specific str...
by joeldavideng Path Finder in Knowledge Management 12-27-2017
0 6
0
6
mdey
I have a data model where I want to enrich "index" field. I m very new to datamodel section and reading docs to gain ...
by mdey New Member in Knowledge Management 12-23-2017
0 1
0
1
mikclrk
I've got a bunch of data records arriving from a remote analytic system. They all have timestamps and a unique key. ...
by mikclrk Explorer in Knowledge Management 12-22-2017
0 1
0
1
proylea
I want to extract certain events into the same index with a different sourcetype, this is simple, but I would like to...
by proylea Contributor in Knowledge Management 12-22-2017
0 2
0
2
hmrabet2
Is there a way up populate contents of a lookupfile such such as srcip and destip obtained from another source curre...
by hmrabet2 Observer in Knowledge Management 12-21-2017
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...