Knowledge Management

Knowledge Management
Community Activity
nik_splunk
Good Morning all, Anybody knows if exists a limit regarding the amount of eventtype I could set into splunk? I alrea...
by nik_splunk Path Finder in Knowledge Management 06-13-2016
1 3
1
3
Olli1919
Hi Fellow Splunkers, After having upgraded to 6.4.1 yesterday, I had a go with fill_summary_index.py again, and noti...
by Olli1919 Path Finder in Knowledge Management 06-10-2016
1 2
1
2
charlescywong
Is it possible to modify an indexed event? My company is using Splunk for detecting suspicious activities. One of the...
by charlescywong New Member in Knowledge Management 06-10-2016
0 1
0
1
saifuddin9122
Hi, I have came across this path /apps/splunk/var/lib/splunk/kvstore/mongo. I tried to understand why this is used, ...
by saifuddin9122 Path Finder in Knowledge Management 06-09-2016
0 5
0
5
HeinzWaescher
Hi, is it possible to use one field alias for multiple fields? For example I want to use field aliases to rename th...
by HeinzWaescher Motivator in Knowledge Management 06-07-2016
1 6
1
6
ra01
I've been asked to create my best case/wished-for Splunk event and our tech team will create it for me. I think I'm i...
by ra01 Path Finder in Knowledge Management 06-07-2016
0 2
0
2
flo_cognosec
Hi According to this page http://docs.splunk.com/Documentation/Splunk/6.0.3/Knowledge/Usesummaryindexing stuff tha...
by flo_cognosec Communicator in Knowledge Management 06-06-2016
0 9
0
9
aaron_harris
Is it possible to save data returned from a virtual index into another virtual index using the collect command in Spl...
by aaron_harris Engager in Knowledge Management 06-06-2016
0 1
0
1
Roopaul
Hi, I am getting logs from 2 servers which is exactly same unless there is some failure. We have to group the events ...
by Roopaul Explorer in Knowledge Management 06-03-2016
0 4
0
4
jkfierro
When you navigate to your Splunk webpage, you first come to a screen that checks for updates and then gives you the o...
by jkfierro Explorer in Knowledge Management 05-26-2016
3 6
3
6
ccsfdave
Greetings, I have read through the Knowledge Manager Manual on summary indexes, but am left with a question for my u...
by ccsfdave Builder in Knowledge Management 05-18-2016
0 2
0
2
renanprado96
I read the doc about the collect command. I understand how it works and what it does, but I wanted some practical exa...
by renanprado96 Path Finder in Knowledge Management 05-13-2016
0 3
0
3
jaredlaney
Is it possible to create a summary index with Hunk? I'm also curious as to the implementation so that we can build i...
by jaredlaney Contributor in Knowledge Management 05-12-2016
0 4
0
4
brent_weaver
Good morning. I have a file that looks like this: 2016-05-09 04:36:02,963[qtp789448364-261]|WARN|org.eclipse.jetty.i...
by brent_weaver Builder in Knowledge Management 05-09-2016
0 4
0
4
chrisnewmanuk
Im hoping someone can help me out here? Apologies if I break any community rules - first post here! Trying to creat...
by chrisnewmanuk New Member in Knowledge Management 05-08-2016
0 2
0
2
ctaf
Hello, I am currently following the "Creating Splunk Knowledge Objects" eLearning course but at one point, the teach...
by ctaf Contributor in Knowledge Management 05-06-2016
1 4
1
4
lguinn2
What is the difference between an “eventtype” and a “Saved Search”? While I know eventtypes can be entered right int...
by Legend in Knowledge Management 05-06-2016
10 4
10
4
daniel_augustyn
I am building a dashboard and I've been having an issue with presenting Statistics Tables on the dashboard while logg...
by daniel_augustyn Contributor in Knowledge Management 05-04-2016
0 15
0
15
danrb1978
I am having trouble setting the value of a KV Store collection field of type time. Does anyone know the best way to d...
by danrb1978 New Member in Knowledge Management 04-28-2016
0 1
0
1
vryzhko
Hello, We have overflow /opt/splunk/var/spool/splunk directory. It contains stash.new files from 2014 year to today....
by vryzhko Path Finder in Knowledge Management 04-27-2016
0 1
0
1
mcbradford
My workflow actions do not show up in the pulldown next to the event within dashboard? What do I need to change to g...
by mcbradford Contributor in Knowledge Management 04-27-2016
1 2
1
2
dcrooks_us
I want to load the data every 2 weeks, but clean out the old data before running the summary index again?
by dcrooks_us Explorer in Knowledge Management 04-25-2016
0 1
0
1
gjohnson
I have been trying to wipe out an eval instance of splunk to start again, but I keep getting errors. I then upgraded ...
by gjohnson New Member in Knowledge Management 04-21-2016
0 3
0
3
splunker9999
HI, We are looking to enhance our real time dashboard performance, in away of that we have scheduled real time searc...
by splunker9999 Path Finder in Knowledge Management 04-21-2016
0 2
0
2
lohit
Hi all , I have configured Splunk buckets to archive indexed logs after 1 month. I will store the archived logs in t...
by lohit Path Finder in Knowledge Management 04-21-2016
0 2
0
2
Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...