| Thread Info | |||||
|---|---|---|---|---|---|
|
We have multiple indexes to separate the access / role limit due to data privacy/security (like index1, index2, index...
by
dhavamanis
Builder
in
Knowledge Management
08-05-2014
|
2
|
2
| |||
|
Splunk's default search screen features a convenient "Data Summary" button which users can click to show a summary fo...
by
pscalise
New Member
in
Knowledge Management
07-31-2014
|
0
|
2
| |||
|
Forgive me if this is a naive question.
We seem to have multiple tags that have the same name.
They contain dif...
by
raoul
Path Finder
in
Knowledge Management
02-10-2011
|
0
|
3
| |||
|
If I run the search:
tag=S100 | stats count
it returns the correct results. So the tag can be searched, but the...
by
mgaraventa_splu
Splunk Employee
in
Knowledge Management
07-25-2014
|
3
|
1
| |||
|
So.. With a lot of reports that are dependent on lookup tables.. Dashboards dependent on saved reports, and so on, it...
by
dstaulcu
Builder
in
Knowledge Management
03-13-2014
|
3
|
1
| |||
|
I am getting the following when using the following search: index=juniperfirewall tag=* |search tag=ids
The tag=* ...
by
aelliott
Motivator
in
Knowledge Management
07-10-2014
|
1
|
1
| |||
|
Here is the search (name = CPU-Summery-WMI):
sourcetype="WMI:CPUTime" earliest=-5m@m | stats avg(PercentProcessor...
by
ww9rivers
Contributor
in
Knowledge Management
10-09-2012
|
0
|
3
| |||
|
For some reason I did get a hang or something while I added a folder of FTP log to the Splunk server.
This made th...
by
lakromani
Builder
in
Knowledge Management
07-04-2014
|
0
|
3
| |||
|
Hi I used macro and its return some results, I want to run dbquery to passing parameter using the macro results How...
by
senthilgoa
Engager
in
Knowledge Management
04-08-2014
|
0
|
3
| |||
|
Each time I try to create a new or save and existing database lookup I get the following error:
{"msg": "Encounter...
by
smorse11
Engager
in
Knowledge Management
06-25-2014
|
0
|
2
| |||
|
I'm seeing searches running with user 'nobody' what quota will be applied? I can't seem to apply any role to nobody?
by
abonuccelli_spl
Splunk Employee
in
Knowledge Management
06-26-2014
|
5
|
1
| |||
|
Hi
From the complex log, I have extracted all the fields, which is about 60+ fields. I want to save these fields i...
by
splunk_worker
Path Finder
in
Knowledge Management
06-22-2014
|
0
|
3
| |||
|
I have 28 saved searches and each one of the searches is executed in 5 mins gaps. Even though I have dispersed the sc...
by
lahariveerlapat
Explorer
in
Knowledge Management
06-11-2014
|
0
|
3
| |||
|
Do we have an expiration on summary indexed data, if yes how long we can keep that data and where can we find this de...
by
vradhakrishnan
Engager
in
Knowledge Management
06-18-2014
|
1
|
1
| |||
|
Normally, the time resolution adjusts itself, seemingly trying to keep the number of bars shown below some "reasonabl...
by
letharion
Engager
in
Knowledge Management
06-18-2014
|
0
|
1
| |||
|
WE have two small international sites. What's the best practice for getting that data into our main SPlunk here in th...
by
earixson
Engager
in
Knowledge Management
06-09-2014
|
1
|
1
| |||
|
I have quite a few hot db and warm in one of my index - sharp. Can I delete the files under the rawdata directory lik...
by
romitsn
New Member
in
Knowledge Management
06-13-2014
|
0
|
2
| |||
|
Where is the path of the file created when creating a bulletin message?
Manager->User interface->Bulletin Messages
by
ben_leung
Builder
in
Knowledge Management
06-10-2014
|
0
|
2
| |||
|
Hello this search query is very neat and I want to know how I can compare it with last 4 weeks based on the day of we...
by
tlow
Explorer
in
Knowledge Management
06-10-2014
|
0
|
1
| |||
|
Hello!
I've got a distributed Splunk setup where the indexers and search heads live on separate hosts. (The indexe...
by
emiller42
Motivator
in
Knowledge Management
04-07-2014
|
0
|
2
| |||
|
We occasionally receive hundreds of thousands of events (sometimes millions) from one or two hosts and if not acted q...
by
ananth_nag_kavu
Explorer
in
Knowledge Management
05-27-2014
|
0
|
2
| |||
|
props.confに以下の設定をして、XMLを取り込んでいます。 KV_MODE = xml pulldown_type = 1 NO_BINARY_CHECK = 1 SHOULD_LINEMERGE = true このと...
by
takoyakiman
New Member
in
Knowledge Management
05-14-2014
|
0
|
1
| |||
|
I have two saved searches, saved them as macros.
1: [search sourcetype="brem" sanl31 eham Successfully completed (...
by
rijk
Explorer
in
Knowledge Management
05-20-2014
|
0
|
2
| |||
|
I want to extend the Event Options Menu which is located beside the result records. The idea is to add a link contain...
by
tpflicke
Path Finder
in
Knowledge Management
05-07-2014
|
0
|
2
| |||
|
Anyone here got some recommendations for forwarding Windows event logs to Splunk without installing the Splunk forwar...
by
vqd361
Path Finder
in
Knowledge Management
05-18-2014
|
0
|
1
|