Thread Info | |||||
---|---|---|---|---|---|
I am trying to use transactions to better summarize what is going on in sessions.
sourcetype="blah" response="200"...
by
jcbrendsel
Path Finder
in
Knowledge Management
03-03-2011
|
1
|
1
| |||
Is there a way to increase the number of maximum threads that the backfill script will use to a value higher than 16?
by
approachct
Path Finder
in
Knowledge Management
03-01-2011
|
0
|
1
| |||
If I have a summary indexing search like this:
.... | sistats median(x)
I get a list of values and counts in a...
by
Lowell
Super Champion
in
Knowledge Management
11-08-2010
|
0
|
1
| |||
I have a search that produces a table. I am piping that search to: | collect index=vulnerabilities
When the searc...
by
jambajuice
Communicator
in
Knowledge Management
02-04-2011
|
3
|
2
| |||
Hi,
Let's suppose that my free splunk server will receive more that 500MB/day of syslog messages (through the TCP ...
by
cos2mih
New Member
in
Knowledge Management
01-21-2011
|
0
|
1
| |||
Hi,
The TCP data input is working on the free splunk 4.1.6 version? (meaning after the first 60 days)
Thanks,
...
by
cos2mih
New Member
in
Knowledge Management
01-21-2011
|
0
|
1
| |||
I have a dashboard that has a pull-down menu with a list of our hosts. By selecting a host, one can get a snapshot of...
by
Branden
Builder
in
Knowledge Management
10-26-2010
|
2
|
3
| |||
Similarly, I want to make a group/eventtype of events from a certain sourcetype where the LOGINID values are all 12 c...
by
gpburgett
Splunk Employee
in
Knowledge Management
12-27-2010
|
0
|
1
| |||
I want to make a group/eventtype with events from a certain sourcetype where LOGINID="I*" and 'I' is capital only. Th...
by
gpburgett
Splunk Employee
in
Knowledge Management
12-27-2010
|
0
|
1
| |||
Is there a way to keep more than 10.000 events on a summary index for a schedule search ?
I would like to store ev...
by
ruisantos
Path Finder
in
Knowledge Management
12-17-2010
|
0
|
1
| |||
It appears that my regularly scheduled summary searches do not run while I'm running the backfill_summary_index scrip...
by
the_wolverine
Champion
in
Knowledge Management
12-14-2010
|
0
|
1
| |||
I would like a list of all eventtypes associated to an IP on a single table. Is there a way to perform this?
I wou...
by
ruisantos
Path Finder
in
Knowledge Management
12-10-2010
|
0
|
1
| |||
In the latest versions of Splunk, summary indexing does not deduct from the licensed indexing capacity. How does Splu...
by
hulahoop
Splunk Employee
in
Knowledge Management
10-15-2010
|
4
|
4
| |||
Hi,
I have a workflow action that creates a link to an external site based on information in a particular field an...
by
gnovak
Builder
in
Knowledge Management
12-03-2010
|
2
|
4
| |||
I'm in the process of setting up summary indexes. We haven't upgraded the forwarders to the new version that supports...
by
wang
Path Finder
in
Knowledge Management
12-02-2010
|
0
|
1
| |||
I need to update a summary index with Unique IP counts every 5 mins.
What would be the optimal way to check for un...
by
john_loch
Explorer
in
Knowledge Management
11-27-2010
|
0
|
1
| |||
I've created a scheduled report that runs and populates a summary index.
From the admin account everything down to...
by
ives
Explorer
in
Knowledge Management
11-24-2010
|
0
|
2
| |||
What is involved in creating custom modules? I'm looking at the existing modules and I'm not sure how all of the file...
by
hoffmandirt
Explorer
in
Knowledge Management
09-10-2010
|
5
|
11
| |||
Hi,
I have a whole bunch of Bluecoat logs in which I will need to create Summary Indexes for them due to the log ...
by
ge90115b
New Member
in
Knowledge Management
11-09-2010
|
0
|
3
| |||
I have roughly 30 saved reports that aggregate data over largish periods of time, and I've just discovered the summar...
by
andrewdotnich
Explorer
in
Knowledge Management
11-08-2010
|
0
|
1
| |||
I was wondering if it were possible to use $variable$ items in workflow actions that you have stored in a custom conf...
by
caphrim007
Path Finder
in
Knowledge Management
10-31-2010
|
0
|
1
| |||
What is the easiest way to transfer populated summary indexes from an old Splunk box over to a new instance?
We ha...
by
mattcg
Explorer
in
Knowledge Management
11-05-2010
|
0
|
1
| |||
I have a summary index that collects stdout from a script that we run on all our hosts (SplunkLightForwarder). The se...
by
Branden
Builder
in
Knowledge Management
10-28-2010
|
0
|
4
| |||
Hi
Apologies in advance if there already is a similar question/answer (I couldn't find it)
Is there a way of se...
by
neg
Engager
in
Knowledge Management
10-28-2010
|
1
|
2
| |||
I've created the following saved search into a Summary Index:
index=access host="xyz" sourcetype="*access*" startm...
by
Branden
Builder
in
Knowledge Management
10-27-2010
|
1
|
2
|