Knowledge Management

Knowledge Management
Community Activity
wang
I'm in the process of setting up summary indexes. We haven't upgraded the forwarders to the new version that support...
by wang Path Finder in Knowledge Management 12-02-2010
0 1
0
1
john_loch
I need to update a summary index with Unique IP counts every 5 mins. What would be the optimal way to check for uniq...
by john_loch Explorer in Knowledge Management 11-29-2010
0 1
0
1
ives
I've created a scheduled report that runs and populates a summary index. From the admin account everything down to t...
by ives Explorer in Knowledge Management 11-24-2010
0 2
0
2
hoffmandirt
What is involved in creating custom modules? I'm looking at the existing modules and I'm not sure how all of the file...
by hoffmandirt Explorer in Knowledge Management 11-12-2010
5 11
5
11
ge90115b
Hi, I have a whole bunch of Bluecoat logs in which I will need to create Summary Indexes for them due to the log vo...
by ge90115b New Member in Knowledge Management 11-10-2010
0 3
0
3
andrewdotnich
I have roughly 30 saved reports that aggregate data over largish periods of time, and I've just discovered the summar...
by andrewdotnich Explorer in Knowledge Management 11-08-2010
0 1
0
1
caphrim007
I was wondering if it were possible to use $variable$ items in workflow actions that you have stored in a custom conf...
by caphrim007 Path Finder in Knowledge Management 11-08-2010
0 1
0
1
mattcg
What is the easiest way to transfer populated summary indexes from an old Splunk box over to a new instance? We have...
by mattcg Explorer in Knowledge Management 11-05-2010
0 1
0
1
Branden
I have a summary index that collects stdout from a script that we run on all our hosts (SplunkLightForwarder). The se...
by Branden Builder in Knowledge Management 10-29-2010
0 4
0
4
neg
Hi Apologies in advance if there already is a similar question/answer (I couldn't find it) Is there a way of settin...
by neg Engager in Knowledge Management 10-28-2010
1 2
1
2
Branden
I've created the following saved search into a Summary Index: index=access host="xyz" sourcetype="*access*" startmin...
by Branden Builder in Knowledge Management 10-27-2010
1 2
1
2
rjyetter
Here's my problem, we have mutiple regional event types based on CIDR IP ranges - within those regions we also have l...
by rjyetter Path Finder in Knowledge Management 10-19-2010
1 7
1
7
Oren
I've setup a summary index that works great. I usually use it like this: index=summary search_name="Z - Top Domain ...
by Oren Explorer in Knowledge Management 10-13-2010
0 1
0
1
sranga
Hi We have a saved-search that retrieves data from an existing summary index. It is of the following form: inde...
by sranga Path Finder in Knowledge Management 10-08-2010
0 5
0
5
msarro
Greetings everyone. I am working to try and aggregate .csv data from a number of sources. Initially its just a few de...
by msarro Builder in Knowledge Management 10-08-2010
0 4
0
4
Oren
I have a simple query: eventtype=request | stats sum(http_bytes) as transfer by http_domain | head 50 | sort -transf...
by Oren Explorer in Knowledge Management 09-29-2010
1 1
1
1
kkuminsky
Is there a way to add an additional field to every event for acknowledgment? I'm analyzing failed login attempts. As...
by kkuminsky Path Finder in Knowledge Management 09-24-2010
1 3
1
3
Caio_Santos
I don't have a clue anymore. My data hasn't been indexed anymore. I attempted all the three ways of Files & Directori...
by Caio_Santos Path Finder in Knowledge Management 09-22-2010
2 4
2
4
sranga
Hi We have a 4.0.10 instance deployed in production and are currently investigating 4.1.2. We are noticing some ch...
by sranga Path Finder in Knowledge Management 09-18-2010
0 5
0
5
oreoshake
I have some summary index data that is stored with sistats: index="_internal" group="per_host_thruput" source=*metri...
by oreoshake Communicator in Knowledge Management 09-16-2010
0 3
0
3
cpusneedlove
How Can I Put Summary Data In for An Old Data?
by cpusneedlove Engager in Knowledge Management 09-15-2010
1 2
1
2
ftk
How can I submit an Enhancement Request (ER) / Request for Enhancement (RFE) to Splunk>?
by ftk Motivator in Knowledge Management 09-15-2010
7 2
7
2
stephanbuys
We use summary indexing to improve search performance and to avoid unnecessary lookups and field extractions. It is s...
by stephanbuys Path Finder in Knowledge Management 09-10-2010
1 6
1
6
Justin_Grant
We're building an app which is intended to be deployed onto Windows, Unix, and Mac versions of Splunk. In our app's c...
by Justin_Grant Contributor in Knowledge Management 09-02-2010
3 5
3
5
srussellnpr
Team, I have a summary index that looks like this: <search string> | sistats count by UserAgent I also have a col...
by srussellnpr Explorer in Knowledge Management 08-31-2010
1 4
1
4
Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...