Knowledge Management

Knowledge Management
Community Activity
gnovak
Hi, I have a workflow action that creates a link to an external site based on information in a particular field and ...
by gnovak Builder in Knowledge Management 12-06-2010
2 4
2
4
wang
I'm in the process of setting up summary indexes. We haven't upgraded the forwarders to the new version that support...
by wang Path Finder in Knowledge Management 12-02-2010
0 1
0
1
john_loch
I need to update a summary index with Unique IP counts every 5 mins. What would be the optimal way to check for uniq...
by john_loch Explorer in Knowledge Management 11-29-2010
0 1
0
1
ives
I've created a scheduled report that runs and populates a summary index. From the admin account everything down to t...
by ives Explorer in Knowledge Management 11-24-2010
0 2
0
2
hoffmandirt
What is involved in creating custom modules? I'm looking at the existing modules and I'm not sure how all of the file...
by hoffmandirt Explorer in Knowledge Management 11-12-2010
5 11
5
11
ge90115b
Hi, I have a whole bunch of Bluecoat logs in which I will need to create Summary Indexes for them due to the log vo...
by ge90115b New Member in Knowledge Management 11-10-2010
0 3
0
3
andrewdotnich
I have roughly 30 saved reports that aggregate data over largish periods of time, and I've just discovered the summar...
by andrewdotnich Explorer in Knowledge Management 11-08-2010
0 1
0
1
caphrim007
I was wondering if it were possible to use $variable$ items in workflow actions that you have stored in a custom conf...
by caphrim007 Path Finder in Knowledge Management 11-08-2010
0 1
0
1
mattcg
What is the easiest way to transfer populated summary indexes from an old Splunk box over to a new instance? We have...
by mattcg Explorer in Knowledge Management 11-05-2010
0 1
0
1
Branden
I have a summary index that collects stdout from a script that we run on all our hosts (SplunkLightForwarder). The se...
by Branden Builder in Knowledge Management 10-29-2010
0 4
0
4
neg
Hi Apologies in advance if there already is a similar question/answer (I couldn't find it) Is there a way of settin...
by neg Engager in Knowledge Management 10-28-2010
1 2
1
2
Branden
I've created the following saved search into a Summary Index: index=access host="xyz" sourcetype="*access*" startmin...
by Branden Builder in Knowledge Management 10-27-2010
1 2
1
2
rjyetter
Here's my problem, we have mutiple regional event types based on CIDR IP ranges - within those regions we also have l...
by rjyetter Path Finder in Knowledge Management 10-19-2010
1 7
1
7
Oren
I've setup a summary index that works great. I usually use it like this: index=summary search_name="Z - Top Domain ...
by Oren Explorer in Knowledge Management 10-13-2010
0 1
0
1
sranga
Hi We have a saved-search that retrieves data from an existing summary index. It is of the following form: inde...
by sranga Path Finder in Knowledge Management 10-08-2010
0 5
0
5
msarro
Greetings everyone. I am working to try and aggregate .csv data from a number of sources. Initially its just a few de...
by msarro Builder in Knowledge Management 10-08-2010
0 4
0
4
Oren
I have a simple query: eventtype=request | stats sum(http_bytes) as transfer by http_domain | head 50 | sort -transf...
by Oren Explorer in Knowledge Management 09-29-2010
1 1
1
1
kkuminsky
Is there a way to add an additional field to every event for acknowledgment? I'm analyzing failed login attempts. As...
by kkuminsky Path Finder in Knowledge Management 09-24-2010
1 3
1
3
Caio_Santos
I don't have a clue anymore. My data hasn't been indexed anymore. I attempted all the three ways of Files & Directori...
by Caio_Santos Path Finder in Knowledge Management 09-22-2010
2 4
2
4
sranga
Hi We have a 4.0.10 instance deployed in production and are currently investigating 4.1.2. We are noticing some ch...
by sranga Path Finder in Knowledge Management 09-18-2010
0 5
0
5
oreoshake
I have some summary index data that is stored with sistats: index="_internal" group="per_host_thruput" source=*metri...
by oreoshake Communicator in Knowledge Management 09-16-2010
0 3
0
3
cpusneedlove
How Can I Put Summary Data In for An Old Data?
by cpusneedlove Engager in Knowledge Management 09-15-2010
1 2
1
2
ftk
How can I submit an Enhancement Request (ER) / Request for Enhancement (RFE) to Splunk>?
by ftk Motivator in Knowledge Management 09-15-2010
7 2
7
2
stephanbuys
We use summary indexing to improve search performance and to avoid unnecessary lookups and field extractions. It is s...
by stephanbuys Path Finder in Knowledge Management 09-10-2010
1 6
1
6
Justin_Grant
We're building an app which is intended to be deployed onto Windows, Unix, and Mac versions of Splunk. In our app's c...
by Justin_Grant Contributor in Knowledge Management 09-02-2010
3 5
3
5
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...