| Thread Info | |||||
|---|---|---|---|---|---|
|
What is involved in creating custom modules? I'm looking at the existing modules and I'm not sure how all of the file...
by
hoffmandirt
Explorer
in
Knowledge Management
09-10-2010
|
5
|
11
| |||
|
Hi,
I have a whole bunch of Bluecoat logs in which I will need to create Summary Indexes for them due to the log ...
by
ge90115b
New Member
in
Knowledge Management
11-09-2010
|
0
|
3
| |||
|
I have roughly 30 saved reports that aggregate data over largish periods of time, and I've just discovered the summar...
by
andrewdotnich
Explorer
in
Knowledge Management
11-08-2010
|
0
|
1
| |||
|
I was wondering if it were possible to use $variable$ items in workflow actions that you have stored in a custom conf...
by
caphrim007
Path Finder
in
Knowledge Management
10-31-2010
|
0
|
1
| |||
|
What is the easiest way to transfer populated summary indexes from an old Splunk box over to a new instance?
We ha...
by
mattcg
Explorer
in
Knowledge Management
11-05-2010
|
0
|
1
| |||
|
I have a summary index that collects stdout from a script that we run on all our hosts (SplunkLightForwarder). The se...
by
Branden
Builder
in
Knowledge Management
10-28-2010
|
0
|
4
| |||
|
Hi
Apologies in advance if there already is a similar question/answer (I couldn't find it)
Is there a way of se...
by
neg
Engager
in
Knowledge Management
10-28-2010
|
1
|
2
| |||
|
I've created the following saved search into a Summary Index:
index=access host="xyz" sourcetype="*access*" startm...
by
Branden
Builder
in
Knowledge Management
10-27-2010
|
1
|
2
| |||
|
Here's my problem, we have mutiple regional event types based on CIDR IP ranges - within those regions we also have l...
by
rjyetter
Path Finder
in
Knowledge Management
10-18-2010
|
1
|
7
| |||
|
I've setup a summary index that works great. I usually use it like this:
index=summary search_name="Z - Top Domain...
by
Oren
Explorer
in
Knowledge Management
10-12-2010
|
0
|
1
| |||
|
Hi
We have a saved-search that retrieves data from an existing summary index. It is of the following form:
in...
by
sranga
Path Finder
in
Knowledge Management
10-06-2010
|
0
|
5
| |||
|
Greetings everyone. I am working to try and aggregate .csv data from a number of sources. Initially its just a few de...
by
msarro
Builder
in
Knowledge Management
09-30-2010
|
0
|
4
| |||
|
I have a simple query:
eventtype=request | stats sum(http_bytes) as transfer by http_domain | head 50 | sort -tran...
by
Oren
Explorer
in
Knowledge Management
09-28-2010
|
1
|
1
| |||
|
Is there a way to add an additional field to every event for acknowledgment?
I'm analyzing failed login attempts. ...
by
kkuminsky
Path Finder
in
Knowledge Management
05-17-2010
|
1
|
3
| |||
|
I don't have a clue anymore. My data hasn't been indexed anymore. I attempted all the three ways of Files & Directori...
by
Caio_Santos
Path Finder
in
Knowledge Management
09-21-2010
|
2
|
4
| |||
|
Hi
We have a 4.0.10 instance deployed in production and are currently investigating 4.1.2. We are noticing some c...
by
sranga
Path Finder
in
Knowledge Management
09-03-2010
|
0
|
5
| |||
|
I have some summary index data that is stored with sistats:
index="_internal" group="per_host_thruput" source=*met...
by
oreoshake
Communicator
in
Knowledge Management
07-01-2010
|
0
|
3
| |||
|
How Can I Put Summary Data In for An Old Data?
by
cpusneedlove
Engager
in
Knowledge Management
09-15-2010
|
1
|
2
| |||
|
How can I submit an Enhancement Request (ER) / Request for Enhancement (RFE) to Splunk>?
by
ftk
Motivator
in
Knowledge Management
07-20-2010
|
7
|
2
| |||
|
We use summary indexing to improve search performance and to avoid unnecessary lookups and field extractions. It is s...
by
stephanbuys
Path Finder
in
Knowledge Management
09-07-2010
|
1
|
6
| |||
|
We're building an app which is intended to be deployed onto Windows, Unix, and Mac versions of Splunk. In our app's c...
by
Justin_Grant
Contributor
in
Knowledge Management
08-18-2010
|
3
|
5
| |||
|
Team,
I have a summary index that looks like this:
<search string> | sistats count by UserAgent
I also have...
by
srussellnpr
Explorer
in
Knowledge Management
08-30-2010
|
1
|
4
| |||
|
Hi - I have a need of running a query to count unique values from a large set of data (>1 million) OVER A 30-Day PERI...
by
clincg
Path Finder
in
Knowledge Management
08-21-2010
|
1
|
6
| |||
|
Hi
I have some summary-indexed data over the last couple of months. I was wondering if its possible to add anothe...
by
sranga
Path Finder
in
Knowledge Management
08-23-2010
|
0
|
1
| |||
|
Can I customize the icons displayed when using iconify? I think it would be cool if I could map specific icon to an e...
by
jamesdon
Path Finder
in
Knowledge Management
08-20-2010
|
0
|
1
|