| What is the recommended way to export/archive a large amount of historical data for retention or offline storage? I ... 0 1 | 0 | 1 | ||
| I'm looking for best practice when setting up a savedsearch email alerting when the alerting has the following requir... 2 6 | 2 | 6 | ||
| I have a few scheduled searches that become 'unscheduled' randomly. I don't notice this until I miss a service outag... 1 1 | 1 | 1 | ||
| Hi I have a saved-search (my_search) that is configured to run every 30 minutes. It gathers aggregate data from th... 1 4 | 1 | 4 | ||
| The docs reference the option of passing macro values into a saved search. How does that work exactly? I understand... 0 5 | 0 | 5 | ||
| I am willfully using the free version, and for now don't have the option to upgrade to the paid enterprise version. ... 0 3 | 0 | 3 | ||
| I am trying to create a macro that would take as it's input the result of an eval earlier in the search string, for e... by stephanbuys Path Finder in Reporting 05-27-2010 0 4 | 0 | 4 | ||
| Hello, I have a central splunk server, a splunk server specifically for the PDF Server application, and my mail serv... 3 3 | 3 | 3 | ||
| I am attempting to setup Splunk on a VM that will become a VM template. I have run sysprep and made it a template. ... 1 3 | 1 | 3 | ||
| I have a situation where a server is crashing as the result of a specific user accessing some specific web site. Don'... 3 4 | 3 | 4 | ||
| (Note: I'm sure this has already been asked, I saw it posted once, but didn't need it, now that I need it, I can't f... 2 2 | 2 | 2 | ||
| Hi folks, I'm creating a knowledge pack add-on that has no ui elements, so in app.conf I have: [ui] is_visible =... 3 1 | 3 | 1 | ||
| When running reports there are times when a field of OTHER is returned. What defines a result to be returned to OTHE... 2 2 | 2 | 2 | ||
| We have a report that provides a nightly email alert with inline results for every successful backup event. Ever sin... 1 3 | 1 | 3 | ||
| I've got some performance data and I want to be alerted when the avg(total_requests) split by uri rises or drops by 1... 1 1 | 1 | 1 | ||
| I got a failed to choose a font error message pretaining to my PDF server, how do I correct? 2010-05-04 14:51:12,871... 2 2 | 2 | 2 | ||
| Alert was triggered because of: 'Saved Search [fortyfor-test]: number of events(2)' Apr 26 20:59:15 dist puppetd[153... 1 4 | 1 | 4 | ||
| Every time I try to run a report on a search, I get 0 records and the following error in the chart editor: Field '_t... 0 1 | 0 | 1 | ||
| I get a message that says Search scheduler is disabled in Splunk's Free version. Scheduled searches that populate th... 1 5 | 1 | 5 | ||
| Anybody out there had experience trying to correlate events with Splunk. A scenario would be like this: (Source : A... 0 3 | 0 | 3 | ||
| Has anyone thought through the pros/cons of setting up an external (independent) PDF server vs running the PDF server... 0 2 | 0 | 2 | ||
| In the UI I navigate to Jobs and see entries identified as Owner "splunk-system-user" why is that? 2 2 | 2 | 2 | ||
| INFO SavedSplunker - Found 2 scheduled saved searches INFO SavedSplunker - About to run saved search: 'admin;search... by the_wolverine Champion in Reporting 04-29-2010 0 1 | 0 | 1 | ||
| how can I change the fonts on an ubuntu server so they are not really ugly? Are there other packages I can install? 1 2 | 1 | 2 | ||
| Error message from users python.log: 2010-04-23 16:30:12,102 INFO xvfb:115 - Starting X Server: ['/usr/bin/Xvfb',... 2 1 | 2 | 1 |
Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.