Reporting

Reporting
Community Activity
melonman
Hi I am using Hunk and configured report acceleration saved searches. report acceleration automatically checks wher...
by melonman Motivator in Reporting 11-06-2014
1 1
1
1
rfds
Hi, I've got some saved searches scheduled to output CSV files using the outputcsv command which works well. From th...
by rfds Path Finder in Reporting 11-03-2014
3 2
3
2
sat94541
When we first stood up some of our systems the events ended up in the main index instead of the windows, firewall and...
by sat94541 Communicator in Reporting 10-31-2014
1 2
1
2
danielrusso1
I'm trying to stagger my scheduled searches in order to spread out resource utilization (20% of searches on the hour,...
by danielrusso1 Path Finder in Reporting 10-31-2014
1 10
1
10
vragosta
OUTPUTCSV is currently appending search results surrounded in quotes, like "1.1.1.1." Is it possible for OUTPUTCSV t...
by vragosta Path Finder in Reporting 10-30-2014
1 3
1
3
a212830
Hi, I'm trying to schedule a report with the following cron config: 2-59/5 * * * * When I try to save this, the "E...
by a212830 Champion in Reporting 10-29-2014
0 6
0
6
bmorgan
The only place I have found the job id is embedded in the link on the jobs page. Is there a way to make the job id a...
by bmorgan Explorer in Reporting 10-29-2014
1 4
1
4
sjanwity
I have some data which is coming from the Splunk DB Connect app, which I need to present onto a report. I want this r...
by sjanwity Communicator in Reporting 10-22-2014
0 33
0
33
anthony_copus
Hi, I've currently got a few accelerated data models set up, however it seems that the summary data is always writte...
by anthony_copus Explorer in Reporting 10-20-2014
4 8
4
8
BobM
I have a saved search that takes hours to run over all time. I would like to be able to do a subsearch of that data o...
by BobM Builder in Reporting 10-16-2014
2 1
2
1
kallu
There has been many questions/requests for better (=configurable templates) email alerts but has anyone actually publ...
by kallu Communicator in Reporting 10-16-2014
3 1
3
1
anuradhaschauha
Hi, I have the following query: index=src | stats count by message which gives me results as message count ...
by anuradhaschauha New Member in Reporting 10-14-2014
0 2
0
2
arber
Hello, when trying to schedule a pdf for a Search inside WSOC app we get a pdf error like: An error occurred while g...
by arber Communicator in Reporting 10-09-2014
1 1
1
1
anirudhk
Hi, I have Splunk DB connect v1.1.1 installed over Splunk 6.1 and The Db connect launcher keeps reloading every 5 se...
by anirudhk Explorer in Reporting 10-08-2014
3 12
3
12
dlovett
2014-10-06 13:26:37,617 Eastern Daylight Time ERROR pdfgen_endpoint:237 - Exception raised while trying to render "M ...
by dlovett Path Finder in Reporting 10-06-2014
1 1
1
1
Jason
I see an entry in ps, or the internal logs, that has an instance of a scheduled search in it. It has this "RMD5" - ho...
by Jason Motivator in Reporting 10-02-2014
1 1
1
1
SaiKalyani
Hi All Suppose i have different uri_paths for single application X ex : /abc/xyz/, 123/abc/, xyz/wer/* i want to s...
by SaiKalyani Engager in Reporting 09-30-2014
0 1
0
1
mikelanghorst
I have a view I've created, and scheduled for PDF delivery. Though when the admin gets the report he must then go to...
by mikelanghorst Motivator in Reporting 09-29-2014
6 3
6
3
tborf
Hi I'm new to splunk. I have an web access log that I want to pull usage information from. Now the URLs are restful w...
by tborf Engager in Reporting 09-26-2014
1 1
1
1
bbthesplunk
My company has a distributed environment with 2 Search Heads and 2 Indexers. Where does REPORT in props.conf and REG...
by bbthesplunk Explorer in Reporting 09-26-2014
1 3
1
3
essklau
Hi. I'm trying to use acceleration for three reports. The Report Acceleration Summary reports the summary status of...
by essklau Path Finder in Reporting 09-25-2014
2 6
2
6
ben_leung
In http://docs.splunk.com/Documentation/Splunk/6.0.5/Knowledge/Manageacceleratedsearchsummaries It says: "your permi...
by ben_leung Builder in Reporting 09-24-2014
2 3
2
3
jamesvz84
How far back in time will datamodel data be kept? I have a datamodel with a large quantity of data and I am wondering...
by jamesvz84 Communicator in Reporting 09-23-2014
0 1
0
1
louieb3
We authenticate to AD through LDAP and have run into the known issue about Splunk not being able to pull email addres...
by louieb3 Path Finder in Reporting 09-22-2014
1 17
1
17
diegosainz
I am looking to build an alert that is fired on the first and last business day of the month. Do you know of a way t...
by diegosainz Path Finder in Reporting 09-22-2014
1 1
1
1