Splunk Dev

Splunk Dev
Community Activity
mw
I'm working on a custom search command which will take the results of a search and create an XML output file. As a v...
by mw Splunk Employee Splunk Employee in Splunk Dev 04-11-2011
0 1
0
1
Charlie
I'd like to understand how external-cmd transforms are being called - for example: Are the results cached, i.e., are...
by Charlie Explorer in Splunk Dev 03-29-2011
1 3
1
3
myli12
Can you group events within a transaction? Suppose that there are two types of events: "down" and "link" and someti...
by myli12 Path Finder in Splunk Dev 03-17-2011
0 1
0
1
mohitvohra109
Hi all, I'm looking to evaluate Splunk for log management w.r.t PCI DSS compliance and have a couple of questions re...
by mohitvohra109 Explorer in Splunk Dev 03-16-2011
1 5
1
5
clarjon
Hi there, How do I add a monitor to watch the system load from a linux machine, so I can send an alert if the load ge...
by clarjon New Member in Splunk Dev 03-08-2011
0 1
0
1
ultra
Hi, I have created an scripted lookup (app) that looks up data in MongoDB and returns some results. I have used an ...
by ultra Explorer in Splunk Dev 02-03-2011
3 1
3
1
msarro
Is it possible to do something like this? It would make my life a whole lot easier if this can be done, or at least s...
by msarro Builder in Splunk Dev 02-01-2011
1 4
1
4
silvermail
Hi everybody, I have a piece of log that goes like the below as a single event. Basically these are the statistics ...
by silvermail Path Finder in Splunk Dev 01-07-2011
0 1
0
1
svsa
# uname -a Linux localhost 2.6.18-028stab064.7 #1 SMP Wed Aug 26 13:11:07 MSD 2009 i686 i686 i386 GNU/Linux # python...
by svsa New Member in Splunk Dev 12-31-2010
0 3
0
3
skippylou
Couldn't find exact clarification on a couple things regarding reducing an index size but assuming how I think it wil...
by skippylou Communicator in Splunk Dev 12-24-2010
1 2
1
2
msarro
Hey everyone. I am trying to create a dashboard; one of the primary items we're looking to create is a composite scor...
by msarro Builder in Splunk Dev 12-21-2010
0 2
0
2
John_Mark
If you've been looking for a way to get system performance metrics, this addon is my first attempt at building suppor...
by John_Mark Splunk Employee Splunk Employee in Splunk Dev 12-14-2010
0 1
0
1
andyk
How can link to and run a Splunk search from our inhouse developed firstline support system? I have a search that lo...
by andyk Path Finder in Splunk Dev 12-07-2010
0 7
0
7
Jeremiah
Anyone out there doing time-based lookups with an external python script? How do you handle the time portion of the ...
by Jeremiah Motivator in Splunk Dev 12-07-2010
1 1
1
1
Justin_Grant
When developing python code that interacts with Splunk, what's a good visual debugger that works well with Splunk's P...
by Justin_Grant Contributor in Splunk Dev 11-02-2010
0 3
0
3
sideview
Reverse engineering this stuff from the logs and existing usage in SplunkWeb's python code, I see a lot of things us...
by SplunkTrust SplunkTrust in Splunk Dev 10-22-2010
1 2
1
2
johnboldt
We are periodically seeing instances where data that was previously indexed no longer shows up, leaving "holes" in ou...
by johnboldt Explorer in Splunk Dev 10-20-2010
0 1
0
1
ngift
Hi, I am in a unique situation of having a 24 core box with 64GB's of RAM as a Splunk Search head. Giving the natur...
by ngift Engager in Splunk Dev 10-19-2010
3 4
3
4
Jason
I need to get data from a MySQL server with Splunk, either for a scripted lookup or a scripted input. I have seen a f...
by Jason Motivator in Splunk Dev 10-15-2010
1 1
1
1
dkerwin
No matter on what message i try to extract fileds i end up with a short Python exception (Error 500): AttributeError...
by dkerwin Engager in Splunk Dev 10-14-2010
1 1
1
1
the_wolverine
I have syslog-ng data coming from LWFs that have been earmarked for indexA. I want to intercept these events and rer...
by the_wolverine Champion in Splunk Dev 09-30-2010
0 12
0
12
cmeo
I find myself continually mystified by Splunk's strategy for placing things like event types, saved searches etc. How...
by cmeo Contributor in Splunk Dev 09-15-2010
0 1
0
1
groundLoop
Would it be possible to remove the fcntl Python module dependency from the pyOSSEC.py script? The fcntl module is on...
by groundLoop New Member in Splunk Dev 09-08-2010
0 3
0
3
caphrim007
Are there any splunk specific variables exposed to scripted inputs that I could use to navigate to files I distribute...
by caphrim007 Path Finder in Splunk Dev 09-04-2010
0 6
0
6
Lowell
Is there a way to directly launch a saved search via the scheduler while passing key/value pairs for macro replacemen...
by Lowell Super Champion in Splunk Dev 08-20-2010
1 1
1
1