All Posts

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Posts

Hi @Ramesh.Jakka, Since the community has not jumped in, you can contact AppDynamics Support for help. If you do, and you get a solution, can you please come back and share it here.  How do I sub... See more...
Hi @Ramesh.Jakka, Since the community has not jumped in, you can contact AppDynamics Support for help. If you do, and you get a solution, can you please come back and share it here.  How do I submit a Support ticket? An FAQ 
Hi @Shubham.Kadam, Did you talk about this with AppD on your call? Or is this a new issue after the call?
Hi @Josh.Varughese, If anyone of Rajesh's replies helped, please click the "Accept as Solution" button if, not, please reply and keep the conversation going! 
Hi @andgarciaa , good for you, see next time! let me know if I can help you more, or, please, accept one answer for the other people of Community. Ciao and happy splunking Giuseppe P.S.: Karma P... See more...
Hi @andgarciaa , good for you, see next time! let me know if I can help you more, or, please, accept one answer for the other people of Community. Ciao and happy splunking Giuseppe P.S.: Karma Points are appreciated
Hi @svibhute  There are a number of options and depending on your app deployment architecture.  1. Download the latest version of the app  from Splunk - extract the tar file - copy over to /opt/s... See more...
Hi @svibhute  There are a number of options and depending on your app deployment architecture.  1. Download the latest version of the app  from Splunk - extract the tar file - copy over to /opt/splunk/etc/apps folder (ensure splunk permissions are set sudo chown -R splunk:splunk - this is typical) and if its Linux based as opposed to Windows.  2. You can directly install via the HF GUI (if you have admin access)  go to managed apps, install from file (you should have already downloaded the tar file) or if you have a registered account with Splunk then use the browser more apps option and di it via there.  3. If you are using a deployment server to manage apps, then follow that process, where the app is pushed out to the HF.  I would also make backup of the /opt/splunk/etc/apps folder on the HF prior to the upgrade.     
Thank You very much
We have RSA SecurID addon installed on Syslog server which also is a HF. Can anyone share steps to upgrade the addon.  @splunk 
Please share your search and dashboard code (anonymised of course)
I am getting result 99.99% but it is getting round off to 100.00% , But I want to show 99.99% only.
| xyseries topic mbean_property_name bytes
Try adding an init block <init> <eval token="latest_Time">relative_time(now(), "+1d")</eval> </init>
inputs.conf web.conf. what is the purpose of these files
How to convert table like this (2 rows per topic):   topic   mbean_property_name bytes A   BytesOutPerSec  60376267182 A   BytesInPerSec   12036381418 B   BytesInPerSec   6246693551 B   BytesO... See more...
How to convert table like this (2 rows per topic):   topic   mbean_property_name bytes A   BytesOutPerSec  60376267182 A   BytesInPerSec   12036381418 B   BytesInPerSec   6246693551 B   BytesOutPerSec  6237320887 to topic   BytesOutPerSec  BytesInPerSec A   60376267182 12036381418 B   6237320887 6246693551
Hi @gcusello! I am using Splunk Cloud. I will check with Splunk Sales. The idea is because one of the users is looking to evaluate if is worthing (cost basis) to increase retention period for the u... See more...
Hi @gcusello! I am using Splunk Cloud. I will check with Splunk Sales. The idea is because one of the users is looking to evaluate if is worthing (cost basis) to increase retention period for the usage of this data temporary instead of backing it up in another location. Thanks, Andrés
Hi @andgarciaa , are you speaking of Splunk Cloud or On-premise? if Splunk Cloud, you have to ask to your Splunk Sales. If on premise, the only cost is the additional storage that you can estimate... See more...
Hi @andgarciaa , are you speaking of Splunk Cloud or On-premise? if Splunk Cloud, you have to ask to your Splunk Sales. If on premise, the only cost is the additional storage that you can estimate duplicating the actual storage. Ciao. Giuseppe
If I have an index with a retention of 90 days. Can I make a rough estimate about the cost of increasing the retention of index=  index-name  extra 90 day?
Hi, we decided to create backups and just go for it. It worked fine! After upgrade everything is indexing without any issues. Also no problem during upgrade from msi. Thanks for giving us a little ... See more...
Hi, we decided to create backups and just go for it. It worked fine! After upgrade everything is indexing without any issues. Also no problem during upgrade from msi. Thanks for giving us a little courage I guess. We decided to "experiment". For the greater good heh.
<form version="1.1"> <label>My dashboard</label> <fieldset submitButton="false"></fieldset> <row id="mainFilterRow" depends="$showHidePanel$"> <panel id="mainFilterPanel1"> <input t... See more...
<form version="1.1"> <label>My dashboard</label> <fieldset submitButton="false"></fieldset> <row id="mainFilterRow" depends="$showHidePanel$"> <panel id="mainFilterPanel1"> <input type="time" token="time"> <label>DateTime</label> <default> <earliest>@d</earliest> <latest>now</latest> </default> </input> </panel> <panel id="mainFilterPanel21"> <input type="dropdown" token="TimeDrop"> <label>TimeDrop</label> <choice value="+1d">1d</choice> <choice value="+2d">2d</choice> <choice value="+5d">5d</choice> <default>1d</default> <change> <eval token="latest_Time">relative_time($time.latest$, $TimeDrop$)</eval> </change> </input> </panel> </row> <row id="chartRow" depends="$showHidePanel$"> <panel> <search> <query>index=main | stats count by host</query> <earliest>$time.earliest$</earliest> <latest>$latest_Time$</latest> </search> </panel> </row> </form>
This is a broad question. What is your specific usecase that you are trying to solve?
If you mean to change the standard timepicker to include your special options into a modified timepicker, try adding new timeranges: Time ranges are configured in Settings -> Knowledge -> User interf... See more...
If you mean to change the standard timepicker to include your special options into a modified timepicker, try adding new timeranges: Time ranges are configured in Settings -> Knowledge -> User interface -> Time ranges section of the Splunk interface.