All Posts

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Posts

Thank you it is working; however, it's repeating the same value. The search will be returning 1000's of logs each with a different value and some will not contain a warning message.      
I pleased to see your query is working; however, it's repeating the same values. Sorry, I did not explain that there will be 1000's of logs, each with a different value.    
@abobengsin  This error often arises when DB Connect cannot properly validate the Java command due to an invalid or misconfigured Java path.     
Thank you.  I thought it was something like this and was going to try but didn't want to lose the 'free' option.  I ending up restarting Splunk and this changed allowing me to setup a peer with the ... See more...
Thank you.  I thought it was something like this and was going to try but didn't want to lose the 'free' option.  I ending up restarting Splunk and this changed allowing me to setup a peer with the license.   Thank you.
After setting up DB connect configuration and updating my java path I was faced with another error message being the task server currently being unavailable with the details saying: ValueError: embe... See more...
After setting up DB connect configuration and updating my java path I was faced with another error message being the task server currently being unavailable with the details saying: ValueError: embedded null character validate java command: . Any help would be appreciated.
Hi @uagraw01 , you forgot to remove the time tokens: <earliest>$TimeTokenMiddle.earliest$</earliest> <latest>$TimeTokenMiddle.latest$</latest> in many rows of your dashboards, replacing them wit... See more...
Hi @uagraw01 , you forgot to remove the time tokens: <earliest>$TimeTokenMiddle.earliest$</earliest> <latest>$TimeTokenMiddle.latest$</latest> in many rows of your dashboards, replacing them with a value for the time window. Ciao. Giuseppe  
We have a setup of data going to splunk, where we query a number of files with varying numbers of fields (sometimes over 100 per file), and have a generic dashboard setup to do some displays of them.... See more...
We have a setup of data going to splunk, where we query a number of files with varying numbers of fields (sometimes over 100 per file), and have a generic dashboard setup to do some displays of them. We use the first line of the query output for the headings of the files, but the field names are very short and not descriptive. Since this is done via ODBC we don't have direct access to the more descriptive column text. So we have for example a file coming in with fields F1,F2...F100. We are able to get those descriptive field names from SYSCOLUMNS into the form "filename, fieldname, fielddesc". Is there a reasonable way to have this display a table in splunk to show the fielddesc for each field vs the field name?
@666Meow  Please contact your sales account team. It’s possible that the account isn’t linked to the Splunk contract and entitlements, which could be why you’re unable to open a support ticket. htt... See more...
@666Meow  Please contact your sales account team. It’s possible that the account isn’t linked to the Splunk contract and entitlements, which could be why you’re unable to open a support ticket. https://www.splunk.com/en_us/pdfs/support/working-with-support.pdf  https://community.splunk.com/t5/Feedback/Trouble-Reaching-Support-to-Submit-Ticket/td-p/670365 
We have a newer (built within the past 6-months) Webex add-on available here. The older add-on that Splunk offered via Splunkbase leveraged the XML API which is now deprecated. This newer add-on leve... See more...
We have a newer (built within the past 6-months) Webex add-on available here. The older add-on that Splunk offered via Splunkbase leveraged the XML API which is now deprecated. This newer add-on leverages REST. Today, this just includes Meetings but we are set for a new release very soon that will include Calling as well, specifically data from the Get Detailed Call History API.
Support Portal is broke and I am unable to submit a case due to one of the required fields being unable to select (see attached image) "Splunk Support access to your company data: --" I've emaile... See more...
Support Portal is broke and I am unable to submit a case due to one of the required fields being unable to select (see attached image) "Splunk Support access to your company data: --" I've emailed support@splunk.com which was suggested in other community posts, but it has now been 2 months and several chase up emails and still no response from support.
Hi, I want to run a Powershell script on a Windows universal forwarder according to a cron schedule. My input looks similar to this [powershell://Test] script = . "$SplunkHome\etc\apps\test\bin\te... See more...
Hi, I want to run a Powershell script on a Windows universal forwarder according to a cron schedule. My input looks similar to this [powershell://Test] script = . "$SplunkHome\etc\apps\test\bin\test.ps1" schedule = */15 * * * * index = test Besides running every 15 minutes as it should, I noticed that the script also runs every time when Splunk starts. Reading https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf it says: "Regardless of which option you choose, the command or script always runs once when the instance starts." I don't want that. I don't want the script to run when Splunk starts. Is there any way to disable that?
Dear Splunk Community, I’m currently facing an urgent issue in my Splunk environment: my storage utilization has reached 95%, which threatens system continuity and performance. I plan to move older ... See more...
Dear Splunk Community, I’m currently facing an urgent issue in my Splunk environment: my storage utilization has reached 95%, which threatens system continuity and performance. I plan to move older data to external storage before it’s too late, but I haven’t yet implemented a bucket‐policy to automate time-based data retention. I would greatly appreciate your expertise on: Best practices for safely and efficiently migrating old data from my current Splunk indexes to external storage. Recommended scripts or Splunkbase apps that facilitate this process. How to ensure continued access to the migrated data when needed, without impacting search performance. Any additional suggestions, practical examples, or links to detailed documentation. Thank you in advance for your time and assistance. Kind regards,
Hi, I am looking to extract complete Health rule violations in Appdynamics(Servers,Application,EUM and all). Currently I could see only to pull violation from specific application.   Need to under... See more...
Hi, I am looking to extract complete Health rule violations in Appdynamics(Servers,Application,EUM and all). Currently I could see only to pull violation from specific application.   Need to understand how to use the API to pull all the violation for specified time period. If not through API any other method available.   Will there a event generation for each violation and if so where it is stored and viewed.
For Netapp data ontap plugin this is because the tar within the tgz contains hydra and the ontap package.
Deleting code. Due internal policy.
Hi @uagraw01 , could you share the code of your dashboard? Ciaol. Giuseppe
@gcusello @livehybrid I have removed all the inputs. But still option is not in a displaying mode.  
Hi @uagraw01  inputs are the fields that you might have at the top of your dashboard, such as time picker, dropdowns, text input etc. Do you have any of these? If so this is why you won’t have the ... See more...
Hi @uagraw01  inputs are the fields that you might have at the top of your dashboard, such as time picker, dropdowns, text input etc. Do you have any of these? If so this is why you won’t have the option to schedule PDF delivery. 
What do you mean by inputs ? Are asking for input tokens ?
Hi @uagraw01  Does your dashboard include any inputs such as time pickers, dropdowns etc? If so this will prevent the PDF schedule option.   Did this answer help you? If so, please consider: ... See more...
Hi @uagraw01  Does your dashboard include any inputs such as time pickers, dropdowns etc? If so this will prevent the PDF schedule option.   Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing.