All Topics

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Topics

Hello, I'd like to understand if it's possible with any Splunk version, preferably version 6 or later, to implement this type of behavior: - Send and email only the first time the alarm condition i... See more...
Hello, I'd like to understand if it's possible with any Splunk version, preferably version 6 or later, to implement this type of behavior: - Send and email only the first time the alarm condition is met. If the alarm (scheduled with the "cron" method) triggers again the next time, don't send any email - Send an "end of alarm" email, after an alarm fired, when the alarm condition is not met anymore Thanks.
Hi, I need to do some analysis on access permissions of an application. I want to graphically show the relationships of users and the access they have. I have a simple data set like the format below... See more...
Hi, I need to do some analysis on access permissions of an application. I want to graphically show the relationships of users and the access they have. I have a simple data set like the format below (I have a much bigger dataset): I would like to answer the question: Of the users who have access to a specific folder, say "Apple", what other folders to they have access to and what are the associated volumes with that connection. I was thinking Sankey diagram but I am having trouble getting the data in the right format. Any help would be really appreciated. UserID Folder 1 Apple 1 Banana 2 Apple 3 Apple 3 Orange
Is there a list of tasks to perform daily / weekly to optimize Enterprise Security? In addition to any useful SPLs please? Thank you for your help & advice in advance.
I have Monitoring console on Ent + ES. Plus I have Splunk Admins + Meta Woot! on the Splunk Ent. Any cool Admin Apps for ES? Or Splunk Enterprise? Your valued message is much appreciated in advance.
Hello,  To pull in specific events in splunk i am trying to write a regex to identify lines that matches both the conditions 1: app_protocol=http or https 2. src_ip = starts with 15. or 16. This ... See more...
Hello,  To pull in specific events in splunk i am trying to write a regex to identify lines that matches both the conditions 1: app_protocol=http or https 2. src_ip = starts with 15. or 16. This is what i have , but doesnt seem to be working , am i doing somting wrong ?  .*app_protocol=HTTP|S\s.*(src_ip\=15\.\d+\.\d+\.\d+|16.\.\d+\.\d+\.\d+)*
I have to find logs between "string1"  and  "string2" in Splunk for index=abc. Then I need to verify if there is any "Error" or "Severe" word displayed in those logs. Can someone please help with th... See more...
I have to find logs between "string1"  and  "string2" in Splunk for index=abc. Then I need to verify if there is any "Error" or "Severe" word displayed in those logs. Can someone please help with the Splunk query?
Hi, I am configuring SSL encryption b/w agent and indexer/deployment server. But passwords placed under deployment-apps, remains in clear text.  I am looking for workaround to ensure password gets ... See more...
Hi, I am configuring SSL encryption b/w agent and indexer/deployment server. But passwords placed under deployment-apps, remains in clear text.  I am looking for workaround to ensure password gets encrypted. If not what are other options do we have to ensure secured communication b/w agent and indexer/deployment server? All suggestions are welcomed.
Hello there, I found what might be bug in dashboard studio. I wanted to fill the "refresh" parameters on dataSource using a token from a Number input field. When i edit the dashboard script to ... See more...
Hello there, I found what might be bug in dashboard studio. I wanted to fill the "refresh" parameters on dataSource using a token from a Number input field. When i edit the dashboard script to fill the "refresh" parameter with my token ($my_refresh_token$) and validate, i got a blank page, have to refresh the dashboard to make it work again, and the change is not saved ( when i fill the parameter with something like "60s" it works.) Can someone confirm this ?  Best regards, 
Hi team,  I need a golang REST API  code for sending the json logs to splunk enterprise. I have a hard time searching in the web , but unable to find the right sort of code that works . It would be ... See more...
Hi team,  I need a golang REST API  code for sending the json logs to splunk enterprise. I have a hard time searching in the web , but unable to find the right sort of code that works . It would be helpful for me if i get some links for it as soon as possible .  Thanks in advance, Arun
Hi all, I have an alert that looks for a specific message that includes the record ID. I would like to be able to create a numeric value for that ID that could be used to create a unique ID when ra... See more...
Hi all, I have an alert that looks for a specific message that includes the record ID. I would like to be able to create a numeric value for that ID that could be used to create a unique ID when raising a ServiceNow ticket.  Therefore, all alerts for the same record ID would write to the same SNow ticket. The record ID is a string of 7 alphanumerics - e.g. abc4efg I would like to be able to change "abc4efg" to "1234567".  Thus the number does not change, but the letters are all the equivalent 1-26 number. The only constant is the length of the record ID which is 7 characters. I've looked at many answers, sadly none provide exactly what I am looking for. Is this something that could be achieved using SED?   Thanks in advance.
Brand new to using the Universal Forwarder, and Splunk in general.   Question: When using the forwarder/monitor, the logs on the forwarding server are still kept locally, correct? They aren't remo... See more...
Brand new to using the Universal Forwarder, and Splunk in general.   Question: When using the forwarder/monitor, the logs on the forwarding server are still kept locally, correct? They aren't removed/modified in any way?
Hi guys. I'm completly new to Splunk. Sorry if my question seems kinda stupid I have some log-data including a GUID. Those are separated in two kinds: "error" and "times". Sometimes, an error-l... See more...
Hi guys. I'm completly new to Splunk. Sorry if my question seems kinda stupid I have some log-data including a GUID. Those are separated in two kinds: "error" and "times". Sometimes, an error-log has the same GUID as a times-log. I need to count those double GUIDs, for that reason I have to extract the GUIDs from their original field und compare them with each other. I managed to extract them with Regex into two new fields. But now I'm searching for an opportunity to compare every error-GUID with every times-GUID. Thanks for your help!
Running Splunk 8.1.4 and Splunk app for Windows Infrastructure 2.0.1. I tried to upgrade to 2.0.4 and after restart splunk service I get the error 404 when I try to access the App. checking splunkd.... See more...
Running Splunk 8.1.4 and Splunk app for Windows Infrastructure 2.0.1. I tried to upgrade to 2.0.4 and after restart splunk service I get the error 404 when I try to access the App. checking splunkd.log I see the following: ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\customize_features.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\guided_setup.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\host_information.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\infra_home.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\lookup_builder.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\lookup_migrator.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\windows_host_inventory.html: The system cannot find the path specified. 09-03-2021 15:00:03.577 +0200 ERROR PropertiesMap - Cannot open: C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\default\data\ui\html\windows_perfmon.html: The system cannot find the path specified.   Checking the file system, the folder html is not present . could someone explain me what is happening?   thanks a lot  
Hi All I have a NodeJS application. I have configured the NodeJS app agent to the application and configured it successfully. Now I need my business transaction to be shown in the flow diagram ... See more...
Hi All I have a NodeJS application. I have configured the NodeJS app agent to the application and configured it successfully. Now I need my business transaction to be shown in the flow diagram of the application's main dashboard, but what I see is Node and other connectivity like DB, etc. If I go to tiers and node I see tier as NodeJS as give during app agent installation and Node is process-0 same which is given during installation. What should I do for getting each business transaction to show as a node in the flow diagram? Please share with me some ideas or steps to work on. If no, please share with me some alternates. thanks
Hi All  We are using a hybrid mobile application that is in Web View and runs through REST APIs on both iOS and Android. Which is the best way to install a mobile agent? Is it through SDK or Ja... See more...
Hi All  We are using a hybrid mobile application that is in Web View and runs through REST APIs on both iOS and Android. Which is the best way to install a mobile agent? Is it through SDK or JavaScript? If both are possible, what are the benefits of SDK and JavaScript? Thanks ^ Edited by @Ryan.Paredez for improved clarity
Hi all. Background is I have recently acquired a JSON feed via Kafka but the schema was developed with other uses in mind so it's not working particularly well for our logging requirements. For som... See more...
Hi all. Background is I have recently acquired a JSON feed via Kafka but the schema was developed with other uses in mind so it's not working particularly well for our logging requirements. For some reason the event type is being used as a key name. It annoys me greatly as there's no way to run a search for a specific event type. Its also playing havoc with extractions as the full path to the required value needs to be known, but can not be in a search as the event type can change. We can get the values if we know a specific event type (eg. Eventtype4.request.someKey), however it's very difficult to return the same value when the specific event type is unknown (eg. *.request.someKey) The second issue is all event types are present in the event but all but one has a null value. This can get very messy when there could be several hundred types of events.... I have tried stripping the first level and extracting the name of a key that has a non-null value but nothing works particularly all that well.  Any assistance will be appreciated. { Eventtype1: null Eventtype2: null Eventtype3: null Eventtype4: {    request: {               "someKey": "helloworld"               "anotherKey": "anothervalue"    }    response: {             "datachunk": "a few values here"    } } header: {               "timestamp": 123456789012               "someid": "323abcd" } }
Hello Splunkers, I am unable to make this trellis align, and remove that scrolling? Can you please help me in this? Tried from my end, but unable to. Below is my html for the same:   <panel d... See more...
Hello Splunkers, I am unable to make this trellis align, and remove that scrolling? Can you please help me in this? Tried from my end, but unable to. Below is my html for the same:   <panel depends="$alwaysHideCSS$"> <html> <style> #si1{ width:20% !important; } </style> <style> #si_viz1 .splunk-status-indicator { height: 100px !important; width: 120px !important; border-radius: 15px !important; float: left; padding: 15px 0px 0px 0px; } </style> </html>
How may I automatically generate a file on an on-prem server from the results of a search query
Hello everybody, I'm using an spl query that extracts some values from a lookup and sends them to a web API via POST request (for this i'm using the WebTools add-on). To send data formatted as repo... See more...
Hello everybody, I'm using an spl query that extracts some values from a lookup and sends them to a web API via POST request (for this i'm using the WebTools add-on). To send data formatted as reported in the api swagger, I'm using the Splunk command "tojson" to convert Spl query results to Json in my test instance. Since the tojson command is really new (props to Splunk for adding this!) and was introduced from 8.2, is there a way to do the same in previous Splunk versions? Splunk Query: |inputlookup l2d.csv |eventstats values(tp) as id | table id,code | tojson <...curl using raw field from tojson> Json format expected and produced with tojson command: {"id":["id1","id2"],"code":"00001"}    Thank you for the attention, have a nice day,