Hi Experts, I have the following data. { "TIMESTAMP": 1742677200, "SYSINFO": "{\"number_of_notconnect_interfaces\":0,\"hostname\":\"test\",\"number_of_transceivers\":{\"10G-LR\":10,\"100G-C...
Hi everyone, I'm currently working on integrating Trellix ePolicy Orchestrator (ePO) logs into Splunk for better monitoring and analysis. I would like to know the best approach to configure Splunk t...
in regex101.com, tested below REGEX it was working Updated below props.conf and transforms.conf in deployment server and 2 heavy forwarders as well, but not working props.conf [nix:messages] TRAN...
Hello folks, I trying to use a base search within a dashboard but it consistently returns no results. However, when I click Open in Search the results appear as expected. Any of you fine people have...
Hello guys, I have a dashboard with two tabs. I've added a dropdown input and I'm going to add more inputs. But I want to display input only for a specific tab. In my case, I want for example ...
Hello, I currently deploy Splunk Enterprise and wanted to find out how to set a data retention policy for the index labelled as ‘Main’ within the index’s section in Splunk Enterprise. Since the ‘mai...
Hello, I have defined a frozenTimePeriodInSecs for 1 hour on my IDX for a certain index, so that the logs it contains are only kept for 1 hour. The definition of the frozenTimePeriodInSecs was made...
Hi Experts,
Is there any way i can add "Hostname,Node Name,Tier name" in healthrule names ?
Tested with some placeholders didn't worked. Appreciate your suggestions.
Eg :
...
Splunk Enterprise ships with a copy of PostGreSQL. The latest splunk installer, v9.4.1, however still ships with a version of Postgresql 16.0 which has several Security vulnerabilities. Is there a do...
Hi I have the following data. I am looking to get a line per data, so I can work with it better. If I use mvexpand I hit memory limits, as I need to do it on all the fields. Is there another way? ...