...rice", "History", "Notify")
There are around 10 values that I want to filter out from 30-40 values. So the list specified in IN will have 10 values.
I want to create an overview dashboard (P...
Greetings!!
1.a. I need to check data size indexed in indexers per day, per month and per year in GB?
1.b. what if the data ingested per day is 200GB/day, How do I calculate to know the ...
...ia the Alert or Scheduler UIs, but how do I access these environment variables via SPL? Should I use the '| rest ....' command? Which REST APIs will have the job title/owner info? Here is w...
Hello, Splunk lovers! I have some questions
What i want:
1. i want to make a table from search history, where time presets were queried by all_time or long diaposone
2. i want find other s...
I am looking for an example of dispatching a saved search job with custom latest and earliest boundaries.
A bit of history: my python program finds a Saved Search by its name and instantiates a j...
...ndex (in order to keep the history) by using collect command:
index=source | ... | eval new_status="a new status" | collect index=source
but the new field is not kept and saved - is any w...
Is anyway to find all historical results of a scheduled report in splunk? I've seen about REST and the | historycommand but that command shows only when that report has been scheduled but I want t...
Out of the box, Splunk is able to collect a lot of Windows data. But I also see many items on Splunkbase for Windows and related Microsoft technologies. Is there a complete list of apps and when to u...
I have searched splunk with one query and also applied some datetime range. Now, I want to see the same search results again. How can I achieve that?
I have used the | historycommand, but it i...