Hi, We are using Splunk Enterprise on-premise. Now, I launched another one with a trial license and I would like to test Security features. However the app download is restricted unfortunately. ...
Hi, I have dataset in the following format Name,Status,Timestamp ABC,F, 04/24/2025 15:30:03 ABC, R, 04/24/2025 15:15:01 I need to be able to only display / render the latest status for a ...
I am thinking about which way is better to use LDAP(AD) or SAML for authentication of Splunk Cloud. Unlike Splunk standalone, the cloud version looks like a little tricky. I read some document that...
Wondering if there's a blacklist parameter I can add to one of my Azure inputs so that Splunk will ignore pulling the event across the WAN. I already have a working ingest action, but the amount of d...
Hi, I have this field in this format and i am using eval to convert but sometimes there is an extra space in it after : Mon 2 Jun 2025 20:51:24 : 792 EDT - with extra space after hhmmss...
Hello all, I have the following case: Splunk accessible on https://dh2.mydomain.com/sendemail931 with "enable_spotlight_search = true" in web-features.conf. If I search for anything and a r...
In the documentation <https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/9.3/build-a-data-model/about-data-models>, there is written: Dataset con...
Hi Team, I have added Red & Green color to Status column, I want to add the same to severity column as well. Can some one suggest me some commands I have used below commands to add col...
Dear everyone, I have a Splunk Clustering (2 indexers) with: Replication Factor=2 Searchable Factor=2 I supposed to sizing a index A on indexes.conf. Then, I found this useful website: https...
Hi , I have this scenario where i am getting data from one of the index with 2 other specified filters like index=index_logs_App989 customer="*ABC*" org in ("Provider1","Provider2") i have ...