What I try to do, I can get to work in dashboard, but I would like it to work in reports (savedsearches.conf)
My data looks some like this
My search | rest /services/licenser/slaves | table l...
I have a handful of searches that I want to build into reports and dashboards so I can collaborate with my team. Can you give me a sketch of how Splunk reports and dashboards work?
...'m doing the following: Create a report in: "Searches, Reports, and Alerts" the query is : index=myIndex source=mySource sourcetype=_json | rename… | table … | stats values(*) as * by T...
I've upgrade Splunk Enterprise in 7.2.3, everything went well. I opened the dashboard and have on most of my dashboard the message could not find object id= ....
I have all the rights and honestly...
Hi,
I have a job set up to create a summary index off the license data for longer term storage. The job ran, but my summary index is empty. Not sure why... here's my saved search:
[H...
I am in need of a search-switcher for simple XML. I can't seem to find anything in respect to this out there. If this is not available, does anyone have any ideas on some custom work that could b...
...ave a dashboard that views system performance statistics for both linux and windows machines. The source data is from custom SAR Python and Perfmon PowerShell scripts (not source data from a Splunk A...
Hi,
I have quite a big number of searches and views within an app, and manage them within the "searches & Reports" panel of the manager is not very convenient. I would really like to create s...
...ave two approaches and can't decide which is the better approach being new to splunk.
Problem: for a given web event, I need to create a custom search expression to extract several fields that are n...
How do you track log and index lag with little overhead? Per device would be awesome and maybe throw in some kind of trending and graphs while we are at it.