Hi Community, I dealt with csv files before, splunk would auto extracted so many fields, shown as figure 1. But today, when I try to search these files again, only fewer fields are displayed... s...
...ven when choosing for fast-mode. However, this seems not to be that way.
So my questions: (How) are fields stored in splunk in an index when extracted during ingest?
Can I tell splunk to N...
Is there a website on Splunk docs that describe about interesting fields and what each field is about? I did research on trying to find what these field names are but still I do not know what they d...
...heir sourcetype is not the same, now ,There are now 5 sourcetype
Now 。I'm going to extract the fields of the apache access log, which requires me to choose a source type. But there is only one source t...
Hi Experts
When using the following eval, I would like to declare a variable in macro as in create_var(3).
| eval var_1 = if(isnull(var_1),"", var_1) , var_2 = if(isnull(var_2),"", var_2), var_3 ...
...S_Email tag associated to them . Now, A new source needs to be fed into the dataModel. The fields of the new source are cim compatible but are not fed into the dataModel. And I checked t...
Hello,
I would like to confirm my understanding on the following manual, and know how to get the max value from psrsvd_gc.
First I have saw this caution in the manual.
Caution: Use of these fields...
Hello again,
I'm developing a compliance app, the intention is to make it the more CIM compliant as possible, but here is the problem, no CIM fields cover windows sessions for example (which s...