I have some doubts about Updating Splunk Apps. 1. The Splunk Apps that comes pre-built/packed with Enterprise Security such as Extreme Search, RapidDiag, Splunk AddOn for UEBA etc.... Do they a...
Hi, all.
I have a cluster environment. (1 search head, 2 indexer)
I want to change the character code of the data.
So, I rewritten and reloaded props.conf of theapplication under d...
does this affect anything typically?
I ask this because I have apps that I downloaded from splunkbase and put into /opt/splunk/etc/shcluster/apps and rand the command recomened but thoses apps a...
SplunkBase,
The following question is partially out of curiosity...
When a search string is saved as a report (e.g. a pie chart), where in the conf files is the information dictating the c...
Hello! We are new to Splunk Cloud and have a question about installing app/add-ons that we couldn't find definitive information on in the documentation. We have 3 instances, IDM, Search head 1, a...
Hi,
We have 3 search heads in a SHC, I am planning to deploy "Splunk_SA_CIM" in my SHC from Deployer.
Question 1- Once the "Splunk_SA_CIM" is deployed in SHC members, and then for example i e...
Is there a way to get the current app name in a search ? I've found how to get the current user name (| rest splunk_server=local /services/authentication/current-context | table username) but I w...
...ork either), but this can time out on behemoth search heads and leaves us having to restart thesearch head if the config is not applying. Is there anything we can do about this? How do we trigger a m...
...e run the setup wizard it will do so for the pre defined ones that come with ES or with Security Essentials app itself. There is nothing mentioned about custom correlation searches that o...
Hi everyone, I have some questions about skipped searches. With the following search, I have found, that on my SH I have a few (2800 last 7 days) skipped searches. index = _internal s...