...I'm left with "No results found. Inspect.."
Clicking through gives me the following:
================================
This search has completed and found 5 matching events. However, the transforming...
Hello,
In the PostProcess Search documentation it says that non-transformingsearches which return raw events have a 10,000 return limit. It is unclear if a transformingsearch still has this l...
Hi All,
I need your helping in writing post process & base searches..
My dashboard requires a chart command in the first panel..
So having the post process search as below in first panel,I...
I have the following stanza on the transforms.conf which actually splits commands separated by characters like |, &, ; etc. and extracts arguments in a separate field
[s...
I am looking to export the results of a Splunk search that contains transformingcommands. When I run the same search in the web GUI the live results "hang" on 50,000 stats, but once the search...
Hello,
I have recently upgraded from Splunk 7 to Splunk 8.2.4.
After the upgrade, I noticed that some transformcommands such as chart or stats do not work in smart and fast m...
Hi guys, I'm using splunk 8.0
I want to create a command that can send some infos to another via web or api. I read the Dev page but hard to understand. Do you know some easy script?
Like I h...
...command like stats, chart and timechart you can lose events if there is more than 500000 events Event retention If the base search is a non-transformingsearch, the Splunk platform retains o...
...ompleted and found 323,136 matching events. However, the transformingcommands in the highlighted portion of the following search:
search sourcetype="cisco_wsa_squid" TCP_DENIED earliest="-24h@h" N...