Hello,
In the PostProcess Search documentation it says that non-transformingsearches which return raw events have a 10,000 return limit. It is unclear if a transformingsearch still has this l...
I have the following stanza on the transforms.conf which actually splits commands separated by characters like |, &, ; etc. and extracts arguments in a separate field
[s...
Hi All,
I need your helping in writing post process & base searches..
My dashboard requires a chart command in the first panel..
So having the post process search as below in first panel,I...
I am looking to export the results of a Splunk search that contains transformingcommands. When I run the same search in the web GUI the live results "hang" on 50,000 stats, but once the search...
...I'm left with "No results found. Inspect.."
Clicking through gives me the following:
================================
This search has completed and found 5 matching events. However, the transforming...
Hello,
I have recently upgraded from Splunk 7 to Splunk 8.2.4.
After the upgrade, I noticed that some transformcommands such as chart or stats do not work in smart and fast m...
Hi guys, I'm using splunk 8.0
I want to create a command that can send some infos to another via web or api. I read the Dev page but hard to understand. Do you know some easy script?
Like I h...
...command like stats, chart and timechart you can lose events if there is more than 500000 events Event retention If the base search is a non-transformingsearch, the Splunk platform retains o...
Hi All, I am using the base searchand post-process searches outlined below, along with additional post-process searches in my Splunk dashboard. The index name and fields are consistent across all t...