Hello Experts, I am trying to work on setting up panels with two different queries output based on a filter. I am using the change on condition option <input type="dropdown" t...
Hello, I'm having a problem with the colouring of a column in my table. I need to colour the AverageExecutionTime column according to the value of Treshold. If AverageExecutionTime > Treshold th...
...xisting instances, i tried to simply change the serverName in server.conf to the hostname and restarting the Splunk service. Splunk service is starting without complains, but the Monitoring Console r...
...ncoming sourcetype. So basically use props.conf to catch any sourcetype with ‘metrics’ in its name, and then use transforms.conf REGEX to change the index name from the default ‘<bla bla>_...
...imechart span=4h aligntime=@h-120m However after testing, neither of these is actually offsetting the span. It only changes the times shown in the resulting table. The values (in my case c...
Hello everyone! I would like to ask about the Splunk Heavy Forwarder Splunk-side config: https://splunk.github.io/splunk-connect-for-syslog/main/sources/vendor/Splunk/heavyforwarder/ With those ...
Hello, I'm to try changing the sourcetype at the indexer level based on the source. First question is that possible on an indexer. Second would it work with props.conf r...
Hello, Splunk offers the option of saving changes made in an app via Splunk Web directly to the default directory. By default, Splunk saves all changes made via the Splunk Web interface in the l...
Hello wonderful Splunk community, I have some data where I want count to change only when status changes: Status Count ------------------- Online 1 Online&n...