...rom same Host/IP and of same type. We would like to consolidate similar ones into one common alert and then have it display the total counts of events next to that alert ?
Hi Folks,
i have events on below format which does not have time stamp on first 20 lines and i tried to create the configuration but it not succeed. could you please help me to create the t...
Hi,
I have a feed that has two different types of events and need to grab them both. Not sure how to do it...here's a sample:
Tracking ntp.fmr.com [1.2.3.4].
The current time is 6/14/2016 1:2...
I'm trying to edit inputs.conf in my forwarder to show ONLY Event 4624, with only Logon Type 2 or 11. I've seen many examples online of similar things, but nothing has worked for me so far. I u...
...endered-charts\splunk-connect-for-kubernetes\charts\splunk-kubernetes-logging\templates\configMap.yaml)
source.files.conf: |-
# This fluentd conf file contains sources for log files other t...
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, many teams can benefit from having Windows Event Log data in Splunk. What are the best p...
I've heard that using AWS Lambda is a great way to get high volumes of data directly into Splunk without the overhead managing hardware. It seems like a great solution, can you provide an overview to...
I cannot figure out which component to enable HEC and where to send the events. We have an on prem Splunk Enterprise distributed configuration with a Deployment server, Indexer and SearchHead. We a...
...dmin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-splunk) and I get the following error when I try to test the connection:
Failed to send a test notification to the event...