...reating these in my cloud environment on thesearchheads that I did not create the index from. The issue is that for things like multi-select dashboard inputs that use this API to select index and I...
...heads. The issue we are having is that when one of the new physical searchheads is made captain all of thedashboard panels in every app display "Action forbidden". The cluster is also unable to d...
I upgraded the Splunk App for Stream to 6.5.1, and now the "Configure Streams", "IP Address Filters", and "Distributed Forwarder Manager" dashboards do not populate with anything except static data....
I'm working on a dashboard, and trying to configure a drill down with a custom search. If the custom search contains the rex command, which includes several special characters including ?, <, &g...
...ow do alerts work? If we create an alert by logging into one of thesearchheads can we then configure it on the other searchhead? If it appears on both searchheads does the alert run twice?
T...
...riority over the older while also benefitting from theconfigurations made in the previous version? SearchHead Local changes to not appear to be visible in the deployer server, so do I have to also i...
...or Multiple Charts
Inspecting the actual searches to analyze performance via the Job Inspector
Run Searches in Advance and Use Cached Results
Evaluate Server Performance with respect to S...
I've found a variety of posts on this, the closest answer I have found is "In order to keep a dashboard stable and live, is there a way to configure automatic login if Splunk service is r...
...orks fine
But ca_sh,ca_btool,ca_tool is where I am stuck. Are they supposed to reside within the parent app config_analytics in thesearchhead or should i put them independently under etc/apps f...
I have Configured Distributed Splunk Setup AWS add-on in Heavy Forwarder and AWS app in SearchHead but Configuration changes not displaying AWS app dashboard