Existential question here... 🙂
What is the appropriate mechanism in Splunk to have multiple (potentially hundreds) of alerts that are based on the latest events, rather than real-time or t...
All,
I see a few examples on convert an event received into a metric. Is there a way to say keep an apache log and create a metric of the stratus?
thanks
-Daniel
we have a data of 14k events under event index, which is unstructured. I'm trying to ingest this data under a metric index at search time using mcollect command and was able toconvert the eventlogs...
...chema:extract_sqlphysicaldisk]
METRIC-SCHEMA-MEASURES = _ALLNUMS_
My SQL index where i would like these logsto go into does not have the "datatype=metrics" setting as i thought this should convert...
Tools such as graphite allow for the concept of "infinity" in charts in order to display vertical lines to be overlayed on charts. These are typically used for marking single events over a c...
When configuring ingest-time logtometrics conversions via props.conf and transforms.conf, does Splunk still index the original events to a normal log index?
Is it possible to have the same i...