...bsp; andcreated xyz = attrs.xyz, but now I have created this field alias and I can't see it (use it to filter the search) but admin user can see this field although correct app - search was s...
We had an EC2 instance become inaccessible via the AWS Session Manager.
Root cause was the main volume filling-up with various splunkfowarder-x.x.x RPM files in /usr/bin/
Yesterday the f...
...oww to organize apps, both Splunkbase downloaded and in-house built and also configuration-only apps, if they are a best practice? Right now we are experimenting with deploying the Splunkbase apps as t...
...DB Connect but didn't updated it yet)
Recently I'm facing an issue that my already configured inputs are working absolutely fine in Splunk DB Connect and whenever I'm trying to create a new i...
...replace it with a bunch of specific users.
Ideally, I am going to have to figure out what services / software / backups etc etc that are run as Administrator.
Is this something Splunk can / w...
I have users creating alerts in our DEV space and I was wondering if those are stored in .CONF stanza that I can pickup anduse to migrate to production?
If they are where are they stored and is t...
Dashboards created in Splunk 6.2 are not showing up correctly on Splunk Mobile App. However, dashboards that were created in an older version of Splunk (ver. 6.1) are rendered correctly (but the t...
Given that my search criteria is this: index=some_index sourcetype=some_sourcetype , is there a shortcut to piping the | table * command where splunk-created fields are automatically excluded? (B...
...ould never detect that.
Problem 2. savedsearch might fail to run and state in _internal still would still show success (Splunk 6.6.4). At least my testing showed that.
Problem 3. With savedsearch, e...