...nstall of splunk customindexes for each log type above the only events I seem to get in the logs are from the date that the customindexes are created and not back to the first log entry on the server....
Not sure what's wrong here. When I try to create any input, the only indexes I can see is history, main and summary. The other add-ons on this instance are showing all the indexes and have a f...
...ble to create a search string like: host="my_fwd_server.net" index="fwd_index" , etc.
Is this possible or is this unnecessary for the data coming from the forwarder since I know the hostname?
T...
...ays:
1. Splunk Web
2. CLI
3. Edit indexes.conf
When using CLI (2), indexers.conf is created in $SPLUNK_HOME/etc/apps/search/local
When editing indexes.conf (3) it says to put it in $S...
...o do is to set additional default fields based on other default field which is "source". Is it possible at all? Would the "source" already exist and be available at that point to create additional f...
Hello Splunkers, Is it possible to limit the searchable indexes within a custom app ? For instance, if I create a new app called "myapp" and inside the Search tab of this app, I want to only b...
Hi
I know that splunk automatically creates default fields like host,sourcetype,index at index time.And also the splunk provides a option to create any new fields also during index time.
My r...
...cans tsidx files for the search keywords and uses their location references to retrieve from the rawdata file the events to which those keywords refer. Splunk Enterprise creates a separate s...
Report acceleration is failing because splunk cannot create the folder for the summary (summaryHomePath ).
This seems linked to my custom homePaths.
It works for this index, and the folder /o...