Hi Splunkers, I spent a long time trying to figure out this story where: I need to create a new alert under name (failed-handshake) in the custom email template to notify tech arch teams if w...
How can I create a customized app which contains a login page with name and submit button?
After hitting the submit button, it redirects to a page, displays date/time and login name.
Hi,
We are planning to create alerts based on the search pattern we are given. We are very new and need your suggestions for this.
We want to create an alert in case of any job failure. For t...
Hello,
Is it possible to createcustom lookup files names and then use them in lookup command in a query?
My events have this field:
... csvfileIndex=1 ...
... csvfileIndex=2 ...
I have m...
While creating a saved search or a custom dashboard through one of the apps, is there a way to make sure that the name of the search will be unique across all the apps? i.e. No two searches should h...
I'm looking for help on creating a custom CEF index.
I have CEF Syslog data sent into my Splunk instance and I'd like to index some of the tokened fields and simply parse the others.
I know h...
...here WHOIS, Severity, and lastCheck are field names in the lookup table.
This should also exhibit the same behavior, dynamically, for `my_macro(destinationAddress)`:
destinationAddress_WHOIS d...
...lerts as notable events in Splunk ES. Facts: 1. I have created a Splunk Correlation search in Content Management "Suricata Medium Severity Alert" which has a custom search: index=suricata s...
...o appear across the row for the same record with separate column names instead of just multiple rows as it is now. The new column headers (fields) would be: Tool, ID, Severity,Incident Id, Progress. T...
Running Splunk Enterprise 8.0.0 on an internal network. I went away on vacation for a few weeks with Splunk working fine and came back to it not. I'm not sure how long it had been down, and no one c...