...onfiguretimestamprecognition?ref=hk)
What i'm trying to do is create a sourcetype that will set _time to the value in eventTime when consumed, but struggling to solve it.
I did try setting TIMESTAMP_FIELDS to e...
I'm having trouble understanding how to create customer fields for my application logs. My logs have the following fields:
Timestamp SourceIP Token HTTP.Method URL Query.String Post.Data U...
“CreateSourceType” inquiry.
We want to create a new sourcetype that break events based a word orderActivityRep { and the event ends with }.
How to do it
The logs arrive to Splunk in t...
Hi,
I'm trying to create a report that has information about all the hosts with the kernel version and OpenSSL version and SSH version. The package.sh (sourcetype=package)script on the Splunk_TA_*n...
I'm trying to create a custom sourcetype which is reading a TSV log file and the 3 column in the file is a JSON payload wrapped in quotes. I can't figure out how to get the sourcetype to parse o...
...omething5
That would mean that whenever a new sourcetype is onboarded I would have to manually add it to all the correlation searches that I created or that are by default in Splunk Enterprise Security c...
Hi there,
I've been trying to create a new sourcetype, but unfortunately - with no success.
My data is uploaded from a CSV file (hold your horses, there's a small catch).
I put all of the r...
hi all,
I am trying to create a dropdown with 3 different sourcetypes to display a graph per sourcetype.
If I try to change the sourcetype, the graph doesn't show up.
An example of the file is below. I want to break on <Object> and I tried (\<Object>\) and (\<Object\s) with no success. Can someone offer some advice or something to try? <Objects&...
Community, need some help to work with 2 different sourcetypes .
I'm trying to run a search where I need to match information from 2 sources in 1 table.
What I'm trying to do is:
index=u...