Hello everyone, I'm working on a project ''Splunk Enterprise: An organization's go-to in detecting cyber threats'' please how/where can I get datasets and logs that I will use for my project.
I am a Splunk newbie and need to be able to search for files with multiple extensions (example: filename.ps1.doc) and am not sure how to query this...Has anyone run across how I would go a...
Hi!
So, we have a license issue. Looks like a common problem. If I'm right we need to wait 30 days or reset the license.
Before buying a license we would like to test the product a bit more.
So...
Does Splunk provide API for an external application to read the parsed data and generate the output for Splunk to display?
We plan to implement proprietary algorithm to detect anomaly in logs, but...
Hello im newbie with Splunk search Can you please help me I have HF request which return: -AAA datetime_of_change -BBB datetime_of_change Every halfhour i get the same dataset from DB to I...
Hi, Instead of passing the username and password in a plain text format, I was trying the basicauth extension for authentication and monitoring the oracledb and require some assistance, as after a...
Hi! I try to accelerate only one dataset in datamodel with multiple datasets. How i can do it through datamodel.conf or in web ui? In webui i cant choose acceleration in edit drilldown(
I've created an alert in Splunk which essentially checks for any occurence of an event with a certain attribute EventType=SOMETHING. If no events have been recorded for a specific time frame e.g 1 ho...
In the documentation on dataset literals there is an example query:
FROM
[
{ state: "Washington", abbreviation: "WA", population: 7535591 },
{ state: "California", abbreviation: "CA", population: 3...