...nterprise, you do this inSplunkWeb or by editing the inputs.conf configuration file. If you have Splunk Cloud, use SplunkWeb to define source types.
And then on a Universal forwarder I have a...
...tored at Search Heads and later somehow migrated to indexers. I can edit them via splunkweb UI directly. But Web UI won't show any source typesdefined in my indexers.
If I want to achieve selective p...
...t for the end-user of the TA within the TA itself?
In the Map to Data Model tab of the Splunk Add-On Builder, I can only see the ability to create EventTypes but not map tags to the eventtype....
I installed the latest release of the Qualys App (the one officially supported by Qualys) and the TA for it.
It would seem that all of the dashboards are driven off of eventtypes that aren't define...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, many teams can benefit from having Windows Event Log data inSplunk. What are the best p...
I've heard that using AWS Lambda is a great way to get high volumes of data directly into Splunk without the overhead managing hardware. It seems like a great solution, can you provide an overview t...