Hi Guys,
In my project environment, every splunkd is installed using splunk user. So I need to create an alert if any splunkd on any splunk server (enterprise or UF) gets startedwith root or any o...
...or what settings I should ignore?
To get to the below images i have a saved report and then I go to Settings > Searches, Reports, and Alerts. find the saved report and here is where I can s...
how to calculate job start time and job end time of transaction for particular time and to set trigger mail when start time and stop time?
This is my query ,i am getting two events as start t...
...he "/etc/init.d/splunk" start-up script, but also sometimes even after I manually shut down Splunk with "splunk stop".
What exactly triggers the unclean shutdown warning and the recovery prompt?
W...
As the title suggests, Im getting the following error when trying to execute a custom alert action script.
The script is quite simple. Its a shell script that basically looks like this:
#!/bin/b...
...anager, but if i schedule that same search but dont make it rt search it does work and I get all my alerts in my inbox.
This problem started after I upgrade to Splunk 5, with Splunk 4.x I didnt have t...
Alerts no longer email, however they do show up in triggered alerts. This started sometime yesterday, before that we have been getting email alerts and creating email alerts for months.
var\log\s...
...he saved searches, alerts. I even recursively grepped the entire splunk config directory but found nothing defined by this name. I think this is causing issue with search disk quota being exhausted. W...
...uman_sub_time = strftime(sub_time,"%y-%m-%d %H:%M:%S")
| table human_epoch_time boot_sec boot_min human_sub_time host
Output:
I am not getting the duration anymore
:Alert email that i am getting...
I am trying to set up an alert that runs a script after finding a result. For some reason, we see this error each time we try to run the script:
06-01-2020 13:20:09.091 -0500 ERROR M...