I'm having no luck building a regex to match cs_usernames . What I'm looking for are two separate searches both based on the
cs_username field. The first search is to find all instances w...
...nformation under "Manage Apps".
Now I want to build a dashboard that shows any available updates for Splunk Enterprise + Splunk apps.
For Splunk apps, it is possible to run a search which shows a...
Hi!
I need help with a search to find scheduled reports that are running. I want to know what are exactly running right now.
Is there someone who can help me with that?
...esponse, 2894 OpenDNS DNSCrypt, 577 I to united similia events and output should be this: signature, count Torrent, 1864 DNS, 87230 Can someone help me with the search p...
So i am trying to convert some of my searches from joins to appendcol to improve performance but I am running into some problems.
I can't figure out how to create a table in this question- so j...
...e able to find the change in value, per server over time.
I would like the results to be similar to:
Server ChangeSinceYesterday
abc 5
xyz 8
Can anyone help me to do this i...
...he usecase.
To check the enabled usecases I'm using the below query.
| rest splunk_server=local count=0 /services/saved/searches
| search disabled=0 AND ( action.risk=1 OR action.notable=1 ) | t...
...ays here, not years):
index=index earliest=-0d@d latest=now | append [search index=index earliest=-1d@d latest=-0d@d]
What's the best way to build this search for this? Would love some help 🙂
I must apologize as I have found partial examples of what I am looking for, but I'm not well-versed enough to merge them together to get what I need. I have a search:
index="msexchange" s...
Hello,
I have built a Splunk testing / staging environment on top of 6 VMs. Splunk version is 6.2.3 and us running on CentOS 6.6. I have 1 Search Head, 1 Utilities Server (Cluster Master / D...