...innow down, analyze, or extract data by reloading the initial dataset with | loadjob sid.xxxxxxx
If the SID were displayed as a colum in the Job Manager, that would greatly improve usability for f...
Hello splunker, i want to write an SPL to list email senders excluding emails in a predefined lookup table. here's my command: index=email eventtype="email-events" action=delivered [ | inpu...
I have a dataset with some data points from a report I made; week end date(MM/DD/YYYY), host, user action, and average response time are the data-points. We have a large dataset so the run time is p...
...xisting lookup if that is possible.
Or perhaps there is a better way of combining the information without using transaction at all.
The downside of the dataset is that transactions can occur o...
Hello guys,
could you explain me differences between data models and datasets?
It seems Pivot reports are based either on datamodels or datasets but both look similar?
In V6.5 : are pivot r...
Hello all,
I have a search technique I've been using to compare smaller sets of data, to find the difference, however I'm running into the subsearch limit with a new set of data. I'm hoping someon...
Hi,
we are currently adding data sources to our Splunk environment. We try our best to make it CIM compliant. We have a dedicated ES search head and we do not want ES to look at this data. How c...
Hi guys, I'm quite new about alert manager app. I'm trying to configure a notification for auto-assigned incidents, but it seems it doesn't work. On incident posture dashboard new incidents are c...