...innow down, analyze, or extract data by reloading the initial dataset with | loadjob sid.xxxxxxx
If the SID were displayed as a colum in the Job Manager, that would greatly improve usability for f...
I was wondering if there is a way to upload / manage Splunk Datasets with the SDK ? I quick run through the very nice documentation doesn't indicate there is anything.
...apabilities inherit by Role = "user"), then from Settings >> User Interface >> Views I have removed the read permission to the following views for "user_read_only" and "user":
Search
Datasets...
...ew app in 6.5, I could see the tab is renamed to "Datasets" and the link is indeed to /en-US/app/appname/datasets.
Shouldn't Splunk manage these things between upgrades?
Best regards,
Victor
I've been playing around with the new datasets add-on - it's very slick, well done. Now I want to delete some of the testing tables I created, but there isn't a Delete option in the Data Model Manage...
The TA mapped our bluecoat index as a Web cim compliant. Looking at our bluecoat index and reports we built on top and some of these fields, that we use are not defined at Web CIM
Therefore, is i...
...xplained. What is expected in these sub datasets is hard to know.
if this is the case, then most TAs should be reworked because most of them map the default tag for all authentication events (cf. W...
We have logs in the following format[1]. We created a report with few fields like time, service, operation, method, principle, systemid and count.
But when ever a field is missing in the log, the ...
Because of security reasons, my Splunk server can't be given Internet access. Is there a way to install an Add-on manually on the Splunk console? I have found a solution that suggested to download th...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...