I have a number of saved searches scheduled to run each morning. However, I have a dashboard that allows certain configuration items to be changed in the app, which then would require those saved s...
...ookup and used the following query | rest splunk_server=local /servicesNS/-/{app_name}/saved/searches
| fields title search eai:acl:owner eai:acl:app alert_type u...
Hi all,
Since the ITSI entities import in CSV through search-based results has a setting only for upsert or append.
How to delete/remove itsi entities which we won't get/don't see in the s...
...uery theAPI via the command below to grab the information but I hope there is an easier way.
| rest /services/authentication/current-context splunk_server=local | fields username
I've also r...
...eceives through STDIN ?
But my primary concern is how to force theRESTAPI /services/data/inputs/ endpoint to edit the right inputs.conf (the one it gets thefields from) instead of reaching for the...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...