MetricWorkspace doesn't seem to show a way to initially limit on index. I now have many metric indices and have duplicate metric names that make it impossible to use theworkspace without filtering....
Hi, I am trying to install "SplunkMetricsWorkspace" for Splunk Cloud following docs.splunk.com/Documentation/SMW/1.0.1/Use/Install#Install_the_Splunk_Metrics_Workspace_on_Splunk_Cloud. However I c...
How do we move towards themetrics usage? Will it replace the conventional log file ingestion? How does it work for an existing standard implementation? Will it replace the existing log file collection?
Hello all, How to add another column from the same index with stats function? | makeresults count=1 | addinfo | eval days=mvrange(info_min_time, info_max_time, "1d") | mvexpand days | eval _...
Not working SEDCMD in my props.conf /opt/splunk/etc/system/local/props.conf [ActiveDirectory] SEDCMD-mask_ms_pwd = s/(ms-Mcs-AdmPwd\s*=)\s*.*/ms-Mcs-AdmPwd=*******/ &n...
I need to get the list of .conf files. On running my below Splunk Query,
"| rest /services/configs/conf-props"
it returns the conf objects, but I need to find the .conf files instead of o...
I have an event that comes to the index. | search index = indexname filed1 field2 field3 I need to write an exception that will discard the field before g...
Hello colleagues. we recently switched from Splunk HF to UF. before this event with sourcetype = MSWindows:2012:IIS. parsed normal but after installation, something went wrong. and events in the s...
...nputs.conf. i ran the command /opt/splunk/bin/splunk reload deploy-server -class heavy_forwarders for the changes to be accepted the file comes to the index, but it does not start up some w...