Hi
I am trying to retrieve data from summary index and it is taking 300secs to retrieve 140000 eventsfrom 4 search peers.
index=summaryindex earliest=-7d@d latest=now (240000 events t...
I have a search query which uses dedup to get the latest eventfrom my source type.
Search:
sourcetype = MonitorLog | dedup Username | WHERE SecondsElapsed >= 300
Username, A...
I able to retrieve Windows event logs from remote machines using WMI, and I'm also indexing local Windows event logs. I like to organize the events coming from the local system and from remote s...
The metadata command does not work for virtual indexes used by Hunk.
My goal is to get a list of values from items enclosed in ${}'s within the v-index path (which are extracted as fields). With t...
Hello,
I trying to retrieve all login/off/fail on my inderxer from UniversalForwarder filtered by Heavy forwarder :
UF v5.0.5 (All Security logs) > HF v5.0.5 (Filtering only 4642/4625/4634 events...
Good morning,
We have an splunk architecture with 2 Search Heads and 2 Indexers.
This morning when our user tried to look for today's logs from the SearchHead, he could not retrieve any data. C...
We recently had an issue where Splunk services were up and running, but new data wasn't being indexed. I'd like to capture data on the LATEST EVENT or INDEXED count with HP SiteScope and report it t...
...he base transaction I'm looking for.
The first index also has a field called ip. What I want to do is use this field to retrieve the eventsfrom the third index into the first transaction (u...
...1/05/2017 EE Epsilon Edition
Now, we see that the value for the key EE changes twice.
For events coming from an index, I have _time and a field called 'Name'.
Like this.
index=event...
...A first step would be to get data from both indexes in the final list of events (or at least from the back_index as this is from there that I will get the details I want).
And I can't figure why I c...