How do I merge the below 2 complex queries? Let me know if it's possible in Splunk? Search 1: -
index=ABC (eventtype=X OR eventtype=Y) log_subtype=DEF field_A="*SQL*"
|...
...he SID of the base search, and I'm looking to access the SIDs associated with the extended search queries within the chained search. How can I effectively retrieve the SIDs for each component of the c...
Hi, this issue has been mentioned here before but still my changes in props.conf are not effective.
Here is the configuration I'm using :
Inputs.conf :
[default]
host = bb1322454b5f
s...
1) There are some features that are in the paid version but not in the free version.
For example, the function to set up automatic sending of PDF file by mail, the setting of a role, the setting of...
I am trying to extract only the top values from fields such as argument, uri, and method for the WAF log. Currently, it is configured using a join statement, but the search speed is very slow, so...
I am having trouble understanding whether there are any issues caused by violating a non enforcement license. All Splunk enterprise editions after 6.5 have a non-enforcement license automatically. Yo...
Hello everyone, I was updating our licenses and I am still new to Splunk, so I accidentally deleted the auto_generated_pool. I recreated the pool to match the auto_generated_one, but I would j...
I am in desperate need to figure out what I'm doing wrong with this props config. Currently I am bringing in logs via syslog-ng that then get written to disk on a heavy forwarder. I push several co...
Hello,
I am trying to merge two charts together. Both charts have two dimensions each with one common dimension - making three total.
Following the advice given in link text, I use the follow...