...o copied version prior to relocating to $SPLUNK_HOME/etc/system/local for distribution.
Issue ---
I observe that in the default indexes.conf there is a globalsetting for repFactor = 0 (no r...
Can someone confirm if there is a way to set a token in Dashboard Studio "in the background"? In classic you could set a token in the source using <init> <init>
<set token="c...
All, Hopefully a straightforward question. Is it possible to increase the following setting in a .../appname/local/limits.conf such that the scope remains localand pertinent only to that a...
...hese are all Server 2019 machines.
I have verified inputs.conf is pointing event logs to index:wineventlog but that index locally has 0 results and about 112,000 results on the cloud server.
I'm s...
...ync" behavior.
What I've tried
I've studied the "Pan and Zoom Chart Controls" example, but that doesn't update the time picker.
I'm using a global time picker that defaults to "All time":
&l...
So this is a bit puzzling, There doesn't seem to be an option to setdefault panel options for the entire dashboard?
for e.g. charting.legend.placement to be set to bottom for all charts
or h...
I have a local indexes.conf file on all my indexers:
[default]
frozenTimePeriodInSecs = 63072000 # 2 yr
[main]
frozenTimePeriodInSecs = 15552000 # 180d
T...
...pps/a/default/savedsearches.conf
[default]
allow_skew=15%
And then a add specific configuration in app b to override the globaldefault (apps/b/local/savedsearches.conf...
...tructured
description = Cloudlock incident aggregate
I confirmed that the settings are as expected with splunk btool props list--debug
/opt/splunk/etc/apps/all_whirlpool_transforms/local/p...