The vector Splunk_hec_log [1] support compression algorithms gzip,snappy,zlib and zstd. It seems the server splunk HEC only supports gzip(I am using docker.io/splunk/splunk 9.2...
Upgraded my clusters from 6.4.4 to 6.5.1 last night. Things appeared okay, but this morning 2 problems surfaced:
scheduled searches are not running on the SHC. If you open the saved search setti...
Hello,
Maybe, it is an easy one and I just did not see it. Basically, I am running the machine learning app to predict a categorical field (OK/NOK).
It worked smoothly and I got some nice pred...
I am using the Quick State visualization to display a greenlight/redlight display for services for my hosts. However the viz doesnt always load when I have it in a dashboard.
It seems to work consi...
Is there a way I can group a window of 3 time points and add it as a field with the last two remaining being ignored?
I'm trying to classify time series patterns using a supportvector machine w...
...ou the IOC matching points. The problem is that the Cisco ESA logs are sent to Splunk in a way that does not allow for easy recognition of all those points in a single "event".
Here is an example...
<search>
<query>index=_internal|stats count by name| eval "Total Count"=case('count'>2800,"severe_".'count','count'<2800 AND 'count'>=2000,"elevated_".'count',true(),"low...
Hi,
We have enabled Application for EUM Browser Monitoring but we are not able to see the data from the Controller UI. We have checked the code snippet for javascript agent that is defined and it ...
We have an On-premise controller configured to access EUM server on the cloud.
Following exception is thrown while the Bowser Application Dashboard is accessed
Failed to connect to the AppD...