So i want to bulk tag multiple fieldvalues with the same Tag/alias using the SplunkWeb search and not Linux configurations settings. I am trying to tag roughly 800 windows, and 800 linux so thats w...
...alias iis : FIELDALIAS-host/cs_host AS host]
I have resorted to the test data in samples iis.log
Does any one know if this website config will work for the test data? or any other p...
...ork when I viewed the dataset's values. The docs don't even mention the "named" column so it makes me wonder if I"m doing it right.
I tried to create an alias for CIM app and my src_ip custom field (c...
...OURCE_KEY = field:lineobj
DEST_KEY = _raw
REPEAT_MATCH = true
The above succeeds in extracting the json field/values out of 'line' - the 'lineobj' field appears in the fields list inSplunkWeb...
...roblem is compounded by the fact that the extracted signature_id field is leveraged in all the eventtypes andtags within the TA too.
The field is really simply based upon EventCode, which is a n...
Now i very interested with command Spath of Splunk, can auto extract values JSON. But i can't extract it to fieldinindex, sourcetype ?
Example: Raw json infield src_content:
index=web s...
...est practices to manage entities in this case. 1. Should I have created 2 other entities with different aliases? That is the second one E2 which has alias "hostname=web01" and E3 w...
I am looking to alias several field names from multiple sources/hosts with an alias of 'Username'.
When looking in the fieldalias section of splunk manager, there is the option to alias by S...
I've indexed some web server logs and than I've assigned a tag to the status field, so I can receive the tag name instead of the http status code. It' works correctly on splunkweb: I can see for e...
I do use eventtypes.conf to extract fields.
Then intags.conf I do set warning=enable for some of the fields.
Some is error and other is information.
In my search, this then shows up as e...