So i want to bulk tag multiple fieldvalues with the same Tag/alias using the SplunkWeb search and not Linux configurations settings. I am trying to tag roughly 800 windows, and 800 linux so thats w...
...ork when I viewed the dataset's values. The docs don't even mention the "named" column so it makes me wonder if I"m doing it right.
I tried to create an alias for CIM app and my src_ip custom field (c...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...
I am looking to alias several field names from multiple sources/hosts with an alias of 'Username'.
When looking in the fieldalias section of splunk manager, there is the option to alias by S...
...OURCE_KEY = field:lineobj
DEST_KEY = _raw
REPEAT_MATCH = true
The above succeeds in extracting the json field/values out of 'line' - the 'lineobj' field appears in the fields list inSplunkWeb...
I do use eventtypes.conf to extract fields.
Then intags.conf I do set warning=enable for some of the fields.
Some is error and other is information.
In my search, this then shows up as e...
I've indexed some web server logs and than I've assigned a tag to the status field, so I can receive the tag name instead of the http status code. It' works correctly on splunkweb: I can see for e...
Now i very interested with command Spath of Splunk, can auto extract values JSON. But i can't extract it to fieldinindex, sourcetype ?
Example: Raw json infield src_content:
index=web s...
...est practices to manage entities in this case. 1. Should I have created 2 other entities with different aliases? That is the second one E2 which has alias "hostname=web01" and E3 w...