...ut I would like for the attributes of an event that have a json format to be further decomposed into fields.
This is an example of an event:
I would like for the `attributes.data` field to b...
Hi, can I ask you for helping me with this small problem, please?
If I read the content of the lookUp using any criteria I receive attribute Attr1. This Attr1 is multivalue attribute.
Attr1
7...
I need to run a daily ldap search that will grab only the accounts that have change in the last 2 days. I can hard code a data into the whenChanged attribute. &n...
Hi,
I am trying to create a navigation menu with HTML href attribute as follows:
<nav color="3075AB">
<collection label="My Label">
<a href="/app/myappname/f...
This is the original link. Anyone know where this has been moved to?
http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F
It describes all of the props.conf attribut...
We have thousands of Universal Forwarders (UF) in a large virtual desktop environment where we need to minimize the footprint and particularly the I/O as much as possible.
Question is for WinEvent...
I have basic web logs with username and jsessionid. I want to group (assume a single index, with one set of data). So thousands of events. I want to group by jsessionid and username - creating...
Here are the screenshots: In incident review setting, I have already labeled signature: Then in Correlation Search content setting, also I have setting the search query which could result in fi...
[monitor:///tmp/ABC.txt] is my monitor stanza.
But if i have the file welcomeabcdef.txt that is "abc" (lowercase instead of uppercase) will it be read and indexed by Splunk?
...t;/unitData>
Before indexing I would like to create new additional attribute machine which should have value depended of these conditions:
case equipment="W052A-22G0014" machine =machine1
c...