Hi,
IThere is an application which is used by multiple teams and we are ingesting the application logs for each team in a single index. Here we want to restrict each team people should be a...
I want to create a bar plot which displays the total number of events on the 1st of every month for the last 12 months. I can't query data for the last 12 months because search timeouts in 5 m...
...hese queries for future reference? I am aware that I could use the Java SDK to extract and aggregate the metrics outside of Splunk, but that approach is not ideal.
Hi, There is an application which is used by multiple teams and we are ingesting the application logs for each team in a single index. Here we want to restrict each team people should be a...
Hi there!
Is there a search command that will allow me to look up results from a "saved result"? I'm looking for ways I could speed up my populating search. My populating search is taking too l...
...ith the results of a search, but in this case the data summary is actually a special summaryindex that is built and stored on the search head. Usesummaryindexingforincreased reporting efficiency s...
...m a bit confued when to use the collect command.
I have configured the search (report) with the summaryindex, but nothing happened...
What am I doing wrong?
Hi,
I have a search that will fetch about 5 GB of application logs. In order not to put load on the Splunk instance and slow search output, i am planning to use "SummaryIndexing" using the new S...
I am trying to make a summaryindexfor data in April 2014.
Using the current default search and joins, and to query more than 25 GB of data takes more than 35 seconds of time.
I want to use a...