...his?
Depending on the time range involved, the base search might return many thousands of events. eval and dedup might not be the most performant choices.
Advice, recommendations welcome.
...think I would need to combine several sub searches for relative times, the first Top10 and the subsequent datasets. Not sure If I moved myself into a dead end here, so any suggestions are welcome....
...ind of suspect I should combine the IIS search into the high-CPU subsearch (reference both indexes) but I'm having a hard time wrapping my head around how that would work. As a side note, p...
...ocal/props.conf file on thesearch head, because that was the only place where i could find a referencetothe monitor i've added.
[mylog-too_small] SHOULD_LINEMERGE = false LINE_BREAKER = ([\r\n...
...ashboard before any search fields etc.
I have also created a reset dashboard button so that I wish to display AFTER the submit button. Is this possible?
Please view the attached image for reference...
...nd Reporting app, there is a lookup_table and lookup_definition, both of which have permissions set to Global (all apps), Everyone can Read. However, the dashboard panels in my custom_app which reference...
Im fairly new to splunk (and linux for that matter) but I am trying to find a Web Page or Manual or whaeter that will list all the possible search commands/strings I can use tosearch through event l...
There used to be a Splunk2Nagios application that came with Splunk, and it worked very well. When 4.x was released it was still possible to get most of the functionality of this plugin working w...