which mode does the splunk forwarder support ? If push or pull mode is all supported, we want to know how to configure the different mode,and the disad...
...| collect index=sec_apps_summary source="savedSearch_1d" And earliest , latest setting as -1@d and @d . There is another SEARCH-2, that invokes the 'saved search' and the SPL starts l...
Is it possible to use collect command to collect data from one index and move it to another, where destiation index is not a summary index ?
index=whatever host=whatever source=whatever w...
I have released an app for Splunk Enterprise. As Splunk Enterprise is kind of on-premise product and runs on customers' local host, I use file log to collect debug logs with reference to h...
I have been unable to get the universal forwarders to correctly collect the SMB Server audit logs. The inputs.conf file on the deployment server has the following stanza configured but there are no l...
Came across an interesting behaviour with collect today depending on whether you specify a sourcetype or not. If you have a field containing a \ character it will escape the \ when using a s...
Hello community,
on my desk, I have a pretty edgy request that is giving me quite a headache.
I would need to collect (with | collect) the output of a search in a new sourcetype created d...
...552aa7f9ebd704a91c8|{authType}|{ "message": { "number": "1856345" }, "transaction": { "sample1": "value1", "sample2": "value2" }}<|<|
I am looking for collecting data from both of above m...
Did i mess something or just compeletly don't understand what collect does. Below is may saved search and conf file, it returns results, it saved as report, it is scheduled seach, and it runs. h...
I have created a collection in app/local/collections.conf a matching lookup in app/local/transforms.conf I have 5 key fields which together for the unique key, the combination of these is also s...