Could someone please help me with the Splunk query to configure the alert if Forwarder, Indexer, or search head had restart? @scelikok @soutamo @saravanan90 @thambisetty @I...
...eport_builder_display
enableSched = 1
realtime_schedule = 0
request.ui_dispatch_view = report_builder_display
search = <our search query>
When we repeatedly power off and on the indexer, the number of e...
How to save/configure the DB SQL query input which is returning the Zero rows results at the point of save/configuration in Splunk DB connect app V2. Please provide the solution i.e. without using b...
Dears
I have an urgent Question regarding SPLUNK DB Connect module
we have SPLUNK DB connect module installed on a standalone Virtual machine, we restarted SPLUNK service on this VM. After restart...
...ould help me the better/efficient search query for the same UC?
Usecase: Splunk search to detect when auditing service on any critical system was disabled, stopped or restarted more than once in t...
All Splunk Apps are installed on Linux Servers and we will apply OS patch. And i have 3 Indexers, 4 Search Heads, 1 Deployment Server and 1 Heavy Forwarder (an Indexer Cluster is integrates wi...
I have set up an alert for when logging has stopped on a Windows endpoint using event code 1100, but want to avoid results where logging has restarted soon after being stopped.
Current query: s...
Hello the issue I am having is with the following command: ./splunk restart When I try to restart I get the following message: As Su user:
Failed to run s...