I just discovered the interesting noop command and have been playing around with it. I cannot find it mentioned ANYWHERE! I was hoping that it would take a single string parameter so that it w...
I am trying to optimize the query speed of the db connect app . I have read the following post, it tell me I can use | noop search_optimization=false , but splunk return an error when I using....
...o the right URL, I get a search screen with the search of noop (no OP) I guess.
How do I fix #1 and what can I do about #2 since it is not showing the report that it should?
Thanks
Chris
I'm trying to implement the Splunk Machine Learning Toolkit Query, found here: https://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_g...
This seems to be a very simple requirement, but I'm unable to find a solution: I built a dashboard where the user enters an ip address which will then be used in a search like:
dest=$ip$
Now...
Each log entry contains some json. There is a field that is an array. I want to count the items in that array.
Example json data
{
"field1": "sample",
"messages": [
"noop...
Hi Splunkers,
Why the relative_time function is not converting +24y? any reason? Any way to achieve this?
|stats count | eval next_time=relative_time(now(),"+24y")
Is there any limitatio...
We are working with several remote datasets that are combined to give our end user a specific result.
Federated Search gives us an LDAP dn, which we are trying to use to pull enhancing inform...
Hi guys i have a gauge chart which normally will display values. however i encounter issues when there is no value, how should i resolve it? i try with "noop" it seem like no working. Mind to s...
...hat the first search adds a "| noop" to the normalized search just before the "|search abc":
| search (tag=attack tag=malware (index=* OR index=_*) (index="estreamer" OR index="pan" OR index="t...