Are Smartstore buckets uploaded to S3 immutable? We've been using Smartstore for almost a year and I have never seen an update to a bucket after its original upload to S3. Can anyone c...
I want to create a 30 day index of data that changes it's indexed timestamp as each day passes. Therefore the data will always show up when I do a last 30 day search and don't need to pick out the sp...
...? Is there another package I should be using? Any help will be greatly appreciated. I also tried with Splunk Client v2.2.7 and immutable v1.4.0 with the same results.
I tried to tag with S...
Hi all, Does anyone know of any way to update an event in Splunk? so far what my searches brought me was reindexing the event, then deleting it with the delete command, and then reindex the whole b...
We have create HTTP event collector event using postman through Rest API. Also we have few events created by uploading log file on our splunk enterprise instance. Is update possible on e...
...earch on that through the (default) search window)
From what i've read, I understand that once the data is written, its immutable, but that an automatic lookup might help me out?
Grateful if someone c...
hello, we have some raw data with one field wrong from April. But we cannot reload data from the source. Is there any way that we can modify only one field? for example: _time id name&n...
I'm trying, as an admin, to delete a couple of lookups, but I don't see a way to do it via the interface. Is there a way to do it? I'm not the owner of them ...
It's interesting that for some of t...
hi phantom team, I have a simple use case to rename a filename in vault. As its immutable, I copied the contents to vault temp dir and renamed it there. And before adding the renamed file into v...
My goal is to replace the host in WinEventLog events with the ComputerName field. The data is being forwarded from an UniversalForwarder and on the indexer these config files were used:
$splunkhom...