Are Smartstore buckets uploaded to S3 immutable? We've been using Smartstore for almost a year and I have never seen an update to a bucket after its original upload to S3. Can anyone c...
We have create HTTP event collector event using postman through Rest API. Also we have few events created by uploading log file on our splunk enterprise instance. Is update possible on e...
Hi all, Does anyone know of any way to update an event in Splunk? so far what my searches brought me was reindexing the event, then deleting it with the delete command, and then reindex the whole b...
...earch on that through the (default) search window)
From what i've read, I understand that once the data is written, its immutable, but that an automatic lookup might help me out?
Grateful if someone c...
I'm trying, as an admin, to delete a couple of lookups, but I don't see a way to do it via the interface. Is there a way to do it? I'm not the owner of them ...
It's interesting that for some of t...
Hi everyone. I have logs that are sent to me in Central Standard Time (-6 hours) but there isn't anything in the TA noting that, so all my logs look like they are 6 hours behind.
As such, I went ...
My goal is to replace the host in WinEventLog events with the ComputerName field. The data is being forwarded from an UniversalForwarder and on the indexer these config files were used:
$splunkhom...
...o what looks like a random string.
Trying to outsmart it, I set outputs.conf on the forwarder and inputs.conf on the indexer with the immutable flag. (chattr +i outputs.conf) and I can see the e...
I have configured heavy weight forwarders to get the JMX server data. While forwarding the data to indexers, source field displays the path of those servers. I want to reduce the unwanted strings and...
Let's say I have an index that contains events with cleartext passwords. I can delete those events and they are no longer searchable in the UI, but the raw data still exists in the journal.gz file. I...