hi I have created a tag for the field "counter" called "a" But when I run a search with tag=a or with tag::counter="a", there is no results what is the problem please?
Can you apply transformative operations inside set tags from drilldown tags? ex: <drilldown> <set token="form.builds_tk">$click.value$</set> </drilldown> Would l...
Hi, I am forwarding sysmon logs to splunk, for normalization, I could see event ID : 12, 13, 14 are captured (Registry object added or deleted, Registry value added, Registry value modified) All ar...
Hello Is it possible to style the status_indicator.status_indicator_app in a manner like we can for the
"single value" chart? Can code similar to this be used?
<html> <style> #test ...
...aying "Unexpected close tag" on this line: <query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard&g...
I have tags for the name of cameras and then tags for the status of the cameras that I created through eventtypes. Both of these tags are under the same tag category in my data and I want to create a...
...he actual server was i.e. web server, DB server etc.).
So my question is:
- Can the hosts in Splunk be tagged with metadata to describe their function?
Hey All, I get no results found for a tag that looks for fields created by a rex. So... sourcetype=DataServices | rex "JOB: Job (?<BIMEJob><(?<=<).*(?=>)>)" i get the f...
How many tags can be created before Splunk's performance is adversely affected? And what specifcally is adversely affected when too many tags are defined-- index perf, search perf, or both?