Hi, I am forwarding sysmon logs to splunk, for normalization, I could see event ID : 12, 13, 14 are captured (Registry object added or deleted, Registry value added, Registry value modified) All ar...
I have tags for the name of cameras and then tags for the status of the cameras that I created through eventtypes. Both of these tags are under the same tag category in my data and I want to create a...
Hello Is it possible to style the status_indicator.status_indicator_app in a manner like we can for the
"single value" chart? Can code similar to this be used?
<html> <style> #test ...
...aying "Unexpected close tag" on this line: <query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard&g...
Hi,
I am creating a dashboard where one of the queries is using the rex command. However, in the XML, I am getting the error "Unexpected cloase tage> at the end of the end of the query. T...
Hi what is the rex for "No is invalid. Please ask to a admin" Here is the log: 21:32:26.729 customer modules: type="xsd:string"><response><result>ActionFail</r...
...he actual server was i.e. web server, DB server etc.).
So my question is:
- Can the hosts in Splunk be tagged with metadata to describe their function?
Hey All, I get no results found for a tag that looks for fields created by a rex. So... sourcetype=DataServices | rex "JOB: Job (?<BIMEJob><(?<=<).*(?=>)>)" i get the f...
How many tags can be created before Splunk's performance is adversely affected? And what specifcally is adversely affected when too many tags are defined-- index perf, search perf, or both?
...bsp; searching from a datamodel "malware". I'll attach screenshots of the datamodel. I'll attach a screenshot of the datamodel. I'm assuming my event didn't match because it was not tagged a...