I have Screen 1 for which I have set default time range in viewstates.conf for a user as follows:
[Screen_1:_current]
TimeRangePicker_0_0_0.default = Last 7 days
When Screen Loads for f...
For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table", but only "source", "eventtype" for app B. How can I do this?
I am indexing a CSV file into Splunk and wish to display the row number in a seperate column called 'row count'.
Example:
Field 1 Field 2 Row Count Field 3
blah blah 1 blah
...
We just upgraded to Splunk 5.0 and all of our upgraded saved searches and reports can no longer be deleted or moved via SplunkWeb. Why do we have to remove or move them manually from the server?
...
When you run the following
https://<IP Address of Splunk instance>:<PortNumber>/en-US/debug/refresh
What exactly do you refresh?
E.g. Indexes.conf, reading for new a...
I am trying to modify the 'Overview-Top Clients by IP' search on the dashboard overview page in Splunk for BlueCoat. I go to the 'Apps Manager\splunkforbluecoat-View Configurations\Overview - Top Cli...
...hart/report type used. I looked in the savedsearches.conf file, but there was no reference to the chart type, only to the search string, and some alert based options.
I have flicked through the rest o...
...avedsearch name obviously), but cloning and modifying 400+ times seems wasteful
is there a way to do this using copy/pasta in savedsearches.conf/viewstates.conf?
would i need to manually create vsid values?