...nstead of NULL it just have ",," (no NULL values just two single quotes.). Need the rex command to capture the field in both the case. If event has NULL then need the NULL field and if just two single q...
Hello All,
I am using the Splunk Cisco TA plugin to get all kinds of data from the cisco devices reporting to splunk. I am sending the cisco logs direct from the cisco host to splunk. Is there a wa...
...uestion is:
How do those Splunk's commands work? What type of "technique" do they use to predict, associate or cluster? Is it statistics?
PREDICT = we can do it with algorithms like: ARIMA, Logistic r...
Hi colleagues,
Is there option to add text filter with different type of matching, like it is in Excel (containts, doesnt contain, begginig with, end with, etc.) to dashboard.
I have a json data from file generated from the okla speedtest -f json command. I have tried to cast it or eval in different ways but I am doing something wrong. Error in 'eval' command: Type...
Hi,
I am looking to use predict command with multiple fields without typing all their names.
For example I know it can be used liked this:
Make results |Predict field1 field2 f...
...ass %"-"yest Pass %")|table "dbyest Pass %" "dbyest Fail %" "yest Pass %" "yest Fail %" "Pass % diff" When i ran this , i am getting the error "Error in 'eval' command: Type checking failed. '-' only t...
Splunk's commandtypes page is missing a few functions, including accum. I would like to know if accum is a centralized streaming command, distributable streaming command, or none of the above. E...
...ecause if I remove that section, I can get the non-filtered results. I've played around with including other fields and even using other event types in the search command, always making sure to include a...
Hello all,
I have been trying to use the spath command correctly to create a pie chart divided by type of errors received. When I create the search and click on the object, the field where the e...