I have a number of saved searches scheduled to run each morning. However, I have a dashboard that allows certain configuration items to be changed in the app, which then would require those saved s...
...ookup and used the following query | rest splunk_server=local /servicesNS/-/{app_name}/saved/searches
| fields title search eai:acl:owner eai:acl:app alert_type u...
...do not have enough points to post links
It was working great with Splunk seeing thefields and stripping them out for the "Interesting Fields" section. We wanted to modifytheRESTAPI call and a...
Hi all,
Since the ITSI entities import in CSV through search-based results has a setting only for upsert or append.
How to delete/remove itsi entities which we won't get/don't see in the s...
...uery theAPI via the command below to grab the information but I hope there is an easier way.
| rest /services/authentication/current-context splunk_server=local | fields username
I've also r...
...ALUES (?,?,?,?,?,?)" SQL_CODE=1861 SQL_STATE=22008 STATE=completed
After some research I realized this error has to do with the Oracle Date Column. I am formatting the first column as a
Date Time field...
...eceives through STDIN ?
But my primary concern is how to force theRESTAPI /services/data/inputs/ endpoint to edit the right inputs.conf (the one it gets thefields from) instead of reaching for the...
We have recently upgraded to Splunk 6.6.6 from 6.5.2. After the upgrade completed we started having issues with one of our SideView dashboards that is used to modify single records on a lookup t...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...