Activity Feed
- Posted Splunk Cloud - props.conf setting for changing TZ to AEST for my events data in UTC format on Getting Data In. 08-12-2021 11:57 PM
- Posted Re: Unable to update email address in my Splunk Account profile on Security. 05-09-2021 10:39 PM
- Karma Re: SPLUNK License master down - what is the impact ?? for esix_splunk. 06-05-2020 12:48 AM
- Karma Internet Explorer 9: Why panels only display "Loading Events" when drilling down in reports? for garryclarke. 06-05-2020 12:47 AM
- Karma How to reuse the count from a previous search to calculate a percentage in a second search or combine the two searches? for otman01. 06-05-2020 12:47 AM
- Got Karma for Splunk Field values are visible in URL. How can we hide them?. 06-05-2020 12:47 AM
- Got Karma for Is there any way to fill my summary index with only the newer portion data every day from the raw index?. 06-05-2020 12:47 AM
- Got Karma for Why is my custom sendemail script not working in Splunk 6.1.2 and not showing any errors?. 06-05-2020 12:47 AM
- Got Karma for What path do I use to add new files, images, and fonts to load on a dashboard?. 06-05-2020 12:47 AM
- Got Karma for How to give time modifiers to run the search query from yesterday morning 5 am to today morning 5 am ?. 06-05-2020 12:47 AM
- Karma Re: can i dynamically change the label in the form ?? for sideview. 06-05-2020 12:46 AM
- Karma Re: rex word extraction? for alacercogitatus. 06-05-2020 12:46 AM
- Karma Re: How do i get Unique events for my search keyword for kristian_kolb. 06-05-2020 12:46 AM
- Karma Re: regex help for timestamp extraction from event log for MuS. 06-05-2020 12:46 AM
- Karma Re: stats usage to display output as follows for alacercogitatus. 06-05-2020 12:46 AM
- Karma Re: can i have a trend line graph on a bar graph ?? for Gilberto_Castil. 06-05-2020 12:46 AM
- Karma Re: Can we disable the inspect link from the search results ?? for yoho. 06-05-2020 12:46 AM
- Karma Re: eventtypes combination for jerrad. 06-05-2020 12:46 AM
- Karma Re: Module Hiddensearch help for sideview. 06-05-2020 12:46 AM
- Karma Re: Need Solution for stats command for ziegfried. 06-05-2020 12:46 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
12-15-2015
03:44 AM
1 Karma
Hi Splunk team,
I have a scenario where i have a raw index and a summary index, and a scheduled search which is used to populate data from the raw index to summary index. My scheduled search runs on daily basis and fills the summary index, and every thing is working fine as expected.
Now here the problem is for Eg . if my raw data is updated with the newer portion of data on already passed days, I need to fill this as well in the summary index which I tried a backfill script for, but it give me proper results.
Example :
index="main" -- raw index
index="summary" - summary index
Assuming the main index has only Dec 12th data i.e with _time Dec 12th and summary generating search ran on dec 12 th and populated all the 12th data in summary index.
Now lets say Dec 15th , I had a few more data of Dec 12th which has come now from the forwarder and it has gone to the "main" index for Dec 12th. Now my issue is to fill in this newer portion of data in the summary index.
I have tried backfill and re-run the searches, but every time it's creating duplicates. I used the nolocal option as well, but no luck.
Any way to fill only the newer portion of data every time to a summary index?
manythanks,
Rakesh.
... View more
12-15-2015
02:33 AM
option -nolocal true is taking lot to time to execute and its degrading the splunk performance on the server. is there any better way to achieve this. thanks
... View more
08-19-2015
02:21 AM
Hi All,
I am using Splunk version 6.1.2 and running a simple search with index name. My search is resulting 27 lakh events for last 30 days, but it's taking too much time for execution. It's almost taking 2.03 minutes to execute the search, which I feel is a bit slow. Is this retrieval time good or bad? I definitely feel the customer experience would be not good letting the customer wait for 2 minutes to get the results.
Now even when I tried adding required fields to the search to get the exact results, 2 minute window is increasing and not reducing. Can anyone help why Splunk is taking this much time to return search results?
I have used the following search.
index="summary"
thanks,
Rakesh.
... View more
07-22-2015
05:43 AM
hi bmacias84,
can u specify where we will have this static folder ..
i mean can u give the path from the base splunk installation location.
Thanks,
Rakesh.
... View more
07-21-2015
07:09 AM
1 Karma
Hi ,
I have custom fonts for my dashboard and added the same in my app in the below path.
/opt/splunk/etc/apps/MY_APP/static/fonts/BTFont_Rg.ttf
but when I run the dashboard, it is not able to load the fonts and throwing a 404 errror when looked in Firebug. Can u please suggest the appropriate path to put the fonts folder?
//error i am seeing in Firebug
NetworkError: 404 Not Found - http://localhost:8080/en-GB/static/@255606/app/fonts/BTFont_Rg.ttf
... View more
06-18-2015
06:51 AM
Not only rest-api search command . even a simple dashboards with a search is not displaying anything..its showing the message populating the search ... etc .but giving me any search results.
... View more
06-17-2015
05:27 AM
Hi All,
I have configured Splunk SSO configuration with siteminder for my application. All the siteminder configurations and splunk configurations looks fine, and I am able to access my application via siteminder URL without any error in Mozilla, but when comes to Internet explorer i am not able to see any data in the drop-downs.
My drop-downs will use the REST API interface commands to list different roles based on the user login, but this is not working in internet explorer. By the way, the Splunk version I am using is 6.2.2 and Internet explorer version is 11.
REST API command which is not in working in I.E alone is
| rest /services/authentication/current-context | table username,roles
Is there any configuration or cache issue with internet explorer? The same is working fine in Mozilla.
Any help on the above scenario would be appreciated.
Thanks,
Rakesh.
... View more
06-03-2015
03:53 AM
Can i forward data from single UF to 2 different indexers. same data in 2 different index groups. ?? is this possible.?
... View more
03-30-2015
02:08 AM
No vincenteous... i am using this configuration at indexer .
... View more
03-27-2015
07:10 AM
Hi Laya123,
Can you post sample log here. basically your interested in knowing the time difference b/w the page1 and page2 right ?
Rocky
... View more
03-27-2015
06:34 AM
Thanks for the update stephan. but this seems not working below is my configuration.
// inputs.conf
[monitor:///opt/splunk/splunkInput/mylog_sample.txt]
disabled = false
followTail = 0
recursive = false
sourcetype = temp
index = myindex
// transforms.conf
[set_group1_routing]
REGEX = XXX
FORMAT = sourcetype::group1
DEST_KEY = MetaData:Sourcetype
[set_group2_routing]
REGEX = YYY
FORMAT = sourcetype::group2
DEST_KEY = MetaData:Sourcetype
// props.conf
[group1]
TRANSFORMS-350_routing=set_group1_routing
DATETIME_CONFIG = CURRENT
MAX_TIMESTAMP_LOOKAHEAD = 150
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = false
[group2]
TRANSFORMS-350_routing=set_group2_routing
DATETIME_CONFIG = CURRENT
MAX_TIMESTAMP_LOOKAHEAD = 150
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = false
Help me if am missing something. thanks in advance 🙂
... View more
03-26-2015
06:02 AM
Hi ,
I have a single source which has a huge number of events. These events are broadly classified into two groups and all are present in the same file single file. Now, my requirement is to get the file indexed into a single index as called "myindex" and have two different sourcetypes "group1" and "group2". group1 and group2 category in the file is distinguihsed with the help of the keyword XXX and YYY in my log file.for example XXX denotes group1 and YYY denotes group2.
Here is the sample of log file.
// mylog_sample.txt
24-08-2014 10:23:34 12e,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:35 12e,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:36 1w2,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:37 12e,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:39 122,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
25-08-2014 10:23:34 12e,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:35 12e,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:36 1w2,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:37 12e,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:39 122,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
All the data is present in the same file. Now i want to split the whole data into two different sourcetypes "group1" and "group2" in a single index.
so if i search the data with:
index="myindex" sourcetype="group1"
it should list the following data ..
24-08-2014 10:23:34 12e,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:35 12e,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:36 1w2,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:37 12e,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
24-08-2014 10:23:39 122,34,56,67,87,90,123, 34,545,45,XXX,56,5768,342,34456
and if I search with the following:
index="myindex" sourcetype="group2"
it should list the following data ..
25-08-2014 10:23:34 12e,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:35 12e,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:36 1w2,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:37 12e,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
25-08-2014 10:23:39 122,34,56,67,87,90,123, 34,545,45,YYY,56,5768,342,34456
Any help on the above use case. I used to transforms.conf, but no luck on separation. Please post the proper configuration that helps and suits the requirement.
Many thanks.
Rakesh.
... View more
02-17-2015
04:14 AM
Hi All,
I was having a requirement to enable / disable table element drilldown. i mean if my SH is a Job server i would enable the drilldown option for table elment and should disable the option if its a Search head.
I have used the following code snippnet . but this not working . Can you please help me ? where am i going wrong ??
// Sample code
var element1 = new TableElement({
"id": "element1",
`"link.exportResults.visible": "true",
"link.inspectSearch.visible": "false",
"link.openSearch.visible": "false",
"drilldown": "row",
"rowNumbers": "true",
"managerid": "search1",
"el": $('#element1')
}, {tokens: true}).render();
if(host ="JobServer") {
element1.settings.set("drilldown","row");
}
if(host ="SearchHead") {
element1.settings.set("drilldown","none");
}
Please help me !! Thanks in Advance 🙂
... View more
02-03-2015
04:52 AM
Hi Team,
When ever splunk dameon (splunkd) process was down , Splunk is reporting the "splunk daomen error page and giving a link to return to Splunk Home Page" . We are looking at a requirement to modify or edit this html page. Can you anyone help us where this html page located in the server.
I have tried searching but couldnt able to find the error html page , that is been shown when splunkd was down.
Thanks for ur help in advance !!
Rakesh.
... View more
- Tags:
- splunk
11-25-2014
02:13 AM
custom script log ?? where can i find that ??
... View more
11-24-2014
02:05 AM
1 Karma
Hi ,
I am using Splunk 6.1.2 version, I have a requirement to add custom messages to the sendemail.py script like adding a logo etc. I have modified the script and kept in the script in my app directory "MYAPP/bin/local_sendemail.py" . local_sendemail.py is the script edited by me.
point here is this seems to be not working in Splunk 6.1.2 version . I have included the following in commands.conf as well as below.
// commands.conf settings
[sendemail]
filename = local_sendemail.py
streaming = false
run_in_preview = false
passauth = true
required_fields =
changes_colorder = false
supports_rawargs = true
I have used the same earlier in Splunk 4.3.2 and it's working. Now modified the existing latest script in Splunk 6 and its not working.
Is commands.conf deprecated in Splunk 6.x , or is there is something i need to do to make the script work?
earlier question w.r.t splunk 4.3.2 posted by me
http://answers.splunk.com/answers/95735/sendemail-external-search-command-sendemail-returned-error-code-1.html
Present script in splunk 6.1.2 is not even throwing any error. Can someone help me on this?
Thanks.
Rakesh.
... View more
11-20-2014
11:01 PM
The following appoarch is working fine in Splunk 4.3.2 , but the same has not been working in Splunk 6.1. I have updated the latest sendemail.py python script. but still no luck. is any one faced the same problem ?? splunk 6.1 is not supporting commands.conf behaviour to run own sendmail.py script ??
... View more
10-08-2014
01:17 AM
I was looking for generic timestamp Mus. Thanks for ur reply.. 🙂
... View more
10-08-2014
01:16 AM
Great tom.. missed this + sign.. thanks 🙂
... View more
10-08-2014
12:47 AM
1 Karma
Hi All,
Can anyone help me on the time modifiers ... for giving the earliest and latest for yesterday morning 5 am to today morning 5 am.
earliest=-1d@5h latest=-0d@5h but this doesnt work
thanks.
... View more
- Tags:
- earliest
09-23-2014
07:16 AM
Still no luck mario M .. 😞
... View more
09-23-2014
03:59 AM
Hi ,
I have a created a role called "userrole" and have imported the default "user" role capabilities and added the "change_own_password" to the capabity.
i.e below is the sample
[role_userrole]
importRoles = user
change_own_password = enabled
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
search = enabled
srchIndexesAllowed = _internal,_audit
srchMaxTime = 0
Now i have created a user called "rakesh2" and assigned the above role "userrole" . Once logging with the below user "rakesh2" and clicking on the edit account to change the password.. its not all showing me any data.
i am getting the below screen ..
alt text
Can anyone suggest ..is this a bug in 6.1.2 or am i missing something ??
... View more
- Tags:
- authentication
- issue
06-24-2014
05:58 AM
hmm.thanks splunk12er. i was asking about the logo /text on the left side which is highlighted in the screenshot.
i have used the following setting in application.css but didnt work.
a.brand {visibility:hidden; display:none;}
... View more
06-20-2014
05:36 AM
Hi ,
I want to cusomize the splunk logo and menu screens which are highlighted in the screen. I mean i dont to show Mesasges,Settings,help menu items in the SPLUNK GUI. How can i customize them ? Can i have the notes or startin point to do this pls.
Attached the screenshot, highlighted the parts i need customization.
... View more
06-19-2014
04:18 AM
Hi Splunker12er. i guess you got my requiremnt wrong. i dont want the label namevalue inside the dropdown list. If you see my code above i am able to create a drop down with the following data i.e All as "", ItemId1 as "23" ,ItemId2 as "33" and ItemId3 as "43" . Here All,ItemId1,ItemId2 and ItemId3 are the Label names which i show to user , and internal i pass the values associated to it . ie. 23,33,43 or "" . now my problem is i have a html module to show the heading the user something you selected so and so item. to give this heading i need the above requirement.
... View more