Activity Feed
- Posted Re: Okta SAML authentication error on Security. 09-18-2020 02:10 PM
- Got Karma for Re: How to change table header after using transpose command?. 06-05-2020 12:47 AM
- Posted Re: need to route data to nullqueue based on index on Splunk Search. 05-08-2018 03:08 PM
- Posted Re: need to route data to nullqueue based on index on Splunk Search. 05-02-2018 07:28 PM
- Posted Re: need to route data to nullqueue based on index on Splunk Search. 05-02-2018 03:45 PM
- Posted Re: need to route data to nullqueue based on index on Splunk Search. 05-02-2018 03:15 PM
- Posted need to route data to nullqueue based on index on Splunk Search. 05-02-2018 02:40 PM
- Tagged need to route data to nullqueue based on index on Splunk Search. 05-02-2018 02:40 PM
- Posted Re: Why do I see a count difference running a saved search via Splunk REST API call and running the search manually? on Splunk Search. 01-23-2018 12:00 PM
- Posted Re: Is it possible push notifications to Splunk mobile app even after user logs out of splunk app? on All Apps and Add-ons. 10-20-2016 03:29 AM
- Posted Re: Is it possible push notifications to Splunk mobile app even after user logs out of splunk app? on All Apps and Add-ons. 10-19-2016 11:34 PM
- Posted Is it possible push notifications to Splunk mobile app even after user logs out of splunk app? on All Apps and Add-ons. 10-19-2016 03:52 AM
- Tagged Is it possible push notifications to Splunk mobile app even after user logs out of splunk app? on All Apps and Add-ons. 10-19-2016 03:52 AM
- Tagged Is it possible push notifications to Splunk mobile app even after user logs out of splunk app? on All Apps and Add-ons. 10-19-2016 03:52 AM
- Posted Re: How to change table header after using transpose command? on Splunk Search. 10-12-2016 11:27 PM
- Posted Re: How to transpose a table to make the values in Column 1 the header labels? on Splunk Search. 10-12-2016 11:23 PM
- Posted Re: Where did the download links for wget go on splunk.com?! on Installation. 08-18-2016 02:33 AM
Topics I've Started
09-18-2020
02:10 PM
I have the same issues. Issue is fixed by correcting the EntityID in my saml configurations.
... View more
05-08-2018
03:08 PM
doing this using host stanza.
... View more
05-02-2018
07:28 PM
I tried the props stanza with index and it didn't work. Looking for other approach to achieve this.
... View more
05-02-2018
03:45 PM
For sourcetype: though they have the common sourcetype, PROD index is also using the same sourcetype. Hence, dropping the data using soucetype will drop the prod data with matching pattern. Hence this is ruled out.
For host: the combination are too many and it is going very complex.
... View more
05-02-2018
03:15 PM
yes, to be more clear.
I want to drop all the events with string ERROR in it from set of indexes whose starting string is QA
... View more
05-02-2018
02:40 PM
Hi,
I need to route the index data to null-queue based on the strings from the events. For example, all the events that contain string pattern "Error" from all the QA* indexes should to routed to nullqueue.
Doing it with host and sourcetype is very complex. Can someone suggest me with solution?
... View more
- Tags:
- splunk-enterprise
01-23-2018
12:00 PM
HI,
I am facing the same issue. How did you solve this issue?
... View more
10-20-2016
03:29 AM
Exactly, I mean the first scenario. In this, there are two cases.
User logged in and the mobile app is running on background.
User logged in and after some time mobile session was killed either by users/system.
Requirement: In both the cases user should receive notification.
I tested the case one and the test was successful. I am able to get the notification alert.
2nd test was failed. When I killed the splunk background program/session on my mobile, Notification alerts were stopped. I am not sure if this has something to do with SSO.
When I was checking the documentation for "Splunk® Add-on for Mobile Access Installation and Configuration" (http://docs.splunk.com/Documentation/MobileAddon/2.4.0/Install/SSOConfiguration)
I ignored the SSO part and jumped into "configuring of mobile app".
... View more
10-19-2016
11:34 PM
Hi,
I agree with your point.
Let me re-phrase my question.
I have some users who will be using the mobile app to check the business statistics through some measures. We have created dashboards for same. Users cannot keep on monitoring the mobile dashboards 24X7. And so, alert notifications should be sent in case of critical alerts even when they are logged out of mobile app.
Can you guide me achieve this?
... View more
10-19-2016
03:52 AM
Greetings,
I have configured splunk alert notification to mobile app. Alerts are only triggered when the user is logged-in to mobile app. Is there a way to trigger the alert to mobile app irrespective of user's login?
... View more
10-12-2016
11:27 PM
1 Karma
https://answers.splunk.com/answers/345937/how-to-transpose-a-table-to-make-the-values-in-col.html?sort=newest
use transpose header_field=
... View more
10-12-2016
11:23 PM
Hi,
Thank You Very much. "transpose header_field=a" worked.
... View more
08-18-2016
02:33 AM
for 6.4.2 version, following are the links.
wget -O splunkforwarder-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=6.4.2&product=universalforwarder&filename=splunkforwarder-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm&wget=true'
wget -O splunk-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=6.4.2&product=splunk&filename=splunk-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm&wget=true'
,For splunk 6.4.2 version following are the links.
wget -O splunkforwarder-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=6.4.2&product=universalforwarder&filename=splunkforwarder-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm&wget=true'
wget -O splunk-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=6.4.2&product=splunk&filename=splunk-6.4.2-00f5bb3fa822-linux-2.6-x86_64.rpm&wget=true'
... View more