Activity Feed
- Got Karma for How to optimize a search performance of a slow, composite search. 11-18-2020 04:52 AM
- Got Karma for How to optimize a search performance of a slow, composite search. 06-05-2020 12:47 AM
- Got Karma for How to optimize a search performance of a slow, composite search. 06-05-2020 12:47 AM
- Got Karma for How to optimize a search performance of a slow, composite search. 06-05-2020 12:47 AM
- Got Karma for Is it possible to get the time it took to search from a SearchManager?. 06-05-2020 12:47 AM
- Got Karma for Re: Is it possible to get the time it took to search from a SearchManager?. 06-05-2020 12:47 AM
- Posted Re: How to optimize a search performance of a slow, composite search on Splunk Search. 01-28-2015 10:20 AM
- Posted Re: How to optimize a search performance of a slow, composite search on Splunk Search. 01-28-2015 02:44 AM
- Posted Re: How to optimize a search performance of a slow, composite search on Splunk Search. 01-28-2015 02:32 AM
- Posted How to optimize a search performance of a slow, composite search on Splunk Search. 01-27-2015 10:22 AM
- Tagged How to optimize a search performance of a slow, composite search on Splunk Search. 01-27-2015 10:22 AM
- Tagged How to optimize a search performance of a slow, composite search on Splunk Search. 01-27-2015 10:22 AM
- Tagged How to optimize a search performance of a slow, composite search on Splunk Search. 01-27-2015 10:22 AM
- Tagged How to optimize a search performance of a slow, composite search on Splunk Search. 01-27-2015 10:22 AM
- Tagged How to optimize a search performance of a slow, composite search on Splunk Search. 01-27-2015 10:22 AM
- Posted Re: Is it possible to send host grouping information from a forwarder? on Getting Data In. 01-16-2015 06:52 AM
- Posted Re: Is it possible to set monitor paths dynamically without the use of wildcards? on Getting Data In. 01-15-2015 10:37 AM
- Posted Re: Is it possible to set monitor paths dynamically without the use of wildcards? on Getting Data In. 01-15-2015 10:27 AM
- Posted Is it possible to set monitor paths dynamically without the use of wildcards? on Getting Data In. 01-15-2015 10:09 AM
- Tagged Is it possible to set monitor paths dynamically without the use of wildcards? on Getting Data In. 01-15-2015 10:09 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
4 | |||
0 | |||
0 | |||
0 | |||
1 |
01-28-2015
10:20 AM
I did read up on multisearch, but it seems it would collide with the dedups and transactions, right?
... View more
01-15-2015
10:37 AM
What about using a either the whitelist or blacklist option for the monitor stanza?
http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Specifyinputpathswithwildcards
http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Whitelistorblacklistspecificincomingdata
[monitor:///path/*/logfile.log]
blacklist = [Uu]nwanted[Hh]ost[Rr]egex[0-9]/logfile.log$
OR
[monitor:///path/*/logfile.log]
whitelist = /path/goodhost[0-9]/logfile.log$|/path/this[4-9]host/logfile.log$
... View more
01-16-2015
06:52 AM
I almost suspected that. Thanks for summarizing my options ... "host" and "source" won't work because those are outside my jurisdiction (I don't own the monitorees) and I agree, abusing "sourcetype" for that purpose would harm "sourcetype" as a more or less well-known concept in my Splunk deployment.
... View more
05-14-2015
11:19 AM
1 Karma
This is possible, and supported, however it will be tricky if you wish to UPDATE the lookups post deploy via the deployment server.
There is a deployment server option to exclude folders/files from updates:
excludeFromUpdate = $app_root$/lookups
This will populate the lookups directory if it doesn't exist, but if the app already has a lookups folder it will completely ignore it. If you have a single lookup file that you wish to exclude from the deployment server, you should be able to specify that particular lookup:
excludeFromUpdate = $app_root$/lookups/mylookup.csv
Hope this helps,
Jim Goddard
... View more
12-09-2014
02:49 AM
1 Karma
nice, thanks for sharing! Will come in handy 🙂
... View more