Does anyone know why the tag based search is not working in metric based commands. Is there any restriction or any alternative approach? Working here, index=_internal tag=windows_lab_iis No Results for this command, | mcatalog values(metric_name) WHERE tag=windows_lab_iis index=metrics* BY index, host
... View more
Hi, Since you want to do it in HF, you can modify the input stanza to specify the default index. [tcp://9991]
index = supplier1
[tcp://9992]
index = supplier2 OR you can add the props & transforms transforms.conf (if you want to filter you can use sourcekey & regex) [tcp9991_syslog_supplier1]
SOURCE_KEY = MetaData:Host
REGEX = (10.*.*.*)
DEST_KEY = _MetaData:Index
FORMAT = supplier1
[tcp9992_syslog_supplier2]
SOURCE_KEY = MetaData:Host
REGEX = (10.*.*.*)
DEST_KEY = _MetaData:Index
FORMAT = supplier2
... View more
Thanks, Below command fix that issue.
chmod 400 /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key
I was not able to open Splunk Add on builder TA due to this issue. Now its been fixed by changing the permission to the mongo key file.
... View more
its possible to pass the token through saved search, but token field name is the one you need to use it in your savedsearch report query.
if you want to exexute : |savedsearch "Syslog Report" token_SourceIPAddress="$ip$"
your saved search should be like,
index=someindex src_ip_field=$token_SourceIPAddress$
... View more
earlier i dropped mail to certification, later to education_APAC and now i forwarded the same to elearn. lets see. thanks for your support.
... View more
Hi,
I completed the elearning course topics
**Splunk Infrastructure Overview 6.x (eLearning)**
Searching And Reporting With Splunk 6.x (eLearning)
Creating Splunk Knowledge Objects 6.x (eLearning)
Using Splunk 6.x (eLearning)
but only for Splunk Infrastructure Overview 6.x (eLearning) course attended status is not coming. i completed all videos and passed all quiz. Kindly help or advice on how to get certified and complete the course. [Few of the videos are in started state on transcript- if i view the videos again also its in same state.]
... View more