Activity Feed
- Karma Re: Is It possible do two different searches and write the output data in another index? for alacercogitatus. 06-05-2020 12:47 AM
- Got Karma for Splunk DB Connect 2: Oracle does not input data in index. 06-05-2020 12:47 AM
- Karma Re: dashboard migration for davecroto. 06-05-2020 12:46 AM
- Posted Re: Splunk DB Connect 2: Oracle does not input data in index on All Apps and Add-ons. 05-22-2015 01:48 PM
- Posted Re: Splunk DB Connect 2: Oracle does not input data in index on All Apps and Add-ons. 05-21-2015 11:15 AM
- Posted Splunk DB Connect 2: Oracle does not input data in index on All Apps and Add-ons. 05-21-2015 11:13 AM
- Tagged Splunk DB Connect 2: Oracle does not input data in index on All Apps and Add-ons. 05-21-2015 11:13 AM
- Tagged Splunk DB Connect 2: Oracle does not input data in index on All Apps and Add-ons. 05-21-2015 11:13 AM
- Posted Re: Configure input before execute oracle procedure and select on All Apps and Add-ons. 05-14-2015 01:30 PM
- Posted Configure input before execute oracle procedure and select on All Apps and Add-ons. 05-14-2015 01:23 PM
- Tagged Configure input before execute oracle procedure and select on All Apps and Add-ons. 05-14-2015 01:23 PM
- Tagged Configure input before execute oracle procedure and select on All Apps and Add-ons. 05-14-2015 01:23 PM
- Posted Is It possible do two different searches and write the output data in another index? on Splunk Search. 12-02-2014 05:06 AM
- Tagged Is It possible do two different searches and write the output data in another index? on Splunk Search. 12-02-2014 05:06 AM
- Tagged Is It possible do two different searches and write the output data in another index? on Splunk Search. 12-02-2014 05:06 AM
- Tagged Is It possible do two different searches and write the output data in another index? on Splunk Search. 12-02-2014 05:06 AM
- Posted Re: Indexer with high IO on Getting Data In. 03-28-2014 04:30 AM
- Posted Indexer with high IO on Getting Data In. 03-27-2014 03:02 PM
- Tagged Indexer with high IO on Getting Data In. 03-27-2014 03:02 PM
- Tagged Indexer with high IO on Getting Data In. 03-27-2014 03:02 PM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
1 | |||
0 | |||
0 | |||
0 | |||
0 |
05-22-2015
01:48 PM
Yes i'm using db connect v2.
my data are something around 2008 until now
i dont understand very right this field timestamp input_timestamp_format i cant input the format like YYYY-MM-dd HH:mm:ss I need to put real date to this field be valid like this 2015/05/19 20:57:02
i try put like this input_timestamp_format = YYY/MM/dd HH:mm:ss but splunk db connect don't accept.
... View more
05-21-2015
11:15 AM
input.conf
[mi_input://Coleta]
connection = SM9
description = Coleta
index = oracle_servicecenter
input_timestamp_column_name = OPEN_TIME
input_timestamp_column_number = 1
input_timestamp_format = 2015/05/19 20/:57:02
interval = 24 * * * *
max_rows = 1000000
mode = tail
output_timestamp_format = YYYY-MM-dd HH:mm:ss
query = select * from log_report_adm.v_sm_open_documents
source = /opt/splunk/var/log/splunk/rpc.log
sourcetype = coleta_oracle_incidentes
ui_query_catalog = NULL
ui_query_mode = advanced
tail_rising_column_name = IDENTIFICADOR
tail_rising_column_number = 5
ui_query_schema = SPLUNK_SMUBR
tail_follow_only = 1
... View more
05-21-2015
11:13 AM
1 Karma
I am trying to make an select and input this data into splunk.
In preview, i can see all data that i need but when job run to input data, nothing happens the data doesn't appear in the index
... View more
05-14-2015
01:30 PM
thank you for your help.
... View more
05-14-2015
01:23 PM
Hi..
i need to execute this to get my data
begin
delete log_report_adm.sm_open_documents_new;
log_report_adm.p_sm_collect_open_documents;
end;
select * from log_report_adm.v_sm_open_documents;
but i got this error command="dbxquery", ORA-06550: line 6, column 1: PLS-00103: Encountered the symbol "SELECT" i think its is because i have ";" in this row but how i will execute this procedure before query
... View more
12-02-2014
05:06 AM
Is It possible do two different searches and write the output data in another index?
... View more
03-28-2014
04:30 AM
Thank you for your reply. I will try contact the support and i will install a dedicated license master server.
But still I find it strange slowness of searches .. I have noticed that the splunk-system-user user runs at least 20x more searches than the normal user.
... View more
03-27-2014
03:02 PM
Hello, I have the following question.
I have in my environment 4 index servers and 2 search head.
I also have 2 licenses 100GB and 2 license master servers. Each with 100GB
Lately my splunk has been very slow, I noticed that the license servers are with IO much higher than the other two, I came to cogitate be the balancer but the configuration is correct.
The only thing I have different is that 2 servers are as indexer and master license and the other 2 just as indexer.
I use distributed search so my file $SPLUNK_HOME / etc and $ SPLUNK_HOME / var are shared on an NFS.
I have a high volume of searches and simultaneous users logged.
I do not use all my 200GB license, I'm using only 140GB
Can you give me an idea?
... View more
08-09-2013
01:11 PM
Very strange ... I got a copy of the free version of the $SPLUNK_HOME/etc/apps/search/local/data/ui/views to my other in $SPLUNK_HOME/splunk/etc/apps/incidents/local/data/ui/views, also copied $SPLUNK_HOME/etc/apps/search/metadata/local.meta to $SPLUNK_HOME/etc/apps/incidents/metadata/local.meta and still can not view the dashboards.
... View more
08-09-2013
08:42 AM
Hello I am wanting to change my dashboard of a free version of splunk for a version with license, but this is a licensed version 4.2.3 .. even managed to migrate saved searches and visions .. I just can not migrate dashboards,
where are this files? I can not just copy the directory because I'm using an existing app with other things in the licensed version.
... View more
- Tags:
- dashboards
- migration