Activity Feed
- Posted Re: dashboard is showing zero for one user whereas result is appearing for others on Dashboards & Visualizations. 01-07-2021 08:43 PM
- Posted dashboard is showing zero for one user whereas result is appearing for others on Dashboards & Visualizations. 01-07-2021 08:40 AM
- Posted combining 2 rows in to a single row on Splunk Search. 12-01-2020 07:57 AM
- Posted Re: multisearch in table format on Splunk Search. 11-19-2020 03:54 AM
- Posted Re: multisearch in table format on Splunk Search. 11-19-2020 12:59 AM
- Posted Re: multisearch in table format on Splunk Search. 11-18-2020 07:51 PM
- Posted multisearch in table format on Splunk Search. 11-18-2020 03:34 AM
- Posted Re: column data output is going to next row on Splunk Search. 11-13-2020 03:09 AM
- Posted Re: column data output is going to next row on Splunk Search. 11-10-2020 02:32 AM
- Posted Re: column data output is going to next row on Splunk Search. 11-10-2020 01:26 AM
- Posted Re: column data output is going to next row on Splunk Search. 11-04-2020 08:56 PM
- Posted Re: column data output is going to next row on Splunk Search. 11-04-2020 03:54 AM
- Posted column data output is going to next row on Splunk Search. 11-04-2020 02:28 AM
- Got Karma for forwarder version upgrade by remotely. 10-23-2020 06:16 AM
- Posted forwarder version upgrade by remotely on Getting Data In. 10-23-2020 02:24 AM
- Posted splunk inventory on All Apps and Add-ons. 09-30-2020 04:14 AM
- Posted customized app origin is showing as uploaded instead of Splunk on Getting Data In. 09-15-2020 03:18 AM
- Posted log is going to _internal index on All Apps and Add-ons. 09-15-2020 03:13 AM
- Karma Re: edit role is greyed out for isoutamo. 09-15-2020 03:08 AM
- Posted Why can't I edit roles or assign new roles when I have admin permissions? on All Apps and Add-ons. 08-31-2020 04:15 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
1 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
01-07-2021
08:43 PM
how to give back the permission to that user then ?
... View more
01-07-2021
08:40 AM
Hi,one of my user complained that dashboard data is coming as zero suddenly from last 3-4 days( earlier he was) where as his collegue is able to see them .. both are having same access and permission ( same Security grp as well).. any thoughts how to resolve ?
... View more
Labels
- Labels:
-
table
12-01-2020
07:57 AM
Hi, I was trying to add 2 rows in to a single row . After combining,I am getting results for 1st column .but not for 2nd result .Something wrong here ? host=t-fus* ("SRCreateRequest" OR "SRPublishRequest" OR "SRUpdateRequest" OR "JNPRCreateSRPublish" OR "JNPRPostSRUpdate" OR "JNPRUpdateSRPublish")
(Publisher: Completed OR fallacy )
| rename JNPRCreateSRPublish as SRCreateRequest
| rename JNPRPostSRUpdate as SRPublishRequest
| rename JNPRUpdateSRPublish as SRUpdateRequest
| rex "(?<API> SRCreateRequest | SRPublishRequest | SRUpdateRequest )"
| rex "(?<status>Completed| fallacy)"
| where isnotnull(status)
| append
[| makeresults
| eval API=split(" SRCreateRequest | SRPublishRequest | SRUpdateRequest ", "|")
| mvexpand API]
| chart count as count1 by API,status
| table API, Completed, Error
| fillnull value=0 Error, Completed
... View more
Labels
- Labels:
-
table
11-19-2020
03:54 AM
hm yes, is it possible to display those columns & rows where we have "zero" values ?
... View more
11-19-2020
12:59 AM
yes, it is not giving the output.. but modified as below .. here all APIs are not showing along with "Completed" anything wrong ?
... View more
11-18-2020
07:51 PM
ohk, what could be the good solution for this query to get above result ?
... View more
11-18-2020
03:34 AM
Hi, I was trying to add 2 searches | multisearch [search host=p-css* SRCreateRequest 400 | stats count as CreateSR
| appendcols [search host=p-css* SRUpdateRequest 400 | stats count as UpdateSR]
| appendcols [search host=p-css* SREscalateRequest 400 | stats count as EscalateSR]
| appendcols [search host=p-css* SRCloseRequest 400 | stats count as CloseSR]
| eval type="400"]
[appendcols search host=p-css* SRCreateRequest Publisher: Completed | stats count as CreateSR
| appendcols [search host=p-css* SRUpdateRequest Publisher: Completed | stats count as UpdateSR]
| appendcols [search host=p-css* SREscalateRequest Publisher: Completed | stats count as EscalateSR]
| appendcols [search host=p-css* SRCloseRequest Publisher: Completed | stats count as CloseSR]
| eval type="Completed"]
| chart count(Name) over 400 by Completed Getting error "Error in 'multisearch' command: Multisearch subsearches might only contain purely streaming operations (subsearch 1 contains a non-streaming command)." My expected output will be having a table format: giving some example here API 400 Completed CreateSR 30 50 UpdateSR 5 25 CloseSR 24 30
... View more
Labels
- Labels:
-
subsearch
11-13-2020
03:09 AM
able to remove another column "NULL" using " where isnotnull(status)" But, if I tried with in dashboard , getting an error ,although it was working fine with any other search "Error parsing XML on line 48: Premature end of data in tag form line 1"
... View more
11-10-2020
02:32 AM
yes,I do have multi value fields in the events.. BTW in this query,for 'completed' it is not coming ,only ERROR & Response is coming. If less time range,where result is there then only it is showing , needs to display all 3 columns (if no data,'zero' has to display)
... View more
11-10-2020
01:26 AM
Hi, using @ITWhisperer , I am getting extra column "NULL" which was not expected. Even I tried using same with dashboard query & it not working. I tried to use server name in the query.. host=server1 (SRCreateRequest OR SRUpdateRequest OR SRPublishRequest) (Completed OR ERROR OR response) something I am doing wrong ?
... View more
11-04-2020
08:56 PM
Hi, yes, I tried.. but I am getting following screens. If I have less time range, then it is showing only 2 rows and if increase time range,then extra columns showing like NULL,200 etc. I wanted to have only 3 rows and 3 columns ..
... View more
11-04-2020
03:54 AM
Hi, Added these lines and output is coming NULL instead of status. something I am doing wrong ?
... View more
11-04-2020
02:28 AM
Hi, Here is my query: | search SRCreateRequest Completed | stats count as CreateSR | appendcols [search SRUpdateRequest Completed | stats count as UpdateSR] | appendcols [search SRPublishRequest Completed | stats count as PublishSR] | transpose header_field=a | appendcols [search SRCreateRequest ERROR | stats count as Failure] | append [search SRUpdateRequest ERROR | stats count as Failure] | append [search RPublishRequest ERROR | stats count as Failure] | appendcols [search SRCreateRequest response | stats count as Response] | append [search SRUpdateRequest response | stats count as Response] | append [search RPublishRequest response | stats count as Response] | rename "column" as "API", "row 1" as "Success" | table API,Success,Failure,Response Output is not coming in to proper table.. any suggestion
... View more
Labels
- Labels:
-
table
10-23-2020
02:24 AM
1 Karma
Hi,I do have 100+ servers where splunk forwarders' version is older one and needs to upgrade . I don't have access to these servers. Without effecting configuration,how do I upgrade those by remotely ?
... View more
Labels
- Labels:
-
universal forwarder
09-30-2020
04:14 AM
Hi, How to check technology inventories like new asset added,new software added,storage total attached ,memory of each hosts for last 30 days.. ? Also, how to get Splunk volume usage and Top 10 apps for every month/quarter ?
... View more
Labels
- Labels:
-
administration
09-15-2020
03:18 AM
Hi, I have uploaded customized app ,but App origin is showing as "Uploaded" ,we suppose to have "Splunk" How to change this ?
... View more
Labels
- Labels:
-
index
09-15-2020
03:13 AM
Hi, Logs are going to _internal index instead of customized index. host = xxxx index = _internal source = C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log sourcetype = splunkd inputs.conf and props.conf are set properly in deployment server.Also verified in the SplunkForwarder "Windows" server. Still getting above one , not going to customized index. What could be the reason ?
... View more
Labels
- Labels:
-
configuration
-
troubleshooting
08-31-2020
04:15 AM
Hi,
I am unable to 'edit role' or assign a new role to a user although I do have an admin role.?
What could be the solution ?
... View more
- Tags:
- permission
- roles
Labels
- Labels:
-
administration
08-27-2020
10:56 PM
Hi, I was trying to run 'reload deploy server' .. /opt/splunk/bin/splunk reload deploy-server Your session is invalid. Please login. Splunk username: admin Password: An authentication error occurred: Client is not authenticated. What went wrong ?
... View more
- Tags:
- error