Activity Feed
- Posted Re: required conf files to monitor csv data frequently on Getting Data In. 08-09-2024 05:59 AM
- Posted Re: required conf files to monitor csv data frequently on Getting Data In. 08-09-2024 03:40 AM
- Posted required conf files to monitor csv data frequently on Getting Data In. 08-08-2024 09:38 PM
- Posted join query issue on Deployment Architecture. 08-01-2024 12:31 AM
- Posted Re: Issue with Microsoft Azure add-on for Splunk on All Apps and Add-ons. 07-25-2024 08:35 PM
- Posted Re: MS security integration with splunk on Getting Data In. 07-25-2024 08:29 AM
- Posted MS security integration with splunk on Getting Data In. 07-25-2024 07:36 AM
- Tagged MS security integration with splunk on Getting Data In. 07-25-2024 07:36 AM
- Posted commvault integration with splunk on Dashboards & Visualizations. 06-20-2024 11:47 PM
- Posted Re: join on Dashboards & Visualizations. 06-11-2024 10:43 PM
- Posted Re: join on Dashboards & Visualizations. 06-11-2024 10:22 PM
- Posted Re: join on Dashboards & Visualizations. 06-11-2024 10:18 PM
- Posted join on Dashboards & Visualizations. 06-11-2024 09:56 PM
- Karma Re: How to show data for second week of tuesday every month for emdaax. 05-28-2024 12:56 AM
- Karma Re: How to show data for second week of tuesday every month for gcusello. 05-28-2024 12:56 AM
- Karma Re: How to show data for second week of tuesday every month for gcusello. 05-27-2024 05:08 AM
- Posted Re: How to show data for second week of tuesday every month on Dashboards & Visualizations. 05-27-2024 05:07 AM
- Posted How to show data for second week of tuesday every month on Dashboards & Visualizations. 05-26-2024 09:54 PM
- Posted Re: Weekly Trend for a moth and Monthly trend for last 6 months on Dashboards & Visualizations. 05-20-2024 09:24 PM
- Posted Re: Weekly Trend for a moth and Monthly trend for last 6 months on Dashboards & Visualizations. 05-20-2024 07:53 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
08-09-2024
05:59 AM
its not extracting the whole data
... View more
08-09-2024
03:40 AM
Hi , Thanks for the response! Please find the details below filename -BackupJobSummaryReport_2024-07-07-08-00-06 ( it will be in incremental order based on date) path - C:\Users\_svcAPACCommVault01\OneDrive - Lendlease\Desktop\csv\*.csv column separator,- Client,Host Name,Total Jobs,Completed,Completed with errors,Completed with warnings,Killed,Unsuccessful,Running,Delayed,No Run,No Schedule,Committed,Size of Application,Compression Rate,Data Written,(Space Saving Percentage),Start Time,End Time,Protected Objects,Failed Objects,Failed Folders sourcetype - backup index - acn_lendlease_commvault
... View more
08-08-2024
09:38 PM
Hi All, Please provide conf files ( inputs.conf,props.con,outputs.conf) to index the below format data on daily basis
... View more
Labels
- Labels:
-
login
08-01-2024
12:31 AM
Hi all I am trying to fetch incident details from servicenow, but its showing duplicate values index=acn_lendlease_certificate_tier3_idx tower=Entrust_Certificate | join type=left source_host max=0 [search index=acn_ac_snow_ticket_idx code_message=create uid="*Saml : Days to expire*" OR uid="*Self_Signed : Days to expire*" OR uid="*CA : Days to expire*" OR uid="*Entrust : Days to expire*" | rex field=_raw "\"(?<INC>INC\d+)," | rex field=uid "(?i)^(?P<source_host>.+?)__" | table INC uid log_description source_host | dedup INC uid log_description source_host | rename INC as "Ticket_Number"] | fillnull value="NA" Ticket_Number | stats latest(tower) as Tower, latest(source_host) as source_host , latest(metric_value) as "Days To Expire", latest(alert_value) as alert_value, latest(add_info) as "Additional Info" by instance,Ticket_Number | eval alert_value=case(alert_value==100,"Active",alert_value==300,"About to Expire", alert_value==500,"Expired") | search Tower="*" alert_value="*" alert_value="About to Expire" | sort "Days To Expire" | dedup instance | rename instance as "Serial Number / Server ID", Tower as "Certificate Type" , source_host as Certificate , alert_value as "Certificate Status"
... View more
Labels
- Labels:
-
distributed search
07-25-2024
08:35 PM
please post the solution
... View more
07-25-2024
08:29 AM
Hi , I have added the config details already , still data is not coming
... View more
07-25-2024
07:36 AM
Hi All, Data is not getting indexed after adding the conf
... View more
- Tags:
- addon
06-20-2024
11:47 PM
I want to integrate commvault with splunk to create a dashboard using addon. I dont find how to procced further .so please provide with the steps.
... View more
Labels
- Labels:
-
Classic dashboard
06-11-2024
10:43 PM
Hi bowesmana Thanks for the efforts we have data sets
index=acn_lendlease_certificate_tier3_idx tower=Self_Signed_Certificate
| stats latest(tower) as Tower, latest(source_host) as source_host , latest(metric_value) as "Days To Expire", latest(alert_value) as alert_value, latest(add_info) as "Additional Info" by instance
| eval alert_value=case(alert_value==100,"Active",alert_value==300,"About to Expire", alert_value==500,"Expired")
| where alert_value="About to Expire"
| search Tower="*" AND alert_value="*"
| sort "Days To Expire"
| rename instance as "Serial Number / Server ID", Tower as "Certificate Type" , source_host as Certificate , alert_value as "Certificate Status"
here i am trying to add one more coulmn called incident To extract the incident details with respect to certificate values If inc is available , then it should display numbers, orelse null To extract the INC, using the below query
index=acn_ac_snow_ticket_idx code_message=create uid="*Saml : Days to expire*" OR uid="*Self_Signed : Days to expire*" OR uid="*CA : Days to expire*" OR uid="*Entrust : Days to expire*"
| rex field=_raw "\"(?<INC>INC\d+),"
| rex field=uid "(?i)^(?P<source_host>.+?)__"
| table INC uid log_description source_host
| dedup INC uid log_description source_host
| rename INC as "Ticket_Number"
... View more
06-11-2024
10:18 PM
yes I have created regex to extract incident details and source host
... View more
06-11-2024
09:56 PM
index=acn_ac_snow_ticket_idx code_message=create uid="*Saml : Days to expire*" OR uid="*Self_Signed : Days to expire*" OR uid="*CA : Days to expire*" OR uid="*Entrust : Days to expire*" | rex field=_raw "\"(?<INC>INC\d+)," | rex field=uid "(?i)^(?P<source_host>.+?)__" | table INC uid log_description source_host | dedup INC uid log_description source_host | rename INC as "Ticket_Number" | selfjoin source_host [ search index=acn_lendlease_certificate_tier3_idx tower=* | table *] | stats latest(tower) as Tower, latest(source_host) as source_host , latest(metric_value) as "Days To Expire", latest(alert_value) as alert_value, latest(add_info) as "Additional Info" by instance,Ticket_Number | eval alert_value=case(alert_value==100,"Active",alert_value==300,"About to Expire", alert_value==500,"Expired") | where alert_value="Active" | search Tower="*" AND alert_value="*" | sort "Days To Expire" | rename instance as "Serial Number / Server ID", Tower as "Certificate Type" , source_host as Certificate , alert_value as "Certificate Status" I am trying to map incident number with respect to source_host using join command but its not working as expected
... View more
Labels
- Labels:
-
Classic dashboard
05-27-2024
05:07 AM
Thanks!! Its working
... View more
05-20-2024
09:24 PM
Thanks for your response! I got the query I index | timechart span=1d sum(abc) as total by xyz | eval day=lower(strftime(_time,"%A")) | where day=="monday" | fields - day
... View more
05-20-2024
07:53 AM
still its not working
... View more
05-20-2024
06:56 AM
Its throwing an error
... View more
05-20-2024
05:05 AM
I want to show data for every monday on weekly basis
... View more
05-17-2024
12:01 AM
I want to show weekly data in a trend ,it should not add total Right now using the below query, but it showing overall count of a week
| timechart span=1w@w7 sum(abc) by xyz
@splunk
... View more
Labels
- Labels:
-
single value
-
timechart
04-03-2024
05:21 AM
may i know the exact answer Please
... View more
- Tags:
- shalomsuresh
02-28-2024
05:43 AM
How to show total count values in label of pie chart? instead of percentage example ,I want to show over all count (i.e 501455) next to EOL @developers
... View more
- Tags:
- @everyone
Labels
- Labels:
-
chart
-
Classic dashboard
-
CSS
02-22-2024
08:14 AM
Hi I want to change font size label (to bold) in pie chart please help me with code
... View more