Activity Feed
- Posted Re: LINE_BREAKER is being ignored on Getting Data In. a week ago
- Posted Re: LINE_BREAKER is being ignored on Getting Data In. a week ago
- Posted Re: LINE_BREAKER is being ignored on Getting Data In. 2 weeks ago
- Posted LINE_BREAKER is being ignored on Getting Data In. 2 weeks ago
- Posted Re: use colorpallette to change color of extremes on a dashboard on Dashboards & Visualizations. 3 weeks ago
- Posted use colorpallette to change color of extremes on a dashboard on Dashboards & Visualizations. 3 weeks ago
- Karma Re: comparing scores for livehybrid. 3 weeks ago
- Posted comparing scores on Splunk Search. 4 weeks ago
- Posted Pulling data into splunk via API on Getting Data In. 03-04-2025 11:48 AM
- Posted Props and the Magic 8 on Getting Data In. 11-25-2024 11:57 AM
- Tagged Props and the Magic 8 on Getting Data In. 11-25-2024 11:57 AM
- Posted using addcoltotals on Splunk Search. 08-09-2023 01:24 PM
- Tagged using addcoltotals on Splunk Search. 08-09-2023 01:24 PM
- Posted Is there a limit to the number of white/blacklists you can put under a stanza in the serverclass.conf file? on Deployment Architecture. 04-27-2023 05:57 AM
- Posted inputs.conf blacklist format- Is there a format that needs to be adhered to when using a blacklist with regex? on Getting Data In. 02-11-2023 03:13 PM
- Tagged inputs.conf blacklist format- Is there a format that needs to be adhered to when using a blacklist with regex? on Getting Data In. 02-11-2023 03:13 PM
- Tagged inputs.conf blacklist format- Is there a format that needs to be adhered to when using a blacklist with regex? on Getting Data In. 02-11-2023 03:13 PM
- Tagged inputs.conf blacklist format- Is there a format that needs to be adhered to when using a blacklist with regex? on Getting Data In. 02-11-2023 03:13 PM
- Posted What is the best was to identify the outage window in one search? on Splunk Search. 06-13-2022 11:55 AM
- Posted Re: Web_service.log is empty after upgrading from Splunk version 7.3 to 8.0. on Deployment Architecture. 05-24-2020 08:24 PM
a week ago
Very helpful it is set to stream XML so I guess that is the issue and I need to either find a way to deal with it or modify the setting which as you mentioned looks easier said than done.
... View more
4 weeks ago
Ah @bowesmana , I may have misunderstood the ask here, as you say. I used streamstats by test_name after sorting by (an assumed sequential) test_id. Although I'm not sure why there being the same test_id for multiple test_name would affect the output here, as I'm not using the test_id in the streamstats? I may have missed something though (and not had coffee yet!) @dolj Please let us know how you are getting on, and if you clarify the requirement I'd be happy to help further and update the previously posted search if required 🙂 Please let me know how you get on and consider adding karma to this or any other answer if it has helped. Regards Will
... View more
03-04-2025
02:42 PM
Further to my last message - this is a great blog post on getting started with UCC so well worth checking out https://www.splunk.com/en_us/blog/customers/managing-splunk-add-ons-with-ucc-framework.html Let us know how you get on and if you have any further questions 🙂 Will
... View more
11-25-2024
12:31 PM
1 Karma
Yes, it's recommended as a best practice to implement all Magic 8 configs because they establish consistency and reliability in data onboarding. While most TAs start with Magic 6, adding the EVENT_BREAKER configs gives you better control over event distribution and parsing. Think of Magic 6 as the minimum standard, and Magic 8 as the complete package for optimal data handling. The TAs can be updated with the additional configs when needed based on your specific deployment, but having all 8 from the start is generally ideal as it prevents potential data parsing issues down the line. If this Helps, Please Upvote.
... View more
08-09-2023
11:26 PM
You can't use the total calculated by addcoltotals as it's in a new row at the bottom of the table, however, as @richgalloway the typical way to calculate percentages is to use eventstats to add up all the counts, so that the total is added to _every_ row in your data set, which you can then calculate the percentages with. Then discard that calculated total field if you no longer need it
... View more
04-27-2023
07:28 AM
Here is the spec doc for the serverclass.conf file. https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Serverclassconf I have not run into any limits on the number of items. Especially when I use a csv file to specify 100s of servers for a specific class. You should be good.
... View more
02-12-2023
01:07 PM
1 Karma
Escaping with regex may make it hard to read, but luckily there is a smart way around it. You can start and stop in regex with \Q and \E on what you like to get literal. | makeresults
| eval _raw= "C:\Program Files (x86)\Google"
| regex "\QC:\Program Files (x86)\Google\E" This makes regex much more readable. https://www.regular-expressions.info/characters.html
... View more
06-13-2022
11:28 PM
Hi @dolj, if you want to find the time borders of a search you can use "addinfo" (https://docs.splunk.com/Documentation/Splunk/8.2.6/SearchReference/Addinfo). If instead you want to display the first and the last event, you can use stats and the options "first" and "last", something like this: your_search
| stats first(_raw) AS first last(_raw) AS last Ciao. Giuseppe
... View more
05-24-2020
08:24 PM
not sure why but it wasn't working and it now is.
I found this log related to the web UI
05-24-2020 23:12:06.172 -0400 ERROR UiHttpListener - An applicaiton server has exited unexpectedly, web UI cannot be used until it is restarted
... View more
05-05-2020
05:29 PM
I Installed 6.5.10 and configured all windows event logs locally and see events coming in but nothing in the borwser index and nothing in the dashboar even after a restart.
... View more