Activity Feed
- Posted Re: How to disable csv replication in the Search Head cluster. on Splunk Enterprise. 02-04-2021 12:18 AM
- Tagged How to disable csv replication in the Search Head cluster. on Splunk Enterprise. 02-03-2021 04:57 AM
- Posted How to disable csv replication in the Search Head cluster. on Splunk Enterprise. 02-03-2021 01:08 AM
- Karma Re: How to generate a timechart from multiple data sources? for somesoni2. 06-05-2020 12:48 AM
- Karma Re: How to troubleshoot Search Head Clustering initial bootstrap failing with error "found different peer with serverName and hostport already registered and UP"? for rbal_splunk. 06-05-2020 12:47 AM
- Karma Re: How to troubleshoot Search Head Clustering initial bootstrap failing with error "found different peer with serverName and hostport already registered and UP"? for rbal_splunk. 06-05-2020 12:47 AM
- Karma Re: Moving manual rex to props.conf and transforms.conf for martin_mueller. 06-05-2020 12:47 AM
- Karma Re: Why am I getting "WARN AuthorizationManager - Unknown role" errors in splunkd.log after deleting the VMware and Windows Infrastructure apps? for bravon. 06-05-2020 12:47 AM
- Karma Re: splunkd.log error message for tmarlette. 06-05-2020 12:46 AM
- Karma License pools for Indexes rather than Indexers for Damien_Dallimor. 06-05-2020 12:46 AM
- Karma Re: License pools for Indexes rather than Indexers for Glenn. 06-05-2020 12:46 AM
- Karma Re: SPLUNK DB Connect: Timestamp Not Working for pmagee. 06-05-2020 12:46 AM
- Got Karma for Re: How to retrieve data from Tibco EMS with jms_ta. 06-05-2020 12:46 AM
- Karma Re: Does Splunk index gzip files? for hulahoop. 06-05-2020 12:45 AM
- Karma Re: What is the OTHER field? for Lowell. 06-05-2020 12:45 AM
- Karma Re: Change Logo on Login Screen for vcarbona. 06-05-2020 12:45 AM
- Posted Re: How to do a text search from the lookup into index? on Splunk Search. 06-13-2017 04:54 AM
- Posted Re: How to do a text search from the lookup into index? on Splunk Search. 06-13-2017 03:38 AM
- Posted Re: How to do a text search from the lookup into index? on Splunk Search. 06-13-2017 03:20 AM
- Posted Re: How to generate a timechart from multiple data sources? on Splunk Search. 03-03-2017 07:55 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
02-04-2021
12:18 AM
Hello! Thank you for your participation, but unfortunately I have already tried this option earlier 🙂 As I understand it, this setting works only when transferring a bundle from SHC to Indexer nodes. distsearch.conf
... View more
02-03-2021
01:08 AM
Good afternoon, community. There was a need to remove lookup files from replication between Search Heads (version 8.1.2). Tried tweaking the server.conf file and setting the values: conf_replication_include.lookups = false conf_replication_summary.blacklist.lookups = (system | (apps / *) | users (/ _ reserved)? / * / *) / lookups / * If the lookup file is created through the UI, it remains local, but unfortunately this does not help when using the outputlookup command and the file is distributed across the cluster. Btool on search head: splunk btool --debug server list | grep lookup Search Head Clustering: Configuration Replication (when using the outputlookup command): Perhaps you have any ideas where else to pay attention to completely close the possibility of replicating lookup files?
... View more
- Tags:
- search head cluster
Labels
- Labels:
-
administration
-
configuration
06-13-2017
04:54 AM
Sorry, error on copy paste. Correct search string:
index="iot" [ | inputlookup "transaction.csv" | return 10000 $transaction_name] | rex "transaction name: (?<transaction_name>\S+)" | table transaction_name
But the structure of the message is the same? I mean "transaction name: Workflow".
... View more
06-13-2017
03:38 AM
When you using "table" command you must specify field name.
To make your search work please modify it to:
index="iot" [ | inputlookup "transaction.csv" | return 10000 $transaction_name] | rex "transaction name: (?\S+)" | table transaction_name
And you get a text search, then create a field and a table based on the field.
... View more
06-13-2017
03:20 AM
Or that 🙂
index=*
[| inputlookup transaction.csv
| return 10000 $search]
| rex "transaction name: (?<transaction_name>\S+)"
| stats count by index,transaction_name
... View more
03-03-2017
07:55 AM
No problem 🙂 I'm glad to hear that your problem has been solved.
... View more
03-03-2017
05:18 AM
Plz try that.
index=app_ops_prod host=abcdefgh source="Test.log" SessionID="*" | timechart span=1m count(SessionID) | appendcols [search index=app_ops_prod host=abcdefgh source="Test.log" ("error.badurl" OR "error.timeout") | timechart span=1m count]
Also on the chart, you can add the chart overlay to better illustrate your data.
... View more