Thread Info | |||||
---|---|---|---|---|---|
Hello,
I collect security events from an active directory domain. I 'm trying to get the number of logons by usern...
by
smarechal
Explorer
in
Knowledge Management
01-26-2012
|
0
|
2
| |||
Is it safe to clear the _internal index like this? Or should this never be done in the first place? What are the issu...
by
rayfoo
Path Finder
in
Knowledge Management
05-02-2010
|
3
|
2
| |||
Is it possible to auto-tag a field from the results of a search from the cli or the search bar? Something like:
"s...
by
swdonline
Path Finder
in
Knowledge Management
01-18-2012
|
0
|
1
| |||
When I search for index=summary in search head, the result only shows one of the server in splunk_server field. But I...
by
vadud3
Path Finder
in
Knowledge Management
01-20-2012
|
0
|
3
| |||
I am experiencing some very weird behaviour with SI's.
I have two apps. App1 and App2. App1 has a search named tes...
by
johandk
Path Finder
in
Knowledge Management
11-15-2011
|
0
|
5
| |||
In Manager -> Searches and Reports -> [summary index], there is an option to select "Basic" or "Cron" Schedule type. ...
by
oscarspaz
Explorer
in
Knowledge Management
01-12-2012
|
0
|
2
| |||
I was trying the use ./local/eventtypes.conf to override the values in ./default/eventtypes.conf. Using btool, it sho...
by
oscarspaz
Explorer
in
Knowledge Management
01-10-2012
|
0
|
4
| |||
I'm trying to build a running distinct count against a summary index. I came up with a solution, but it seems a littl...
by
vbumgarn
Path Finder
in
Knowledge Management
01-03-2012
|
0
|
1
| |||
I'm totally lost when it comes to arguments in macros. Here is what I want to do. I have three partial searches that ...
by
kmattern
Builder
in
Knowledge Management
12-30-2011
|
2
|
2
| |||
I've tagged my host field with their respective customer. I want to display the host as well as the tagged value in a...
by
lisheridan
Explorer
in
Knowledge Management
12-20-2011
|
0
|
1
| |||
I have a search to SI index=sec marker=01
sourcetype=cisco_firewall | bin _time span=5m | sistats count by log_lev...
by
Starlette
Contributor
in
Knowledge Management
09-26-2011
|
1
|
5
| |||
I am somewhat new to tags as a "Knowledge Management" tool, and I am reviewing the tags configured on my SPLUNK searc...
by
mfeeny1
Path Finder
in
Knowledge Management
11-21-2011
|
0
|
1
| |||
I have a little problem with summary indexing seemingly ignoring some fields.
My logfile looks like this:
# /ho...
by
seriea
Engager
in
Knowledge Management
06-30-2011
|
2
|
4
| |||
How can a device name be displayed for the IP address in the summary search window?
by
kmille2
Explorer
in
Knowledge Management
09-02-2010
|
0
|
7
| |||
Do I get to have my own website? And if I do, how do I go about creating one? That is mainly why I'm on here. TO crea...
by
kissinggame76
New Member
in
Knowledge Management
11-25-2011
|
0
|
1
| |||
We are reporting daily new user added in system. WE have recently moved to summary indexing and we are getting data. ...
by
sumitnagal
Path Finder
in
Knowledge Management
11-18-2011
|
0
|
1
| |||
Consider the following pair of macros, the former of which functions as expected whereas the latter fails with an err...
by
woodcock
Esteemed Legend
in
Knowledge Management
11-22-2011
|
0
|
1
| |||
The subject has the entirety of my question but as a bonus to anyone who reads this, here is a macro that everyone sh...
by
woodcock
Esteemed Legend
in
Knowledge Management
11-18-2011
|
1
|
4
| |||
Technically, summary indexing can be configured on either the search head or indexing server. Are there advantages/di...
by
hulahoop
Splunk Employee
in
Knowledge Management
03-03-2010
|
4
|
2
| |||
I have created a summary index,
from the following query (i called it base query), and the summary index co...
by
karche
Path Finder
in
Knowledge Management
11-03-2011
|
0
|
1
| |||
I need to set the "_time" of a summary index equal to the time of a field value. Like for example: Event:
...
by
lpolo
Motivator
in
Knowledge Management
10-24-2011
|
1
|
1
| |||
When developing an App for SplunkBase for widespread use, is it a good practice to put all of my app's data in a new ...
by
Jason
Motivator
in
Knowledge Management
01-25-2011
|
5
|
6
| |||
I have a saved search that i am running using the backfill script, but the data isn't showing up in the summary index...
by
beaumaris
Communicator
in
Knowledge Management
01-14-2011
|
1
|
2
| |||
hi i am using the below query to summary index
index=level3 earliest=+285min latest=+300min | eval volumegb=volum...
by
splunkingsplunk
Explorer
in
Knowledge Management
10-12-2011
|
0
|
2
| |||
I have si search "save" for every 5 mins as :
search = sourcetype="cisco_firewall" | sitimechart count
When run...
by
Starlette
Contributor
in
Knowledge Management
10-10-2011
|
0
|
2
|