Quantcast
Channel: Questions in topic: "splunk-enterprise"
Browsing all 47296 articles
Browse latest View live
↧

Help with timewrap Command

Hi, I am trying to show a comparison of traffic on my website for today, yesterday and last week. I am using below query for getting the results. My query is if i put that into a chart then on x-axis,...

View Article


Assign subsearches to multple fields and evaluate their additions/substractions

I have a base search and there are multiple events that I can find depending on some set of the subtstring. Let's say A, B, C I just want to get the counts of these events and calculate a single result...

View Article


How to extract words and digits from a particular field

Hello everyone, I am trying to extract strings containing SAMM #2222-A-1111 from other strings in a field named SAMU This is what I have entered SAMU="SAMM*" "#2*" "-*" It works but also output other...

View Article

Monitor files in a Windows Directory with wildcards

I am having a problem trying to monitor some files on some Windows servers. The directories that I am trying to pick up the files from are: **D:\webroot\www.foo1.foo.cd\App_Data\logs...

View Article

Splunk App for Infrastructure: Error message on search head

Splunk App for Infrastructure data collection on Search Head Followed: https://docs.splunk.com/Documentation/InfraApp/2.0.0/Admin/ManualInstalLinuxUF Environment: Search Head 7.3.0 Indexer 7.3.0 Setup:...

View Article


How to assign subsearches to multiple fields and evaluate their...

I have a base search and there are multiple events that I can find depending on some set of the subtstring. Let's say A, B, C I just want to get the counts of these events and calculate a single result...

View Article

Remove data after moving index location

I just moved my homePath and coldPath to a new location, and wanted to delete the data stored on Splunk's default index location ($SPLUNK_DB). I would leave it, but it's using the bulk of that...

View Article

How to join fields that have different values

I need to join two searches that do not have a common fields. First search has a field **FileName=Test.json** Second search has field **FileName=Test.json.pgp** How do I join the two searches? Thanks

View Article


Why does syslog data delay when setting no_priority_stripping=true?

Hi, When I set no_priority_stripping = true in input.conf in Splunk server, my syslog data send to Splunk work but a very long delay of time. When I remove no_priority_stripping = true from input.conf....

View Article


How to match index search results to CSV lookup

I have a search that returns information about usernames and their IP, machine name, etc. I want to cross-reference a CSV lookup that has a list of usernames and then the search result would only show...

View Article

Is it possible to route events to particular license pool based on host or...

Hi, We have a situation where we want to have multiple pools in our license master and each pool should index data from specific host. We don't want multiple indexer OR license master to achieve this....

View Article

I'm trying to use makeresults to test an alert but it doesn't work

I'm trying to use makeresults to test an alert but it doesn't work because "number of events" is always 0, but I thought the point of makeresults is to always make events?

View Article

Sending logs to HEC endpoint

Hi, I need to sent logs to HEC through HTTP. Only available option via HTTPEVNTCollector APPender. But Httpeventcollector is Layout Based. But i am using Encoder in my project. Can anyone suggest...

View Article


How do I send just the value of token $job.resultCount$ to a webhook?

We have a simple alert with a Webook action assigned to it with an endpoint is OMI. Search: index=xyz TCP_ERROR appName="jojothedolphin" Alert: If number of results > 10 After the alert is...

View Article

timecharting 2 seperate data sources with a case statement. What about this...

Something about this search makes it so we absolutely never get into the case that would label the column "msad". I have tried switching everything up: Making the zscaler case first, changing the msad...

View Article


Syslog event timesteamp not display in correct format with...

Hi, How do I display the correct syslog event timestamp in Splunk. this is Syslog Event timestamp when display in Splunk with no_priority_stripping=true. 2019-11-14T14:34:02-08:00 I want to display...

View Article

Do I need to meet all course prerequisites to take a class?

I would like to take and advance class that has course prerequisites. Do I need to meet all requirements in order to register?

View Article


How to add text fields to dashboard to specify start and end time filter ?

We have a dashboard and wanted to add text fields to enter start date with time and end date with time say (11/13/2019 08:00 pm - 11/14/2019 10:00 AM) so that dashboard should be updated according to...

View Article

Support for Python 3 ?

Hello @starcher Are you planning to upgrade you app to support Python 3 / Splunk 8.x.x ? It would be great. Thanks.

View Article

error when executing samlpull command

I installed your app on a SHC with SAML (ADFS) configured. When executing | samlpull, I get an error. Inside log, I see: 11-15-2019 09:23:26.615 ERROR ScriptRunner - stderr from '.../splunk/bin/python...

View Article
Browsing all 47296 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>