URL : http://docs.splunk.com/Documentation/Splunk/5.0.1/SearchReference/SearchCheatsheet
URL in the
Display events from the file "messages.1" as if the events were indexed in Splunk.
"| File / var/log/messages.1"
Were tested with the contents of the manual
However, it does not work properly.
Search Command "file" Command does not use you asking?
Hello,
You may need to add the "use_file_operator
" capability into your role in order to use the "file" search command.
If my role doesn't have this capability, Splunk reports the error message; "You have insufficient privileges to perform this operation."
And the default admin role doesn't have it. So, you need to add it.
Thanks.
Hello,
You may need to add the "use_file_operator
" capability into your role in order to use the "file" search command.
If my role doesn't have this capability, Splunk reports the error message; "You have insufficient privileges to perform this operation."
And the default admin role doesn't have it. So, you need to add it.
Thanks.
Thank you.
Did not set the roles(use_file_operator).