Thread Info | |||||
---|---|---|---|---|---|
Where index retirement policies are concerned, if you define both size and age I assume first policy type hit wins?
by
ualbanytech
Path Finder
in
Splunk Search
04-05-2011
|
0
|
4
| |||
We need advice on setting up search head(s). We have set up a distributed search system with 12 indexers and 2 search...
by
mctester
Communicator
in
Splunk Search
09-14-2010
|
1
|
6
| |||
Hi,
I would like to combine two searches. The first one gives me the session-id which i would like to use in a sec...
by
kochera
Communicator
in
Splunk Search
04-05-2011
|
1
|
6
| |||
What's the best way to retrieve stats from multiple reports in the summary index? We have a remote client that will u...
by
beaumaris
Communicator
in
Splunk Search
04-04-2011
|
1
|
4
| |||
When trying to run a search from a remote CLI instance, I keep getting a 404.
The command-line I'm running is:
...
by
bcotton
Engager
in
Splunk Search
04-04-2011
|
1
|
1
| |||
I'm using timechart to show the number of connections we have over a collection of servers. When these servers go thr...
by
dang
Path Finder
in
Splunk Search
03-28-2011
|
1
|
4
| |||
Hi,
I encountered a problem with the splunk indexing.
I developed a script to invoke tshark to generate HTTP ...
by
wanling
Path Finder
in
Splunk Search
04-04-2011
|
0
|
2
| |||
"?" and escape permutations don't seem to work.
by
piebob
Splunk Employee
in
Splunk Search
04-03-2011
|
2
|
1
| |||
"Enable configuration changes made to transforms.conf by typing the following search in Splunk Web: | extract reload=...
by
s6a9d6u9s
New Member
in
Splunk Search
04-01-2011
|
0
|
4
| |||
I have performance data captured with Splunk with fields and data like this:
DatabaseCachePercentHit=0 Databas...
by
jamesklassen
Path Finder
in
Splunk Search
03-25-2011
|
0
|
2
| |||
How does Splunk determine which fields to add to "other interesting fields"?
by
rroberts
Splunk Employee
in
Splunk Search
04-01-2011
|
2
|
3
| |||
Hi
I am at a loss on how to approach this problem. Lets say we have the following data:
Input 1: Contains list...
by
sranga
Path Finder
in
Splunk Search
03-30-2011
|
1
|
5
| |||
Are there any way to further customize the setup.xml file for my app?
I'm trying to include some radio-buttons, or...
by
klee310
Communicator
in
Splunk Search
04-01-2011
|
0
|
2
| |||
host=myserver JobWrapper | transaction keepevicted=true jobid
| where job="provisioningJob" | stats max(duration) AS...
by
bowa
Path Finder
in
Splunk Search
03-31-2011
|
1
|
7
| |||
I have a setup.xml and a myappsetup.conf all setup properly (lets make that assumption for now, still many bugs to ir...
by
klee310
Communicator
in
Splunk Search
03-31-2011
|
0
|
2
| |||
I am looking for the best way to search multiple IP ranges. Currently I am using rex as follows
sourcetype=mysourc...
by
bsteelz93
Path Finder
in
Splunk Search
03-29-2011
|
0
|
3
| |||
Hi,
Is there a search or metrics.log that one can get an idea of the amount of data/events being sent to the nullq...
by
ephemeric
Contributor
in
Splunk Search
03-25-2011
|
1
|
3
| |||
Hey everyone. I am trying to bind the forwarding service to a particular IP because one of the boxes we are using as ...
by
msarro
Builder
in
Splunk Search
03-30-2011
|
0
|
2
| |||
Hello. I am giving this software a testdrive on one of my servers. Accidently I pointed to a log-directory holding 23...
by
tore_stensby
New Member
in
Splunk Search
03-31-2011
|
0
|
1
| |||
Using the documentation reference from here, I am trying to create a setup screen for my application which uses both ...
by
klee310
Communicator
in
Splunk Search
03-31-2011
|
0
|
4
| |||
I have a chart with numbers in millions, e.g. 430938493293. How do I display it such that it shows 430,938 in million...
by
wyang6
Path Finder
in
Splunk Search
03-30-2011
|
1
|
1
| |||
index and alert if any host over the last 30 minutes sees more than 1k of messages.
How do I do this?
by
postrowski
New Member
in
Splunk Search
03-02-2011
|
0
|
2
| |||
All,
I am trying to remove duplicate values in a list of email addresses. First, I am loading this from a CSV, ins...
by
jgauthier
Contributor
in
Splunk Search
03-30-2011
|
0
|
4
| |||
Hi,
I have a search that looks kinda like this:
host=host1 OR host=host2 AND (errcode=E OR errcode=R) | dedup ...
by
ostoul
Engager
in
Splunk Search
03-30-2011
|
1
|
3
| |||
sourcetype=syslog "CPU Temp" | sort –CPU_Temp | table host CPU_Temp
CPU_Temp is a field with a numerical value (Te...
by
beaunewcomb
Communicator
in
Splunk Search
03-29-2011
|
1
|
3
|