Removing Splunk Chrome Modules
Is it possible to remove the Splunk Chrome Modules from a dashboard written in Simple XML? Thanks!
View Articledisplaying icons in search
Is there any way to do a lookup on a value and display an icon for that value? I would like to do application ID lookups and put the icons in place.
View Articlecan i have a trend line graph on a bar graph ??
Hi,i have a bar graph . can i add a line overlay on this bar graph ?? i mean i need a straight line appering on top of this bar graph ?? is it possible ??
View Articlehow to disable the data for metrics.log ??
Hi..How can i disable / restrict the data to the metrics.log at forwarder level...can anyone pls help. i have changed the sizes in log.cfg file but then i could the metrics data..###...
View ArticleStats command perfomance issue ?
HI..Wen i am trying to search raw events for my query .. say something like this.report_name="MainReport" (xmlg_message="Request document" OR b2b_LText="Received request " OR...
View ArticleForwaders hosts are also being displayed as comsumed data
Hi I have used the following query to find indexer host wise mb consumed in indexeing. index=_internal source=*metrics.log group=per_index_thruput series="Myindex" | eval MB=kb/1024 | stats sum(MB) by...
View ArticleChange hostname transform
We have a host where logs are aggregated already. I want to Splunk these logs. The source host for the logs is in the file path. I attempted the below props/transforms as a PoC, but no luck. Can anyone...
View Articlecan we avoid the scrollbar appearing in pulldown module ?
Hi.Is there any way to disable or adjust the scrollbar of the pulldown module list ? i.e when ever i am having a huge list scroll bar is appearing..can i make it disable or adjust its length ??
View ArticleStyle Sheet Help ?
Hi ,I am using Style sheet as follows.<style type="text/css"> .SplunkModule.Pulldown,.SplunkModule.Button,#TimeRangePicker_0_3_0 { float:left; padding-left:15px; } </style> which must give...
View Articlesetup user authentication with TAM-Tivoli Access Manager
Hi All! Did anyone ever integrate Splunk Authentication with TAM - Tivoli Access Manager? we're asked to do that but we don't know if TAM is a sort of LDAP like system or what.Thanks for support!Marco
View Articlewat is nx mean in summary index data ?
Hi..While i am running sistats command i am getting so many fields with nc,nx,ss and so on..can anyone pls explain wat are these fields for ?? and can we use these fields to sum of two events ..say i...
View ArticleAuthentication Failed after starting the app
hmm, I can“t try it out cause I get -- after starting the app, and loading 100% -- an error: Authentication FailedWhat which authentication???Looks like a redirecting problem, error shows...
View Articledb connect to db2...
Hi,I'm trying to connect to a DB2 db, via DB Connect and ODBC. I keep getting some generic error (see below). Has anyone seen this? Is there anything else that needs to be done when using...
View ArticleHow can i set valusetter module for dynamic pulldown ??
Hi .I have a dynamic pulldown which will have values generated dynamically . Now my requirement is in the dynamic pulldown.. when ever the dashboard is loaded i want the first value of the pulldown...
View Articlediscard not needed events
Hi, I am new to splunk, I only want to forward specific events to splunk (for example: failures)and discard the rest.In the props.conf file I added these lines below [WMI:WinEventLog:Security]...
View ArticleCan I use rex/regex in split() in deliminator?
Hi,I am facing problem in split() in eval query. Is there a way to add rex/regex in split function to as deliminator?I have a field with a value in really big string and i want to split the word based...
View ArticleHow do you include index/sourcetype in table data? (e.g. | table ..., ...,...
Hey guys, having a little trouble with this one.How does one include the index in a table. This doesn't work:(index=cwdswindows OR index=cwds) earliest_time="-7d"| stats max(_time) AS last_seen by host...
View Article_audit index not getting replicated in clustering
_audit index is not getting replicated in clustering.
View Articleeval an existing field which is used for a lookup...
Hi Base, when I do an eval on an existing field which is also used for a lookup than the lookup ignores the eval result and use the origin instead. f.e. I have IP addresses from 2 fields fieldIpA and...
View ArticleHow do I clean a clustered index?
What's the best way to completely clean an index in a clustered environment?
View Article