The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: Posted by TobiasBoone
| Topic | Author | Replies | Latest Post |
|---|---|---|---|
|
Custom Criteria to send report
In: SplunkReporting
(Not tagged)
tag::host="dc" "EventCode=4625" NOT Account_Name2=*$ | stats count(Source_Network_Address) as totalbadsbymachine ...
|
–
|
20 months ago... | |
|
TZ usage specifics
In: SplunkGeneral
(Not tagged)
What ended up being the solution? I have the same issue. Tried the props.conf on both the indexer ...
|
11
|
33 months ago... | |
|
new 'EDIT USER" syntax in 4.01?
In: SplunkAdministration
(Not tagged)
used to be I could run:
splunk edit user admin -password newpass -auth admin:changeme
now it returns ...
|
–
|
34 months ago... | |
|
Splunk 4 Forwarder Licensing
In: SplunkAdministration
(Not tagged)
On my 3.4.x forwarders and lightforwarders, I would copy the receiving systems splunk-forwarder.license ...
|
1
|
35 months ago... | |
|
Set global search time (past 15 minutes) as default
In: SplunkAdministration
(Not tagged)
In 4.0 I am stupified as to how to set the default search time parameters to be 15 minutes instead of ...
|
2
|
35 months ago... | |
|
Delete host data
In: SplunkAdministration
(Not tagged)
May be worth updating that article...
I need to do some host cleanup (I didn't know what I was doing with hosttag's initially) I found ... |
2
|
35 months ago... |