The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by TobiasBoone

Topics 1–6 of 6

Topic Author Replies Latest Post
Custom Criteria to send report
In: SplunkReporting (Not tagged)
tag::host="dc" "EventCode=4625" NOT Account_Name2=*$ | stats count(Source_Network_Address) as totalbadsbymachine ...
TobiasBoone
Posts
20 months ago...
TZ usage specifics
In: SplunkGeneral (Not tagged)
What ended up being the solution? I have the same issue. Tried the props.conf on both the indexer ...
cpen
Posts
11
33 months ago...
new 'EDIT USER" syntax in 4.01?
In: SplunkAdministration (Not tagged)
used to be I could run: splunk edit user admin -password newpass -auth admin:changeme now it returns ...
TobiasBoone
Posts
34 months ago...
Splunk 4 Forwarder Licensing
In: SplunkAdministration (Not tagged)
On my 3.4.x forwarders and lightforwarders, I would copy the receiving systems splunk-forwarder.license ...
TobiasBoone
Posts
1
35 months ago...
Set global search time (past 15 minutes) as default
In: SplunkAdministration (Not tagged)
In 4.0 I am stupified as to how to set the default search time parameters to be 15 minutes instead of ...
TobiasBoone
Posts
2
35 months ago...
Delete host data
In: SplunkAdministration (Not tagged)
May be worth updating that article...
I need to do some host cleanup (I didn't know what I was doing with hosttag's initially) I found ...
TobiasBoone
Posts
2
35 months ago...