The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by rm90495

Topics 1–5 of 5

Topic Author Replies Latest Post
Converting to Epoch time and subtracting.
In: SplunkAdministration (Not tagged)
Internally splunk uses epoch time so you can use this at the end of your search {{ | eval end_time=_time ...
eploughe
Posts
1
23 months ago...
Customizing emailed reports
In: SplunkAdministration (Not tagged)
Grrrrr The splunkbase reorg hits again. **The above link does not work** I've found it at :- h...
jhart@edmunds.com
Posts
7
39 months ago...
What are savedsearches.conf-local for
In: SplunkApplications (Not tagged)
OK thanks. It makes sense but could do with pointing out somewhere in the docs.
I have noticed a number of apps (eg netsec) have a {{etc/apps/apname/default}} folder containing a {{savedsearches.conf-local}} ...
rm90495
Posts
2
39 months ago...
Extracting the Host from a filename
In: SplunkApplications (Not tagged)
actually the \S above will pick up anything other than a space (or tab) so it would incorrectly pick ...
if you add a stanza like this to your inputs.conf {{[monitor:///var/log] disabled = false host_regex ...
mvanaswegen
Posts
6
39 months ago...
Splunk for VMWare
In: SplunkApplications (Not tagged)
A client has installed this and is complaining "//I have installed the VMWare for Splunk app, but all ...
wibbit
Posts
3
42 months ago...