The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: Posted by sgtquezada

Topics 1–12 of 12

Topic Author Replies Latest Post
Get Average Count per hour over time
In: SplunkSearchAndAlert (Not tagged)
For some reason this search query should be pretty straight forward. However, I am not coming up with ...
sgtquezada
Posts
23 months ago...
Search Form - Cannot save/export results via 'actions'
In: SplunkDev (Not tagged)
I recently created a search form for my department that allows them to lookup application session Ids. The ...
sgtquezada
Posts
1
27 months ago...
Limitation in character length in a search?
In: SplunkSearchAndAlert (Not tagged)
Hey - We monitor middleware SOAP logs and one of the ways we search is on session Ids. These can ...
sgtquezada
Posts
1
27 months ago...
Mask various credit card length using regex and SEDCMD- in props.conf
In: SplunkAdministration (Not tagged)
I read on the topic on how to mask credit card numbers at index by providing a proper regex/sed command ...
sgtquezada
Posts
1
27 months ago...
How to alert if avg(val) > X?
In: SplunkSearchAndAlert (Not tagged)
Sweet! thank you so much = )
I have a search that returns the value of a response time for a particular call. My initial search ...
sgtquezada
Posts
2
28 months ago...
Splunk AD Authentication (LDAP) - Sub-Group members not authenticating
In: SplunkAdministration (Not tagged)
I've configured splunk to use LDAP authentication using MS AD. It works well, but the only problem ...
sgtquezada
Posts
1
28 months ago...
outputs.conf - multiple target groups - data not showing up?
In: SplunkAdministration (Not tagged)
Excellent! I am receiving data now. Thanks for the info!
I configured a test windows forwarder to send data to two indexers via outputs.conf below is my config: [tcpout] [tcpout:prod_indexer] disabled ...
sgtquezada
Posts
2
29 months ago...
installing internal certificate for splunkweb ssl
In: SplunkAdministration (Not tagged)
SplunkwebSSL is set to true in my web.conf. That's not the issue. It works well with the default self-signed ...
Does anyone know the proper steps to take in order to install your own internal certificate for splunkweb ...
sgtquezada
Posts
4
33 months ago...
Cannot save Extracted Field
In: SplunkGeneral (Not tagged)
I am on ver 4.0.2 for the local indexer and when a user is attempting to extract a field and save it ...
sgtquezada
Posts
33 months ago...
How do you set up LDAP authentication using Microsoft Active Directory? (Part 1)
In: SplunkAdministration (Not tagged)
Does anyone know if Splunk can authenticate using distribution lists inside another AD group? It doesn't ...
scottprigge
Posts
6
33 months ago...
Deployment Server
In: SplunkAdministration (Not tagged)
I believe I am also having the same issue. The idea of a deployment Splunk server might be different ...
I am also fairly new to this but based on the documentation, you should be able to create multiple server ...
anon1m0us
Posts
12
34 months ago...
Automatic Header-Extraction
In: SplunkAdministration (Not tagged)
Does anyone know if automatic header extraction works in a distributed set up? For some reason the props.conf ...
sgtquezada
Posts
1
35 months ago...