Splunk : Building the Knowledge Object change tracker dashboard

Поделиться
HTML-код
  • Опубликовано: 25 ноя 2024

Комментарии • 14

  • @venugopal-ss8ip
    @venugopal-ss8ip 2 года назад +1

    It's good channel for complete splunk, Thank you for sharing the knowledge

  • @venkat3983
    @venkat3983 2 года назад +1

    Thank you for the video,
    Please make videos on splunk version upgrades of clusters sh and indexer

  • @jeremywieland714
    @jeremywieland714 2 года назад +1

    Very useful, thank you

  • @bradlee4826
    @bradlee4826 2 года назад

    thanks for sharing!

  • @odelakumar06
    @odelakumar06 2 года назад

    Very useful sir

  • @mayanksword
    @mayanksword 2 года назад

    Hello Siddharth, how to track changes performed on correlation search by a user? (Identify user which performed the change on saved searches)
    I did look into /servicesNS/-/-/saved/searches, but dint see any usernames who performed changes:(

  • @eydersandino6088
    @eydersandino6088 Год назад

    Maracuyá 🤷🏻‍♂

  • @DavinStuder
    @DavinStuder 2 года назад

    This works great most of the time. However, I've found that in the config tracker log that there are times where an event has multiple stanzas that are updated. Each of those stanzas can have multiple properties and each property has and old and new value. So, to truly work you would need to account for the multiple stanzas as well. I tried just mvzipping the stanza on to the front, but that doesn't totally work. When I do that I only get the first property under the edited stanza.

    • @splunk_ml
      @splunk_ml  2 года назад

      Thank you Davin for pointing this out, I will do this fix in the next video.

  • @lakromani8172
    @lakromani8172 2 года назад

    What if time logged show 10:15:22.985 and the config tracker shows 10:15:23? Join will not happens since 10:15:22 is not equal to 10:15:23. Can this happen?

    • @splunk_ml
      @splunk_ml  2 года назад

      As far I have seen the log this should not happen. Anyway this is new feature in splunk 9 probably we need to keep an eye on this.

  • @lakromani8172
    @lakromani8172 2 года назад

    New nice video, but take care. Path in Linux do use / and not \ ans Windows do use, so this needs to be change for it to work in Linux. @Splunk & Machine Learning: I think it would be better if you change from using Splunk in Windows to use Splunk in Linux that most other use. I know it work mostly in Windows, but its created for and works better with Linux.

    • @splunk_ml
      @splunk_ml  2 года назад

      Yes true, I have mentioned about the path in the initial video, I should have mentioned it again here.

    • @visor617
      @visor617 Год назад

      @@splunk_ml I maybe a bit too late but in my case I have KOs from both windows and linux machines and well this works for windows paths. Any tips on how I can use the eval function to extract from both linux and windows paths?