Sir, Please make videos on upgradation of SH-Cluster and Index Cluster This will help us a lot
@venkatvenkat-nv7qn2 жыл бұрын
Sir, Please make videos on splunk version upgradation of SH-Cluster and Index Cluster, heavy forwarder This will help us a lot
@hemnaathgovartan30832 жыл бұрын
Hi Splunk guru, Yet another good video from you, I have question to you, I am facing a problem when creating an instance in GCP, that is dispatch directory is getting full even though I had created the instance with 20GB disk space, can you tell me how did you overcome this issue. As I see from your video there is warning ⚠️ sign seen in splunk consoles.
@mayanksword2 жыл бұрын
Hello Siddharth, how to track changes performed on correlation search by a user? (Identify user which performed the change on saved searches) I did look into /servicesNS/-/-/saved/searches, but dint see any usernames who performed changes:(
@pravinkumar-ci7jb Жыл бұрын
In Splunk v9.0 you can see the changes made by user on correlation search It might help you index=_audit action=create_saved_search actions=* app=* disabled=* info=* user=* | table _time savedsearch user action actions app disabled info
@mayanksword Жыл бұрын
@@pravinkumar-ci7jb thank you. I did find it under index=_configtracker. However, the limitation is, to identify the user who performed the change is the challenge. We could find this in _internal and sometimes in _audit as well!
@jeremywieland7142 жыл бұрын
Great content as always, love your videos.
@bradlee48262 жыл бұрын
thank you for sharing this good video!
@splunk_ml2 жыл бұрын
Thank you for always giving feedback on my videos, it means a lot