Category "splunk-query"

Sending logs from fluentd to splunk

I am using log4j , so have different formats of logs. I am able to send most of the logs using the below multiline format from fluentd to splunk, but few of the

Output counts grouped by field values by for date in Splunk

I have a Splunk index named http_logs with the following fields: _time status_code status_text requester I'm trying to use this data to create a table that look

Parse nested Json to splunk query which has string

I have a multiple result for a macAddress which contains the device details. This is the sample data "data": { "a1:b2:c3:d4:11:22": { "d