| rest splunk_server=local /services/deployment/server/serverclasses | table title whitelist* blacklist*
0 comments
| rest splunk_server=local /services/deployment/server/clients | eval now=now(), diffTime=now-lastPhoneHomeTime, lastPhoneHomeTime=strftime(lastPhoneHomeTime,"%b %d, %Y %H:%M:%S") | search diffTime>86400 | table hostname ip instanceName utsname package splunkVersion lastPhoneHomeTime
0 comments
| rest splunk_server=local /services/deployment/server/clients | table hostname ip instanceName utsname package splunkVersion
0 comments
| rest /services/apps/local | search disabled IN ("false",0)| table title version description splunk_server
0 comments
index=* | stats count by _raw, index, sourcetype, source, host | where count>1
0 comments
index=* | stats count by _raw, index, sourcetype | where count>1 | stats values(sourcetype) as sourcetype by index
0 comments
index=_internal earliest=@d latest=now | stats latest(_time) as _time, values(view) as view, values(app) as app, values(uri) as uri by user
0 comments
index=_internal earliest=-5m latest=now sourcetype=splunk_web_access user!="internal_monitoring" user!="-" | stats count by user | fields - count
0 comments
index=_audit sourcetype=audittrail savedsearch_name=<insert search title> earliest=-365d | stats earliest(_time) as created | eval created=strftime(created,"%m/%d/%Y %H:%M:%S")
0 comments
| rest /services/server/status/resource-usage/hostwide | eval cpu_count = if(isnull(cpu_count), "N/A", cpu_count), cpu_usage = (cpu_system_pct + cpu_user_pct), mem_used_pct = round((mem_used/mem)*100 , 2), mem_used = tostring(round(mem_used/1024, 3),"commas"), mem = tostring(round(mem/1024, 0),"commas") | fields splunk_server, cpu_count, cpu_usage, mem, mem_used, mem_used_pct | sort - cpu_usage, - mem_used_pct | rename splunk_server AS "Splunk Server", cpu_count AS "CPU Cores", cpu_usage AS "CPU Used (%)", mem AS "Memory Capacity (GB)", mem_used AS "Memory Used (GB)", mem_used_pct AS "Memory Used (%)"
0 comments