Splunk 3.1.4 30364 (Default branch)


 
Thread Tools Search this Thread
Special Forums News, Links, Events and Announcements Software Releases - RSS News Splunk 3.1.4 30364 (Default branch)
# 1  
Old 12-28-2007
Splunk 3.1.4 30364 (Default branch)

Image Splunk is a search engine that indexes and lets you search, navigate, alert, and report on data from any application, server, or network device. It lets you securely access logs, configurations, scripts and code, messages, traps and alerts, activity reports, stack traces, and metrics across thousands of components from one place in real time. This data can include Apache logs, Sendmail logs, J2EE events, custom application logs, configuration files, or any other type of file that a sysadmin or developer will need to examine on a regular basis. License: Other/Proprietary License with Free Trial Changes:
Search strings can now contain variables that are rendered as form elements in the SplunkWeb interface. When used with saved searches, inexperienced users can search efficiently without knowing the details of the search language. This feature simplifies searching by asking the user to input exactly the parameters sought, instead of a complete and potentially complex search. As part of a general effort to simplify the search language, equal signs can now be used where double colons were required.Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

1 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

PHP script that detects if auth is required or not on Apache Splunk

I am currently trying to do a PHP script that detects automatically if Apache Splunk authentication is required or not but I'm having a hard time since HTTP code 303 is always coming back, even if auth is required or not. Here is the script so far; <?php /** * Apache Splunk script to... (4 Replies)
Discussion started by: syrius
4 Replies
Login or Register to Ask a Question
AUSEARCH_ADD_REGEX(3)						  Linux Audit API					     AUSEARCH_ADD_REGEX(3)

NAME
ausearch_add_regex - use regular expression search rule SYNOPSIS
#include <auparse.h> int ausearch_add_regex(auparse_state_t *au, const char *expr); DESCRIPTION
ausearch_add_regex adds one search condition based on a regular expression to the current audit search expression. The search conditions can then be used to scan logs, files, or buffers for something of interest. The regular expression follows the posix extended regular expression conventions, and is matched against the full record (without interpreting field values). If an existing search expression E is already defined, this function replaces it by (E && this_regexp). RETURN VALUE
Returns -1 if an error occurs; otherwise, 0 for success. SEE ALSO
ausearch_add_expression(3), ausearch_add_item(3), ausearch_clear(3), ausearch_next_event(3), regcomp(3). AUTHOR
Steve Grubb Red Hat Sept 2007 AUSEARCH_ADD_REGEX(3)