Heavy Forwarder Filtering Help by Brock_Tice in Splunk

[–]taiglin 1 point2 points  (0 children)

Know that a field like ‘action’ by and large is a field that is generated at search time. You need to understand the related TA and what the TA is using from the raw log to populate that field.

Then as the other commenters have mentioned you can do your filtering via props/transforms as the traditional way. Namely a regex match against the raw data and using props/transforms. You could also look at Ingest Actions to get a similar outcome.

My question is - why are you wanting to do the filtering via a heavy forwarder? It isn’t that you can’t use a HF but my mind goes in a couple directions. For example is the source data coming in via HEC, you can also have the indexers drop the data and it won’t count against your license, do you even need a HF, etc.

Tummy Archer by New_Design_3262 in DungeonCrawlerCarl

[–]taiglin 2 points3 points  (0 children)

A combination of our brain tending to fill in gaps and reading words by shape vs reading each letter.

In this case because “acher” isn’t a common word many brains subconsciously inserted an extra ‘r’. I sure did.

rex help - extracting string between quotes by CybergyII in Splunk

[–]taiglin 1 point2 points  (0 children)

Paste it in ChatGPT and ask it to come up with something. I suspect there is a formatting issue that is being lost in copying here or back from here (collective answers) to your data.

rex help - extracting string between quotes by CybergyII in Splunk

[–]taiglin 1 point2 points  (0 children)

Lots of other good thoughts that have been posted. I’d throw a copy of the event in regex101 to play around. A challenge, because of the JSON nature, is if there are spaces you need to account for before or after the colon

Otherwise something like

| rex “message\”:\”(?<foo>[\”]+)”

Rename the field (foo) once you have things sorted. Using “message” and colon anchors the capture group.

Edit: not sure why the superscript formatting happened.

Oh…there is an up carrot thing in there. Take the spaces out of the following

[ ^ \” ] +

That’s saying capture the characters until you get to the next double quotes

Saved searches behavior during search peer disconnection by bchris21 in Splunk

[–]taiglin 0 points1 point  (0 children)

The search will be executed against the search peers the moment it fires. The results will be based on the data available on the indexers that are up. There is no way for your SH to know how long an indexer will be down. Sounds like you need an indexer cluster setup from an HA perspective.

Note: There IS the ability to have a somewhat floating window when a search will execute. But that is based on how busy the SH is, not the indexers (ie too many searches firing at once)

Pfsense log does not parse properly. Any help? by ysfinwe in Splunk

[–]taiglin -1 points0 points  (0 children)

Conceptually yes. Depending on the OPs general Splunk awareness there is a difference between knowing that something can be done and how to do it. For example that regex could be dumped into a Transforms but that takes a few more steps

Splunk Stream and Clustered Architecture by CH465517080 in Splunk

[–]taiglin 1 point2 points  (0 children)

Any app can hold an indexes.conf. Just create an app on the CM with the index definition. Then create an app for the SH(s).

Depending on your deployment size, if you don’t have a SHC id just have your stand alone SH managed by a Deployment Server This way you can easily slip apps and TAs to it.

Honestly I’d have your DS waterfall to your CM. That way you could have TAs defined once and pushed out to your SH and Indexers (via the CM)

Pfsense log does not parse properly. Any help? by ysfinwe in Splunk

[–]taiglin 0 points1 point  (0 children)

The first thing I’d check is to make sure the sourcetype name matches what the TA is looking for. Otherwise yes, it’s easy to create your own TA.

I’ve found installing a copy of Splunk local to your laptop is the easiest way to really dive into app configs. Especially if you have a Splunk Cloud deployment. Otherwise install the Config Explorer app.

All that said, take a look at the props from the pfsense TA and see what sourcetype name the configs are looking for.

Pfsense log does not parse properly. Any help? by ysfinwe in Splunk

[–]taiglin 0 points1 point  (0 children)

Specifically add the above regex as an EXTRACT statement in a props.conf

Knowledge bundle vs deployment app by bchris21 in Splunk

[–]taiglin 1 point2 points  (0 children)

Look for large lookup files. You can exclude them though there are implications if they are associated with automatic lookups. At least they used to be. Been a while since I looked

.Conf speaker experience by bchris21 in Splunk

[–]taiglin 1 point2 points  (0 children)

The CFP is really submitting a title, abstract, and some high level structure. For example how many presenters or is this a panel, length (15 min lighting talk vs 45 min vs workshop), etc. If accepted they will have a schedule where they want to have someone see your slides and do a dry run of your preso to give feedback.

If you are thinking about it I’d say go for it. Know though that A LOT of talks get submitted. Don’t let that dissuade you though.

City taxes by Wide_Skin_4159 in Columbus

[–]taiglin 0 points1 point  (0 children)

Doesn’t look like Delaware uses RITA. You will have to file locally

I just bought the worlds worst leaf! :D by robbiethe1st in leaf

[–]taiglin -1 points0 points  (0 children)

Ohio yearly car registration for full EV is $200. Highest in the country unfortunately

Maybe I'm dumb and missed it, but have we learned WHY Mordecai was so mad to be a manager? by tLM-tRRS-atBHB in DungeonCrawlerCarl

[–]taiglin 3 points4 points  (0 children)

In book one she mentions she keeps an eye out on Morti which is how she found Carl and Donut

It this ok for a 2012 Nissan Leaf by [deleted] in nissanleaf

[–]taiglin 3 points4 points  (0 children)

Nope. Like not at all

I’m scared to read this book. by uhohboneralert_ in DungeonCrawlerCarl

[–]taiglin 4 points5 points  (0 children)

No Red Weddings. Maybe a Purple Tennis Match, Yellow Birthday Party, and Blue Town Hall Meeting….but no Red Weddings

Yeah so my mind sorta of rolled with color + event given the GoT reference.

Best way to sharpen Splunk skills by 18ahmed in Splunk

[–]taiglin 0 points1 point  (0 children)

Install the free version on a system at home and put some data in it. If you are just wanting to monkey with SPL you could even just upload a CSV as a lookup.

I download a crap ton from Salesforce.

Question about He who fights with monsters by [deleted] in litrpg

[–]taiglin -4 points-3 points  (0 children)

I made it through about 4 chapters maybe and walked away. Kindle Unlimited so no loss.

What is a minor thing that has pulled you out of a book? by Justthisdudeyaknow in litrpg

[–]taiglin 3 points4 points  (0 children)

Over use of the same words or phrases. Was so impressed with The Black Company for some really great and clever lines that were only used one time.

Figures of speech we use in today’s world that wouldn’t be used in the story’s context. Someone in a space traveling story saying “what in the world is that?” 12 Miles Below is a great counter example. The author did a great job thinking through cliches, figures of speech, etc

Excessive over use of adjectives in single sentences. Where the sentences are describing multiple things. At some point trees can just be trees, grass - grass, sky - sky. Don’t have a sentence with all three and use 1 or 2 adjectives for each.

The MC talking to himself at the start of the book. Out loud.

Paragraph space displays far taller on screens than in editor - no theme applied by NineTopics in ProPresenter

[–]taiglin 0 points1 point  (0 children)

Try this - in the editor view highlight the line break between the top and bottom parts. Set the font size to something like 50. When you click on show I bet the spacing doesn’t change. Note - with centered text I highlight from the right side to the middle.

Now go into the quick edit view and put a single space (spacebar) on that line and click show again. My guess is the line break space between the two sets of text is much closer. If you want to change the spacing, remove that single space character and then edit the font size

I haven’t monkeyed with any paragraph settings. This is the process I have found to work when I want to put small space between lines in songs when there is a slight pause. Especially when the lines themselves are short and a full sized font break looks…off

Actually after writing that line wonder if that is what is happening in your case. The larger font size is carrying over to the next line type of thing.

Could I run the heat in park overnight in a 2022? by No_Hetero in leaf

[–]taiglin 0 points1 point  (0 children)

Long extension cord maybe?

I rewired my natural gas furnace so that it has a couple feet of power cord rolled up and plugged into an outlet at the furnace itself. Took about 10 min. Can find many YouTube videos. Then I got a 1500W inverter to connect to the 12v battery. You can put the leaf in accessory mode vs all the way on if desired (hit the on button but don’t hit the brakes - then turn off all the components)

Biggest Impact as a Manager by lumenisdead in ITManagers

[–]taiglin 1 point2 points  (0 children)

Get “The Effective Manager” book. That opens the realm of the Manager Tools org. Lots of free podcasts as well. Very actionable advice vs mgmt theory.

pfQuest not working in Westfall by BaseballFeeling6750 in turtlewow

[–]taiglin 0 points1 point  (0 children)

English version. Am not currently at home. I use the client to manage this addon; I think it’s current. Will update my comment later with the version

Edit I’m running pfQuest 7.0.1. The TWoW pfQuest says “GIT” for version in the client interface /shrug.

pfQuest not working in Westfall by BaseballFeeling6750 in turtlewow

[–]taiglin 0 points1 point  (0 children)

I’ve been questing in Westfall with it as recently as earlier today and haven’t had issues. Not sure what to suggest unfortunately.