With that out of the way here is the query:
Monday, May 5, 2014
Splunk DateParserVerbose logs - Part 2
In part 1 of this subject we talked about what Splunk's DateParserVerbose internal logs are and I gave an example query that at its heart attempts to rollup and summarize timestamp related issues. In this post I'll present a query for taking the sourcetypes Splunk is having issues with from a timestamp perspective and display the relevant props configs. What we've done is thrown both queries into the same dashboard to make things easier to work though. I should note a couple things here. The first is the foreach command is only available in Splunk 6 (I believe). The second is the REST endpoint I'm getting the config data from is likely only available in 6.
Labels:
Administration,
Data Management,
Monitor,
Performance,
Splunk
Subscribe to:
Posts (Atom)