Skip to content

Commit

Permalink
update
Browse files Browse the repository at this point in the history
  • Loading branch information
TonyPhipps committed Feb 22, 2024
1 parent c348de1 commit e536938
Showing 1 changed file with 5 additions and 1 deletion.
6 changes: 5 additions & 1 deletion Products/splunk.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,8 @@ index=_internal source=*license_usage.log* type=Usage idx=yourindex
| rename idx as index, st as sourcetype
```



## Search Quick Reference

| Goal | Example |
Expand Down Expand Up @@ -166,7 +168,9 @@ Check the latest 7 days for logs, then review the last one day. If a log source
| table title description disabled is_scheduled search cron_schedule actions action.email action.email.to action.email.message.alert alert.expires alert.severity alert.suppress alert.suppress.period alert_comparator alert_condition alert_threshold alert_type allow_skew display.events.fields eai:acl.sharing eai:acl.perms.read eai:acl.perms.write id
```

## Rex Magic
## Regular Expression / Regex / Rex
- If \t doesn't work, remember you can fall back to \s


### Derive the Application Logs within Linux:Messages

Expand Down

0 comments on commit e536938

Please sign in to comment.