Search
  • Todd Waller

Splunk - Please verify your commands, it saves time

Hello Everyone!


This post is a bit of a facepalm moment but I fell like it may be important for someone that may have something they cant't figure out.


Sometimes we find a command or a solution to an issue and we dont slow down enought o look.


This happened to me today.


I grabbed a command from a page I have saved in docs and pasted it into the cli and things didn't work


For example(cleaned for security)

This kept happening over and over, why wasn't my command working:



Finally I asked someone with fresh eyes and they said type it manually


Difference?


Yeah, the first formatted improperly due to copy/paste, check out the "-"


Moral of the story, sometimes its easier to not be fast.


Have a great week!


-Cheers!


141 views0 comments

Recent Posts

See All

Do you need to dedup when using stats?

I had to do some casual counting of sourcetypes today. In the process I was trying to decide if I needed to dedup before going to stats. It seemed to me a dedup would, in theory, pass less data to sta

How do I learn Splunk administration?

Had an old coworker hit me up a week ago. He took a job as a SOC analyst where part of his job is going to be supporting Splunk. He's a smart guy but Splunk is more complex than it looks. Given I've a