Splunk #48
jlangy
announced in
Operations
Splunk
#48
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Reporting
We are using splunk as a reporting tool for our rh-sso instance.
Querying
You can search through our sso logs with sql using the
| es sql="..."
syntax. Make sure that your sql query limits the number of results as much as possible before piping into other splunk commands. SQL is limited to 1,000,000 events and will drop any over that amount, as well as run much more quickly. e.g usegroup by
in your sql if possible instead of aggregating in a plunk chart.Our data
The returned value from our sso-logs can include the following fields:
Beta Was this translation helpful? Give feedback.
All reactions