<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Raw Logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521673#M147012</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The sourcetype=wms_oracle_sessions take the inputs from two oracle servers Ind1ora01 &amp;amp; Indora02.&lt;/P&gt;&lt;P&gt;Can we some how find , which logs it is taking as a Input.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 03:40:06 GMT</pubDate>
    <dc:creator>rahul2gupta</dc:creator>
    <dc:date>2020-09-28T03:40:06Z</dc:date>
    <item>
      <title>Raw Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521185#M146839</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;How do I fetch the raw logs for the source type :wms_oracle_sessions?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Query:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;index=main &lt;STRONG&gt;sourcetype=wms_oracle_sessions&lt;/STRONG&gt; | bucket span=5m _time | stats count AS sessions by _time,warehouse,machine,program | search warehouse=ew | stats sum(sessions) AS psessions by _time,program | timechart avg(psessions) by program&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 03:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521185#M146839</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-09-24T03:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Raw Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521210#M146847</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=main sourcetype=wms_oracle_sessions&lt;/LI-CODE&gt;&lt;P&gt;gives you the raw logs.&lt;/P&gt;&lt;P&gt;If you want to see the raw logs from the stats in your query, run it in verbose mode and look at the events&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 212px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10961i6AA45E686403AC7E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 236px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10962i7B19DDC23294B6C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 07:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521210#M146847</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-24T07:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Raw Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521214#M146850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;When I run the query,I see No Results found .&lt;/P&gt;&lt;P&gt;Does that mean there is no raw logs?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rahul2gupta_0-1600932126959.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10963iF8FACE86CA21D969/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rahul2gupta_0-1600932126959.png" alt="rahul2gupta_0-1600932126959.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 07:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521214#M146850</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-09-24T07:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Raw Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521216#M146852</link>
      <description>&lt;P&gt;Correct - as it suggests, try a different time period&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 07:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521216#M146852</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-24T07:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Raw Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521673#M147012</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The sourcetype=wms_oracle_sessions take the inputs from two oracle servers Ind1ora01 &amp;amp; Indora02.&lt;/P&gt;&lt;P&gt;Can we some how find , which logs it is taking as a Input.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 03:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521673#M147012</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-09-28T03:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Raw Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521692#M147015</link>
      <description>&lt;P&gt;I assume you have forwarders on the oracle servers which as configured to harvest logs and send them to the indexers in splunk. You need to look at the configuration of those to find out which paths they are using to find logs to send.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 06:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Raw-Logs/m-p/521692#M147015</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-28T06:31:33Z</dc:date>
    </item>
  </channel>
</rss>

