Thread Info | |||||
---|---|---|---|---|---|
host=dummy | eval Pattern='arb_usg_mps%06' | where like (source,'%Pattern%') doesnot work . can you help what's wron...
by
smuderasi
Explorer
in
Splunk Search
08-02-2017
|
0
|
2
| |||
I am receiving the audit.log data from a universal forwarder running on a Linux box
Hello below is my search strin...
by
jcorkey
Explorer
in
Splunk Search
08-02-2017
|
0
|
1
| |||
trying to search for when sudo user1 adds user2 to a group and I want to extract the name of the user2 that was added...
by
jcorkey
Explorer
in
Splunk Search
08-02-2017
|
0
|
1
| |||
Want to label sc_status <= 304 as Ok and sc_status >= 400 as Error and get the Ok and Error counts and table the clie...
by
lim2
Communicator
in
Splunk Search
08-02-2017
|
0
|
1
| |||
I have a simple search query to look for vpn alerts
index=nm host = inyod1-jvpn1a-dmz8-lo0 syslog_message="*karach...
by
ringbbg
Engager
in
Splunk Search
07-31-2017
|
0
|
3
| |||
I am very new to regex and I need to extract anything that comes between "device_" and "_1_vol" as volume name.
"...
by
jerin1982
New Member
in
Splunk Search
08-02-2017
|
0
|
4
| |||
I want to create a timechart based on 5 tags. I have tried | timechart count by tag |regex tag="Working|No_Images|Oth...
by
sarahw3
Explorer
in
Splunk Search
08-02-2017
|
0
|
3
| |||
I trying figure out what is the best search query for reporting on the count of different unique status. Following is...
by
t_splunk_d
Path Finder
in
Splunk Search
08-01-2017
|
0
|
3
| |||
Hi there, i try to buildup a firewall report:
"sourcetype="firewall" action=blocked | table host src dest src_port...
by
Aufex
Explorer
in
Splunk Search
07-31-2017
|
0
|
3
| |||
I am using the following splunk query
to combine the events in to one transaction based on the referenceid. It wo...
by
nkannan1984
Engager
in
Splunk Search
07-27-2017
|
0
|
3
| |||
Hi,
I'm trying to replace the host value using a field in the data. I tried to find any previous similar solution ...
by
tamakg
Path Finder
in
Splunk Search
08-01-2017
|
0
|
4
| |||
THis is my query i want to display a time chart where it should display the last 4week ( week by week) in a time char...
by
rijinc
Explorer
in
Splunk Search
08-01-2017
|
0
|
12
| |||
Below is my search string:
index=* host=* sourcetype="*" "usermod" "add" "to shadow group" | rex "^(?:[^'\n]*'){3}...
by
jcorkey
Explorer
in
Splunk Search
08-01-2017
|
0
|
2
| |||
What is the difference between with or without using OUTPUT parameter in lookup command.
by
ankithreddy777
Contributor
in
Splunk Search
08-01-2017
|
0
|
2
| |||
I'm running a query for a 1 hour window. I need to group events by a unique ID and categorize them based on another f...
by
wormfishin
Engager
in
Splunk Search
03-20-2014
|
1
|
4
| |||
I need only amber and severe but i am not getting any result
base search|eval responseTime=TransactionEndtime-Tra...
by
karthi2809
Contributor
in
Splunk Search
08-01-2017
|
0
|
2
| |||
| inputlookup kv_adani | where (tag="CHP.Device1.C1 BELT VW" ) | eval _time=tagtime |dedup _time| stats max(_time) as...
by
mintucs
New Member
in
Splunk Search
08-01-2017
|
0
|
3
| |||
I'm trying to sum a count from one event and group all of these summations by another events unique ID. The two event...
by
jl19
Explorer
in
Splunk Search
07-31-2017
|
0
|
4
| |||
My current search (below) returns 3 results that has a field called "import_File" that contains either the text "Acco...
by
griffinpair
Path Finder
in
Splunk Search
07-31-2017
|
0
|
5
| |||
I have a collection of log data in an index and for the purposes of this discussion _time has the value I want. When ...
by
mumblingsages
Path Finder
in
Splunk Search
07-31-2017
|
0
|
8
| |||
I want to get IP addresses that is not duplicated
There is two example search that A and B.
A search is index=...
by
superhm
Explorer
in
Splunk Search
08-01-2017
|
0
|
4
| |||
Hello,
For same base query I am getting different distinct count result in timechart and stats for same time range...
by
hemendralodhi
Contributor
in
Splunk Search
07-31-2017
|
0
|
5
| |||
Hi There,
Can i please know the ports to be opened for heavy forwarder , indexer , universal forwarder ?
by
kteng2024
Path Finder
in
Splunk Search
07-31-2017
|
0
|
3
| |||
Hello,
Does anybody see something wrong with this regex ?
\w{3}S*ALTSIP*\d{1,2}
When testing against my ho...
by
sylbaea
Communicator
in
Splunk Search
07-30-2017
|
0
|
2
| |||
I'm attempting to track a mule transaction where the correlation ID changes part way through the request, I would nor...
by
Lgo
Explorer
in
Splunk Search
07-31-2017
|
0
|
2
|