Splunk Search

Splunk Search
Community Activity
wcwnesta
When I restart Splunk, accelerated data in data-model WEB is deleted. I update the WEB, then the model gets the data ...
by wcwnesta New Member in Splunk Search 09-20-2017
0 5
0
5
ipops
I am trying to do a field extract but running into problems Here is an example event. I am trying to build a regex ...
by ipops Path Finder in Splunk Search 09-20-2017
0 2
0
2
MuratKuru
My input.conf file: [monitor:///var/log/openvpn/hostname_vpnStatus.log] disabled = 0 crcSalt = SOURCE index = iss-nip...
by MuratKuru Explorer in Splunk Search 09-20-2017
0 5
0
5
zeroCalm
Hello, I am using the following search: index="ips_snaplogic""postsales" lvl="ERROR"| spath| rex mode=sed "s/.*{/{/...
by zeroCalm New Member in Splunk Search 09-20-2017
0 14
0
14
luc_k
Hi, I'd like to search our log for multiple possible errors from our lookup file: to return only the records co...
by luc_k Engager in Splunk Search 09-20-2017
0 5
0
5
nnimbe
Hi All, I need the command for consecutive events which is triggered one after another out of multiple events( 3 con...
by nnimbe Path Finder in Splunk Search 09-20-2017
0 2
0
2
IRHM73
Hi, I wonder whether someone could help me please. I'm using the following query to to interrogate a summary index, ...
by IRHM73 Motivator in Splunk Search 09-20-2017
0 5
0
5
ptur
Hello, When creating tables, i have noticed that if i start renaming fields - for display clarity purpose - like fo...
by ptur Path Finder in Splunk Search 09-19-2017
0 2
0
2
IVV
Hello everyone! The problem: I want to identify users who use SSH with login other than their own. I have two logs: 1...
by IVV Path Finder in Splunk Search 09-19-2017
0 5
0
5
ankithreddy777
I have a scenario, where I need to 1) append results to .csv file. 2) Once I get csv file updated, I need to elimin...
by ankithreddy777 Contributor in Splunk Search 09-19-2017
0 1
0
1
brent_weaver
I need to create a field in splunk that is a portion of the file path, do I need to do that @ index time or can I do ...
by brent_weaver Builder in Splunk Search 09-19-2017
0 4
0
4
matthewb4
I have a lookup abc.csv with the following values... **header1, header2** value1a, value2a value1b, value2b value1c,...
by matthewb4 Path Finder in Splunk Search 09-19-2017
0 4
0
4
virgilg
Hi, I have a search like this: sourcetype=syslog AND host="xxx.xxx.xxx.xxx" AND mpkg | stats count by username, ope...
by virgilg Explorer in Splunk Search 09-19-2017
2 2
2
2
ssaenger
Hi All, I have created an index and sourcetype for two logs files. I have set up my props.conf to extract the date/t...
by ssaenger Communicator in Splunk Search 09-19-2017
0 2
0
2
jh007
I am not sure how to approach what I am attempting to do. In short, I have a field that contains some specific strin...
by jh007 New Member in Splunk Search 09-19-2017
0 6
0
6
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the query below to list the current user accou...
by IRHM73 Motivator in Splunk Search 09-19-2017
0 4
0
4
tmurray3
Trying to use the results of one query in the sub query search. I am not getting the results I expected. The first ...
by tmurray3 Path Finder in Splunk Search 09-19-2017
0 2
0
2
marina_rovira
Hello all, I have some csv files that I'm updating to splunk as lookup files, but there are some german/spanish/fren...
by marina_rovira Contributor in Splunk Search 09-19-2017
0 19
0
19
forrest_NUS
I have an all-in-one environment, which indexed VPN logs. I also want to forward the vpn raw logs to the third party...
by forrest_NUS New Member in Splunk Search 09-19-2017
0 5
0
5
arindam23
Hello, I am trying to create a dashboard in Splunk displaying real-time survey results from sources like Qualtrics, ...
by arindam23 New Member in Splunk Search 09-18-2017
0 3
0
3
ddrillic
We have some messages saying - Search peer <host> has the following message: Received event for unconfigured/disabl...
by ddrillic Ultra Champion in Splunk Search 09-18-2017
0 7
0
7
JordanPeterson
I'm looking at a specific email recipient. I want to see the percentage of emails they receive from specific senders....
by JordanPeterson Path Finder in Splunk Search 09-18-2017
0 4
0
4
vanderaj2
Sounds like I have a manifest file/hashing issue that appears whenever I restart splunkd on an endpoint, like the fol...
by vanderaj2 Path Finder in Splunk Search 09-18-2017
0 4
0
4
dlugasny
Hi, our network count ~9000 Servers. Most of them running in the separate network IP segments. I would like to kind...
by dlugasny New Member in Splunk Search 09-18-2017
0 7
0
7
tlmayes
I have a query below that produces the sum of bandwidth used by remote intermediate forwarders. The output give me a...
by tlmayes Contributor in Splunk Search 09-18-2017
0 5
0
5
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...