| My scenario is thus: The main search searches for a pattern in a sourcefile: source="/apps.log" index=idx "abc" | xm... by dragut New Member in Splunk Search 06-05-2017 0 7 | 0 | 7 | ||
| Using the docs here: http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Propsconf, specifically this section: *... by sillingworth Path Finder in Splunk Search 06-05-2017 0 8 | 0 | 8 | ||
| If I have a lookup containing a list of different regular expressions in a column, is there a way I can input the loo... by lids4dt Engager in Splunk Search 06-05-2017 1 3 | 1 | 3 | ||
| Splunk time and the event time does not match. There is a 5 hour difference. How to get both the timestamps under the... by ppanchal Path Finder in Splunk Search 06-05-2017 0 6 | 0 | 6 | ||
| My current search is: index=ad memberOf=role1 OR memberOf=role2 NOT memberOf=role3 | stats count as "User Group A" |... by igordon New Member in Splunk Search 06-05-2017 0 3 | 0 | 3 | ||
| Hello, I'm joining two tables in splunk and their only common attribute is time. This works well 99% of the time. B... by jcouture Explorer in Splunk Search 06-05-2017 0 6 | 0 | 6 | ||
| Using this SPL: index=main sourcetype=conn_activeifc d_name="JimSimpkins-Surface3" | transaction mvlist=t maxevents=... by simpkins1958 Contributor in Splunk Search 06-05-2017 1 4 | 1 | 4 | ||
| I'm looking at firewall logs which typically have (among other details) a source address and a destination address. I... by robdanl Explorer in Splunk Search 06-05-2017 0 12 | 0 | 12 | ||
| I've concluded that I absolutely need to use mapping, as I need to run the same (large) search query for each Iterati... by snreichel Engager in Splunk Search 06-05-2017 0 3 | 0 | 3 | ||
| So, basically I've a query which ends something like this: | eval uf = if(like(one_reason, "%unknown_failure%"), uf.... by shrutigupta New Member in Splunk Search 06-05-2017 0 2 | 0 | 2 | ||
| Hi, I want to extract particular fields from single event based on fields position. Sample Data: event1: aaa|bbb|c... by gvnd Path Finder in Splunk Search 06-05-2017 0 2 | 0 | 2 | ||
| I am trying to write a query to show number of open and closed incidents in a month. When I try the following in the... by t_splunk_d Path Finder in Splunk Search 06-04-2017 0 34 | 0 | 34 | ||
| I have xml logs as below where I am trying to write a Splunk search to do a search where entry=01 and result = Done... by amanavohra New Member in Splunk Search 06-04-2017 0 3 | 0 | 3 | ||
| I have a CSV containing wine names, vintages and prices, e.g. Description,Vintage,Price A,2012,100 A,2013, B,2014, B... by bowesmana SplunkTrust 0 5 | 0 | 5 | ||
| Hi , I have a scenario. where my _time is chicago time(CST/CDT) . But I need to convert it to London time and do stat... by ankithreddy777 Contributor in Splunk Search 06-03-2017 0 3 | 0 | 3 | ||
| Hello Everyone, I'm having an issue where I cannot use EVAL in search or in the props.conf for a field that has been... by johnmvang Path Finder in Splunk Search 06-03-2017 0 12 | 0 | 12 | ||
| I have a lookup table of IDs like this: (id)uuid - (myid)numeric id (id)uuid - (myid)email (id)email - (myid)numeric ... by rvencu Path Finder in Splunk Search 06-03-2017 0 1 | 0 | 1 | ||
| Basically my search looks like this index=something | rex "(?), " | rex "(?\d+)" | eval _time=strftime(_time, "%d ... by sandyIscream Communicator in Splunk Search 06-03-2017 0 2 | 0 | 2 | ||
| Hi, We have a requirement where client wants to see only events which satisfied the below condition. Any events whi... by surajgupta New Member in Splunk Search 06-02-2017 0 4 | 0 | 4 | ||
| This docs (https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/SearchReference/Runshellscript) says $8 argument i... by testadrianbelen New Member in Splunk Search 06-02-2017 0 5 | 0 | 5 | ||
| Hello! As the title states, my dashboard fails to load a panel that performs a search. If I click "Open in search... by kylbarne New Member in Splunk Search 06-02-2017 0 16 | 0 | 16 | ||
| The documentation on user-prefs.conf is incomplete. I cannot find an explanation for the following settings: appOrde... by matthijsk Explorer in Splunk Search 06-02-2017 0 2 | 0 | 2 | ||
| When running this search (the return value is hard coded, it is coming from an external command). I just pasted the r... by rdownie Communicator in Splunk Search 06-02-2017 0 2 | 0 | 2 | ||
| I'm having problems with what should be a very simple query. I'm trying to get a count of events in an "unavailable"... by richgalloway SplunkTrust 0 5 | 0 | 5 | ||
| I'm monitoring Sysmon events from my laptop, but if I temporarily lose network connection Splunk stops logging comple... by stefan1988 Path Finder in Splunk Search 06-02-2017 0 2 | 0 | 2 |