Splunk Search

Splunk Search
Community Activity
melonman
Hi, I have been using Google Map app mainly for lookup the locations of ipaddress. With Splunk6, I can use native ma...
by melonman Motivator in Splunk Search 05-30-2017
1 5
1
5
ErikaE
I'm counting exceptions over a 24 hour period. My search looks like this: index=exceptionsindex | bin _time span=2...
by ErikaE Communicator in Splunk Search 05-30-2017
0 8
0
8
Ant1D
Hi, I am aware that it can be done at search-time via props.conf: [sourcetype] EVAL-_raw = urldecode(_raw) Is it po...
by Ant1D Motivator in Splunk Search 05-30-2017
0 2
0
2
RocIngersol
Hey Folks, Any suggestions on how to report on the total percent of my events that are duplicates? I can find my du...
by RocIngersol Explorer in Splunk Search 05-30-2017
0 1
0
1
feickertmd
I have a log for a documents database. It gives me a daily report of total documents in each collection (each collect...
by feickertmd Communicator in Splunk Search 05-30-2017
0 2
0
2
scs1960
what command is used to remove the status field from the returned events
by scs1960 New Member in Splunk Search 05-30-2017
0 3
0
3
arunsony
I have a source as ///application.log in my inputs.conf.On the servers the application.log will be rolled when it fil...
by arunsony New Member in Splunk Search 05-30-2017
0 23
0
23
funghorn
In my log files there is a field (path = info.message) that has a certain string. I want to extract a part of that st...
by funghorn Explorer in Splunk Search 05-30-2017
0 5
0
5
gnovak
Can you rename values extracted into fields? Example - Here is a field i have called "filename" and some examples of...
by gnovak Builder in Splunk Search 05-30-2017
1 8
1
8
splunker12er
no . of search head -1 (8 cores) no. of indexers - 4 (24-cores each) So, my system-wide concurrent searches limit i...
by splunker12er Motivator in Splunk Search 05-30-2017
0 2
0
2
nickhills
Any ideas on how to handle this - I am imaging a horrible if/string statement, but any other ideas? i have a field "...
by nickhills Ultra Champion in Splunk Search 05-30-2017
0 7
0
7
umsundar2015
Hi, I have following sample log string , May 13 14:20:32 pcpsd1sb.smart.net 318324: May 13 14:20:31.282 EDT: %CDP-4...
by umsundar2015 Path Finder in Splunk Search 05-30-2017
0 2
0
2
laudai
Hello guys I have lots of columns such as test1 ,test1_up ,test1_down ,test2 ,test2_up, test2_down ,tmp1, tmp1_up,...
by laudai Path Finder in Splunk Search 05-30-2017
0 6
0
6
fvegdom
I have a search like this: |inputlookup CSV-Generic-GenCus-GenLBL-SensitiveDataKeyWords.csv | map [search index="...
by fvegdom Path Finder in Splunk Search 05-29-2017
0 5
0
5
Akshay2Patil
Hi, please explain, what is the function of 'status'? why we use status? what's its function?what does it do? what d...
by Akshay2Patil Engager in Splunk Search 05-29-2017
0 3
0
3
dunsha
I would like to return the value of a string only once even if it shows up multiple times in splunk. For example: "r...
by dunsha New Member in Splunk Search 05-29-2017
0 3
0
3
chinchin96
I have a search that generates two distinct types of record entries (searching for "for event"): 2015-05-05 for eve...
by chinchin96 New Member in Splunk Search 05-29-2017
0 8
0
8
gcusello
Hi at all, I'm ingesting many csv where there are a variable number of columns. some of this columns have name "ser...
by SplunkTrust SplunkTrust in Splunk Search 05-29-2017
0 4
0
4
rvisj
I have some records in csv, each record has a column 'payment method'. I have to count by 'payment method' and the re...
by rvisj New Member in Splunk Search 05-29-2017
0 5
0
5
mngeow
Hi, I am trying to create an anomaly detector for unusually high thruputs across all sourcetypes in my Splunk intern...
by mngeow Engager in Splunk Search 05-29-2017
0 1
0
1
splunk_skr
I tried looking up for a solution and went through almost all suggestions. None worked for me. I have the following j...
by splunk_skr Explorer in Splunk Search 05-29-2017
0 4
0
4
mihenn
Hello everyone, I'm trying to get an analysis of an process log file. The logfile contains an event for every ended ...
by mihenn Path Finder in Splunk Search 05-29-2017
0 3
0
3
TCK101
Hi I am attempt to extra host names from logs they always appear after the 4th semicolon : E.g. I want the extra t...
by TCK101 New Member in Splunk Search 05-29-2017
0 2
0
2
JimSchlaker
Is there a way to determine which logs are not being used anymore, and therefore can be deleted? For example, maybe ...
by JimSchlaker New Member in Splunk Search 05-27-2017
0 4
0
4
andreac81
Hi to all, I have a summary search that doesn't produce results, if I copy and paste the same search in "search & re...
by andreac81 Explorer in Splunk Search 05-27-2017
0 4
0
4
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...