Splunk Search

Splunk Search
Community Activity
moshiro
Need help with searching for patterns in username field values... I want to know if anyone has suggestions for the b...
by moshiro New Member in Splunk Search 03-11-2017
0 4
0
4
rewritex
I can upload a lookup table .csv fine, "| lookupinput <name.csv>" also works fine. When I create an autolookup, the l...
by rewritex Contributor in Splunk Search 03-11-2017
0 6
0
6
asarran
Good Morning, Fellow Splunkers I have a field extraction that outputs four possible values [Example]: Field Extract...
by asarran Path Finder in Splunk Search 03-11-2017
0 6
0
6
jwalthour
I am trying to extract fields out of events that are tab-delimited unless there are quotes around them. For example, ...
by jwalthour Communicator in Splunk Search 03-11-2017
0 9
0
9
nunyabizness123
How would I go about parsing out/extracting the field data for the following log format? "fieldname1":"fieldvalue1",...
by nunyabizness123 New Member in Splunk Search 03-11-2017
0 2
0
2
rlseafor
sourcetype="my_sourcetype" ("Build Failed" NOT "Build Succeeded") earliest=@d+2h | rename host as "Imaging Server" | ...
by rlseafor New Member in Splunk Search 03-11-2017
0 2
0
2
jhayIV
Is there a way to determine days between with the search below? convert ctime(LastScanDate)|eval tnow = now() | conv...
by jhayIV Engager in Splunk Search 03-11-2017
0 2
0
2
shivac
12-000-000-222 for the above IP address, i want to change it to 12.000.000.222. pls help.
by shivac New Member in Splunk Search 03-11-2017
0 4
0
4
jamesar
I am wanting to extract a new field from the original source field, based on regex matches. I would then like to prep...
by jamesar Explorer in Splunk Search 03-11-2017
1 4
1
4
splunkrocks2014
Assuming I have a lookup table with movie title and location, and I got the top 5 location based on distinct title co...
by splunkrocks2014 Communicator in Splunk Search 03-11-2017
0 6
0
6
mblauw
I've just started using RegEx and I'm currently looking on a way to extract multiple events from my JSON flight infor...
by mblauw Path Finder in Splunk Search 03-11-2017
0 2
0
2
shabdadev
Hi, I wrote one simple query index=nmon host=* type=DISKXFER | timechart avg(value) by host and created a dashba...
by shabdadev Engager in Splunk Search 03-10-2017
0 3
0
3
smwilli1
I'm curious if there is a way to get the same effect of transaction w/maxspan, without having to use that process int...
by smwilli1 Explorer in Splunk Search 03-10-2017
0 6
0
6
danje57
Hi all, I need your help. I retrieve a log from Sharepoint which contains the list of all published document with i...
by danje57 Path Finder in Splunk Search 03-10-2017
0 5
0
5
sbhaskaran
I have replication factor of 3 but the data is not replicated to any other indexers. This is happening for tcp input ...
by sbhaskaran Explorer in Splunk Search 03-10-2017
0 2
0
2
vittal_kumar
Hello Everyone, I want to block multiple IP address I got my using IP!=xxx.xx.xx.xx OR IP!=yyy.yy.yy.yy Is there an...
by vittal_kumar Engager in Splunk Search 03-10-2017
0 3
0
3
abhijitnath89
How can we index XML files from a url ending in .xml in splunk? We have an XML URL that we need to index into splunk,...
by abhijitnath89 Path Finder in Splunk Search 03-10-2017
0 5
0
5
chintan_shah
I want to show the previous week date on Title of panel. Can anyone have some thoughts for it?
by chintan_shah Path Finder in Splunk Search 03-10-2017
0 3
0
3
muebel
I have a list of fields within a Datamodel collected as values within the field named "unknown" | datamodel Authenti...
by SplunkTrust SplunkTrust in Splunk Search 03-10-2017
0 2
0
2
akhasriya
I have a multisearch to view data for yesterday only. [search index=... earliest = -1d@d latest=+0d@d| search .... ...
by akhasriya Engager in Splunk Search 03-10-2017
0 2
0
2
f5x6kb8
We need to determine a 30 day average based on the count of two events, a request and a response. The issue is that e...
by f5x6kb8 Explorer in Splunk Search 03-10-2017
0 4
0
4
Gowtham0809
Hi, I have 2 different search queries which i need to combine and generate the report as similar to dashboard and ou...
by Gowtham0809 New Member in Splunk Search 03-10-2017
0 1
0
1
mw
I have a setup.xml which uses the following format for scripted inputs on Unix systems: # inputs.conf [script://./bi...
by mw Splunk Employee Splunk Employee in Splunk Search 03-10-2017
2 9
2
9
stwong
Hi all, I'm adding detail files from FreeRadius, which looks like following: Wed May 2 10:28:04 2012 NAS-IP-Ad...
by stwong Communicator in Splunk Search 03-09-2017
1 6
1
6
sravankaripe
i have fields key and value field "key" contains values sessionID txnID eventSeverity msgType ...
by sravankaripe Communicator in Splunk Search 03-09-2017
0 2
0
2
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...