Splunk Search

Splunk Search
Community Activity
beenagulzar
i have a for loop statement need to get converted to splunk query .. i am not aware how to store the variable and use...
by beenagulzar New Member in Splunk Search 02-15-2017
0 1
0
1
nivethainspire_
I have 3 different values to be extracted. Please help me in writing rex command here is the field values name="ascd...
by nivethainspire_ Explorer in Splunk Search 02-15-2017
0 1
0
1
sharadkapurala
I need AD auth events and some have multiple entries for Account Name field. One entry is a hyphen (-). Can someone h...
by sharadkapurala New Member in Splunk Search 02-15-2017
0 1
0
1
mhornste
Hi, I have source data comma delimited like this from JMeter: timeStamp,elapsed,label,responseCode,responseMessage,...
by mhornste Path Finder in Splunk Search 02-15-2017
0 9
0
9
mintughosh
I need to know the license usage of 5 indexes on a daily basis. All the options I have been trying gives me the licen...
by mintughosh Path Finder in Splunk Search 02-14-2017
0 2
0
2
chetanhonnavile
In the below event "status" key has the value either "1" or "0" . I am looking out to extract those "status" having t...
by chetanhonnavile Explorer in Splunk Search 02-14-2017
0 8
0
8
dellytaniasetia
Hi, I have a simple question, what is the difference between earliest=-15m with earliest=-15m@s? I could not find a...
by dellytaniasetia Explorer in Splunk Search 02-14-2017
0 1
0
1
mattbirk
So my data has, for example, code 001 for connected and 002 for disconnected. Also, each VPN session has a unique ses...
by mattbirk Explorer in Splunk Search 02-14-2017
1 5
1
5
murhammr
I'm having trouble converting a search string into a working regular expression in transforms.conf to send events to ...
by murhammr Path Finder in Splunk Search 02-14-2017
0 7
0
7
nravichandran
We are planning to for a F5 load-balancer to be placed in front of the search heads. For sizing, how can I find out t...
by nravichandran Communicator in Splunk Search 02-14-2017
0 2
0
2
fvegdom
When I use the following search (some criteria obfuscated for security): index=main sourcetype=transaction applicat...
by fvegdom Path Finder in Splunk Search 02-14-2017
1 19
1
19
brent_weaver
Good morning! I am having to parse out Bro log files and with the help of the forum I was more than successful at doi...
by brent_weaver Builder in Splunk Search 02-14-2017
0 3
0
3
jmaple
I'm working on creating a report to monitor VPN usage based on unique user per day. I was able to get the format I wa...
by jmaple Communicator in Splunk Search 02-14-2017
0 1
0
1
faustf
Hi guys I'm not an expert of Splunk. I was wondering if I can use a lookup to reference fields that are stored into ...
by faustf Communicator in Splunk Search 02-14-2017
0 1
0
1
chengyu
My raw data: Feb 7 18:18:23 impact 1 Gbps/137.54 Kpps, importance 2... Feb 7 18:18:23 impact 3600 Mbps/137.54 Kpps...
by chengyu Path Finder in Splunk Search 02-13-2017
0 5
0
5
raghav130593
I have a query where I am performing regex matching on two different fields, field1 and field2. index=proxylogs uri!=...
by raghav130593 Explorer in Splunk Search 02-13-2017
0 4
0
4
pradeep577
Hi All, I am planning to start learning about Splunk. I wanted to know the difference between Splunk and HP Arcsight...
by pradeep577 Path Finder in Splunk Search 02-13-2017
2 3
2
3
JRougeau
How can I show results for a field that is disabled and not re-enabled in a certain amount of time? I want to be ale...
by JRougeau Engager in Splunk Search 02-13-2017
0 1
0
1
ivanayala
I am trying to limit the number of results shown when I use the values command. Here is my search: index="mydata" e...
by ivanayala New Member in Splunk Search 02-13-2017
0 7
0
7
mpatel11
hi, looking to do a stats count something like below. Field1: A,B A B,A B,A,C A,C each row accounts for different...
by mpatel11 Explorer in Splunk Search 02-13-2017
0 2
0
2
sravankaripe
Please help me with rex i have key and value in json format {"context":{<!-- --> "sessionID":"1234567890", "eve...
by sravankaripe Communicator in Splunk Search 02-13-2017
0 14
0
14
Stevensmith529
Hello i have been trying to figure this out for days now. i have logs coming in from multiple sources that only dis...
by Stevensmith529 New Member in Splunk Search 02-13-2017
0 5
0
5
LANGLEYJ
I have a list of Hostnames in a CSV. There are 2 fields 1) cn (hostname) and 2) ComputerType. I would like to compare...
by LANGLEYJ New Member in Splunk Search 02-13-2017
0 1
0
1
sunitakesam
log file:testscripts.log Date &#61; 02/10/17 14:15:00,script &#61; testscript, id &#61; 29251, log&#61;Script started Date &#61; 02/10/1...
by sunitakesam New Member in Splunk Search 02-13-2017
0 6
0
6
msachdeva3
eval test_time &#61; time() - _time | search (test_time &gt; 1800 AND test_time &lt; 86400)| I'm trying to see if the events i...
by msachdeva3 Explorer in Splunk Search 02-13-2017
0 2
0
2
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...