Splunk Search

Splunk Search
Community Activity
mike314
I've created an extracted field using the field extractor GUI in Splunk Seb. When I created it, there were two values...
by mike314 Explorer in Splunk Search 12-13-2016
2 8
2
8
janiceb
Greetings All, I am trying to use a static CSV file that contains bad domain indicators and search Splunk logs for a...
by janiceb Path Finder in Splunk Search 12-13-2016
0 3
0
3
splunkrocks2014
Assuming I have a lookup file, for instance, users.csv, with different contents and is located in different apps and ...
by splunkrocks2014 Communicator in Splunk Search 12-13-2016
0 3
0
3
irfans
I am trying to write a lookup that will pull a value out from one of three different columns. for example Col_A, ...
by irfans Explorer in Splunk Search 12-13-2016
1 3
1
3
douglas_garland
I created a macro and used the search string below. After submitting the search, I received the following error mess...
by douglas_garland New Member in Splunk Search 12-13-2016
0 6
0
6
iamkilarunaresh
| inputlookup Roster.csv Level 1 Manager Level 2 Manager Level 3 Manager Ganesh Ganesh Ganesh Th...
by iamkilarunaresh Explorer in Splunk Search 12-13-2016
0 1
0
1
king2jd
Here is my search: | set diff [search index=os_nix sourcetype="Unix:UserAccounts" earliest =-90d@d latest=-30d@d ho...
by king2jd Path Finder in Splunk Search 12-13-2016
0 3
0
3
namrithadeepak
Hi, I have batch job logs that look like below, My output needs to look like this, The challenge is that the j...
by namrithadeepak Path Finder in Splunk Search 12-13-2016
0 2
0
2
a212830
Hi, I noticed some processes running on the indexer today with the phrase "SummaryDirector" in the command-line. Ca...
by a212830 Champion in Splunk Search 12-13-2016
0 1
0
1
LCM_BRogerson
I’m looking for a way to run a search on the results of a previous search. Subsearch won't work because I don't know...
by LCM_BRogerson Path Finder in Splunk Search 12-13-2016
0 5
0
5
psteja
Splunk newbie here trying to get a nice line graph showing the session creation pattern over a period of time: ........
by psteja Engager in Splunk Search 12-13-2016
0 5
0
5
yuwtennis
Hi! I would like to know what does "Size" stands for Job Manager in ver 5.0.5. Any help is appreciated! Thanks, Yu
by yuwtennis Communicator in Splunk Search 12-13-2016
1 3
1
3
johnbernal553
I have a log event like this: Timestamp: 1477292160453180 537 The number 1477292160453180 is the number of microse...
by johnbernal553 New Member in Splunk Search 12-13-2016
0 8
0
8
alexandermunce
I am working with a field named product which contains an array of values which I would like to replace with more mea...
by alexandermunce Communicator in Splunk Search 12-13-2016
0 11
0
11
colbymahan
SourceName="EBS Check" OR SourceName="EBS Snapshot" | eval hasEBSCheck=1 | append [| metadata type="hosts" | eval has...
by colbymahan Explorer in Splunk Search 12-13-2016
0 5
0
5
tmurray3
I have a search to graph the last 30 minutes in 5 minute intervals: index=web_summary report="volumebyminuteweb" ear...
by tmurray3 Path Finder in Splunk Search 12-13-2016
0 1
0
1
vkumar6
I need an example search to track system time change in a Linux system. Please help me.
by vkumar6 Explorer in Splunk Search 12-13-2016
0 9
0
9
dbcase
Hi, I have this query index=cox UCE-|rex "UCE-(?<UCE_Code>(\d+))"|lookup UCECodes.csv UCE-Code as UCE_Code|eval ud=...
by dbcase Motivator in Splunk Search 12-13-2016
0 3
0
3
HeinzWaescher
Hi, let's say we have a string with various tagged entries: "This {field1} is {delete_this} the example {tagged_el...
by HeinzWaescher Motivator in Splunk Search 12-13-2016
0 8
0
8
mattj81
Hi, I'm struggling with a search string to pull back Active Directory logon times for a specific user and to include ...
by mattj81 New Member in Splunk Search 12-13-2016
0 6
0
6
umsundar2015
Hi, My scenario is to get a time chart with each day's values for a particular period of time (ex: 7 days) and their...
by umsundar2015 Path Finder in Splunk Search 12-13-2016
0 13
0
13
splunkpoornima
hi all i have taskmanager log files which has the events like Mon Jun 25 00:00:30 CDT 2012,DistributedEvaluation,S...
by splunkpoornima Communicator in Splunk Search 12-12-2016
0 2
0
2
medunmeyer
I am running Splunk 6.5 , and I have tried many things for hours, but am still getting: The system is approaching th...
by medunmeyer Explorer in Splunk Search 12-12-2016
0 1
0
1
namrithadeepak
I have 2 jobs running daily (DailyDayJob, DailyNightJob) that logs to a common file. The logs are as given below: 20...
by namrithadeepak Path Finder in Splunk Search 12-12-2016
0 9
0
9
Vicky84
Sorry I am new to Splunk and wondering if can have the report that gives results in a table as below, data as : i...
by Vicky84 Explorer in Splunk Search 12-12-2016
0 4
0
4
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...