| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        I want to compare two dates using case statement Theoretically, case( _time > "2016-01-01") . If True, Print "Yes" in...
        
       
         
           by 
           
                
                    
                        splunk_hvijay
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Would like to do this: 
  Where indexa has two fields, md5 and allmd5 
  Two records exist like this: 
  md5=99ed710d...
        
       
         
           by 
           
                
                    
                        jonbelanger
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Is there a way to search a log and figure out which heavy forwarder sent the log to the indexer?
        
       
         
           by 
           
                
                    
                        galwood
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               02-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Suppose I am interested in finding out the top 5 videogames bought (in the last 24 hours) per top 10 stores and would...
        
       
         
           by 
           
                
                    
                        demkic
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-27-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I have a proxy log index which contains a URL field.  
  I also have a lookup table, which contains a list of known b...
        
       
         
           by 
           
                
                    
                        pdumblet
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have files I am ingesting that have variable formats. I want to pick those lines out that only have an IP address a...
        
       
         
           by 
           
                
                    
                        brent_weaver
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        11-01-2016 14:53:32.199 -0500 INFO  StreamedSearch - Streamed search connection terminated: search......................
        
       
         
           by 
           
                
                    
                        sravankaripe
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi, 
  I want to get results of a search in a CSV file. I tried this, but its giving me error HTTP 400 Invalid output...
        
       
         
           by 
           
                
                    
                        ektasiwani
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-19-2015
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi folks, 
  I have Splunk version 6.2.7 and am trying to create a report to display the top 10 products sold within ...
        
       
         
           by 
           
                
                    
                        demkic
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        I need to provide month over month AV compliance given the following calculation: 
  (Total # AV compliant servers / ...
        
       
         
           by 
           
                
                    
                        tmaltizo
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               10-26-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  9
	 
 | |||
| 
      
        I have 2 fields called sc_bytes & cs_bytes in my results. How can I then filter my results to give me events when the...
        
       
         
           by 
           
                
                    
                        cbr654
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hello Experts,  
  I need help in determining the OS and Browser's that appear in our logs. I understand the easiest ...
        
       
         
           by 
           
                
                    
                        julianj
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               07-29-2015
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  8
	 
 | |||
| 
      
        Hello ppl I have a set of Error messages in an event log that looks like this  ERROR [43f796d8da] there are several c...
        
       
         
           by 
           
                
                    
                        splgeek
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-01-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have a lookup which has an IP address column, and I'm trying to find which if the IP addresses from this lookup tab...
        
       
         
           by 
           
                
                    
                        adamsmith47
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hello, 
  I want to extract a field with the field extractor in Splunk. But when I extract these logs on log 1, I wil...
        
       
         
           by 
           
                
                    
                        nickbijmoer
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I can't get any output data. My test dataset includes two fields f1 and f2:  
  | inputcsv tmp1030.csv | arules f1 f2...
        
       
         
           by 
           
                
                    
                        whl329
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               10-30-2016
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi,  
  Does anyone know how I can view the full city list that Splunk uses for iplocation? I'm exporting my data, th...
        
       
         
           by 
           
                
                    
                        MowLiao
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi all. 
  I have a search that begins with: 
  index="first" OR index="second" sourcetype=*
 
  I need to show a tab...
        
       
         
           by 
           
                
                    
                        changux
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I am utilizing Cisco Ironport Squid logs. I found a suspicious event that is possible malware related and multiple co...
        
       
         
           by 
           
                
                    
                        DavidScavotto
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hi Guys 
  Is there a search that can pull back the forwarders that are missing / not sending data at a point in time...
        
       
         
           by 
           
                
                    
                        AaronMoorcroft
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have two events 
  I'm using this 
  nt_time=strptime(VENDOR_NOTIFIED_TIME,"%F %T")|eval st_time = strptime(START_D...
        
       
         
           by 
           
                
                    
                        msachdeva3
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-31-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hello.  
  I have a simmilar quesiton to this :  https://answers.splunk.com/answers/176585/how-to-extract-a-field-bet...
        
       
         
           by 
           
                
                    
                        shere
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               10-25-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hi Guys, 
  I'm running a search and it seems to take longer than needed. I've search the logs for errors and found t...
        
       
         
           by 
           
                
                    
                        gwobben
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               12-09-2015
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi  
  I have an extracted field from regex, ie Time_extract which gives hour. Now I want to get the logs between a p...
        
       
         
           by 
           
                
                    
                        arunkuriakose
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-30-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I am trying to test a text input box value to determine if an IP address was provided. If an IP address was provided,...
        
       
         
           by 
           
                
                    
                        mydog8it
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               10-01-2015
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  16
	 
 |