Splunk Search

Splunk Search
Community Activity
wzgoda
For my data set, I am looking to see the sum of the number of events per distinct count of servers. Reasoning, I am l...
by wzgoda Explorer in Splunk Search 07-12-2016
0 5
0
5
rashid47010
how can I get/increase my reputation points to post the question
by rashid47010 Communicator in Splunk Search 07-12-2016
1 4
1
4
agemkowacc
Is the openssl vulnerability exploitable on all versions or certain older versions?
by agemkowacc New Member in Splunk Search 07-12-2016
0 1
0
1
mcgi906
Currently, I have a form with a search that populates a two column table, and am using one of the columns as a key to...
by mcgi906 Explorer in Splunk Search 07-12-2016
0 1
0
1
Jhand2016
I have a situation where we break out user classes by adding numeric characters at the end of their username. As an e...
by Jhand2016 Explorer in Splunk Search 07-12-2016
0 5
0
5
wrangler2x
I was under the impression that if I did index=_internal source="/opt/splunk/var/log/splunk/splunkd.log" realtime tha...
by wrangler2x Motivator in Splunk Search 07-12-2016
0 3
0
3
splunker9999
Hi, Need help on a Splunk subsearch. Below is our Splunk basic search which gives us few fields if it satisfies the...
by splunker9999 Path Finder in Splunk Search 07-12-2016
0 4
0
4
mmather67
In props.conf, I would like to create a field abc by saying: abc = "xyz". Is there any way to say this so that Splu...
by mmather67 Path Finder in Splunk Search 07-12-2016
2 12
2
12
sbattista09
I want to see the duration that a user has been logged in to the PC for. Would the transaction command work the best ...
by sbattista09 Contributor in Splunk Search 07-12-2016
0 2
0
2
sureshchinta
My app writes two log statements, audit and activity statement, for each invocation as below: audit: type:audit | ti...
by sureshchinta Explorer in Splunk Search 07-12-2016
0 5
0
5
kmccowen
query: index=ctap source="/charter/apps/gwtrbl/logs/troubleshooting*.log" host=sc58laopp0* End of Branch Execution : ...
by kmccowen Path Finder in Splunk Search 07-12-2016
0 2
0
2
warrenpage
I have a main centralized splunk index server with logs for 50+ hosts. I have a secondary Splunk instance for a smal...
by warrenpage Explorer in Splunk Search 07-12-2016
1 5
1
5
iisaphd
I am writing a search that will track when the firewall sees outbound traffic over non-standard ports. I have a requ...
by iisaphd Engager in Splunk Search 07-12-2016
0 2
0
2
kaskirana01
Hi, I have a list of executables uploaded as a lookup in Splunk and have proxy logs to compare against it. I need to...
by kaskirana01 New Member in Splunk Search 07-12-2016
0 5
0
5
a212830
Hi, I have a customer who uses Splunk via the REST API and runs a search to put into another system. Their output i...
by a212830 Champion in Splunk Search 07-12-2016
0 8
0
8
daniel333
All, So I have a lookup, of say 10,000 items. I'd like to merge it all as one giant event for a specifical visualiz...
by daniel333 Builder in Splunk Search 07-12-2016
0 2
0
2
splunkn
I am able to see that the following search returns the same result for fieldformat as well as eval time conversion op...
by splunkn Communicator in Splunk Search 07-12-2016
1 5
1
5
saradachelluboy
Hi All, Transaction duration based on thread name. I wrote the below search: index="p" sourcetype="x" | transaction...
by saradachelluboy Explorer in Splunk Search 07-12-2016
0 5
0
5
akashjohn
Hi Team, We are trying to create a bar chart from secure log. The ultimate goal is to plot the accounts (top 10) use...
by akashjohn Explorer in Splunk Search 07-12-2016
0 4
0
4
daniel333
All, Weird search. How can I get a count of words in an event? e.g. _raw = "Hello world. Hello state. Hello Franc...
by daniel333 Builder in Splunk Search 07-11-2016
0 3
0
3
koushiknandan
I am trying to use the below search and plot a graph for the TPS field. So, if I draw a chart with the TPS values ov...
by koushiknandan New Member in Splunk Search 07-11-2016
0 9
0
9
tlmayes
Trying to find where a field was created that appears in a search against our BlueCoat proxy logs. The field is s_...
by tlmayes Contributor in Splunk Search 07-11-2016
0 7
0
7
mcgi906
I have a field that is of the form /Code153:4:Item1,Item2,Item3,Item4/Code211:2:Item5,Item6 where I need to extract a...
by mcgi906 Explorer in Splunk Search 07-11-2016
0 1
0
1
skoelpin
I want to tie together 2 events at index time the same way I would tie them together at search time using the transac...
by SplunkTrust SplunkTrust in Splunk Search 07-11-2016
0 4
0
4
ashishlal82
I have this search which basically displays if there is a hash (sha256) value in the sourcetype= software field =sha2...
by ashishlal82 Explorer in Splunk Search 07-11-2016
0 8
0
8
Get Updates on the Splunk Community!

test 2

test 222222

test

test

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors