Splunk Search

Splunk Search
Community Activity
splunkrocks2014
Hi. How do I filter my results from an extracted field and where-clause? I have a user lookup table which contain...
by splunkrocks2014 Communicator in Splunk Search 06-22-2016
0 6
0
6
JSkier
I'd like to sanitize host names during search time in Splunk (IDS alerts), so users don't receive a hyperlink to the ...
by JSkier Communicator in Splunk Search 06-22-2016
0 4
0
4
alan20854
Hi, I am creating a dashboard with 2 drop-downs, one for Services and the other for Methods, and I want the search ...
by alan20854 Path Finder in Splunk Search 06-22-2016
0 4
0
4
KSKandala
Hi, Currently I am consolidating data from different indexes. index=application1 ID=$id$ | rename application1_id ...
by KSKandala New Member in Splunk Search 06-22-2016
0 1
0
1
chvnc
I want to make a new field with extracted values like Header.txt, LogMessage.xml , JSON_HEADER.json (it's from the se...
by chvnc Explorer in Splunk Search 06-22-2016
0 1
0
1
voninski
Not sure how to accomplish this and need some advice from the experts here. I am working with data from a torque too...
by voninski New Member in Splunk Search 06-22-2016
0 4
0
4
DF10569
Search I am trying to use: index="wineventlog" (EventCode=4656 Accesses=DELETE) OR EventCode=1102 OR EventCode=4670...
by DF10569 New Member in Splunk Search 06-22-2016
0 2
0
2
kiran331
Hi How can I extract the "TCP_MISS/200" and "TCP_MISS_SSL/200" or similar from the event below? 1466609862.644 109...
by kiran331 Builder in Splunk Search 06-22-2016
0 1
0
1
zeophlite
I have a field in my events that is a string (but does not translate to a number directly) Is there a way to convert...
by zeophlite New Member in Splunk Search 06-22-2016
0 4
0
4
szabados
I created a datamodel from a source, which had spaces in the field names, but field were automatically created with t...
by szabados Communicator in Splunk Search 06-22-2016
3 2
3
2
daniel_augustyn
I am not sure how to fix the date extraction from a raw log which is done by default by Splunk. Splunk extracts date ...
by daniel_augustyn Contributor in Splunk Search 06-21-2016
0 4
0
4
sanchitguptaiit
I have a requirement where I need to search all logs to match a set of patterns and extract some values. Is there som...
by sanchitguptaiit Explorer in Splunk Search 06-21-2016
0 1
0
1
goodsellt
My problem stems from how the last value functions, where it pulls the last value from the previous event. While I wa...
by goodsellt Contributor in Splunk Search 06-21-2016
0 1
0
1
haziqwebs
I want to rename CPU001 to CPU1, CPU_ALL to CPUALL, is it possible?
by haziqwebs New Member in Splunk Search 06-21-2016
0 3
0
3
prakash007
Need help with regex...should start with " end with space or ? Need entire string in a field starting with " and end...
by prakash007 Builder in Splunk Search 06-21-2016
0 3
0
3
fredclown
I know that I ca get the event time using "_time". Does Splunk keep track of the time the event was loaded into Splun...
by fredclown Builder in Splunk Search 06-21-2016
1 6
1
6
bgdatasar
How do I fix this Regex syntax error in subpattern name missing terminator? Error in 'rex' command: Encountered the ...
by bgdatasar New Member in Splunk Search 06-21-2016
0 1
0
1
bsellapi
Hi I am getting below error when I use the metadata command. Could someone explain to me in detail what this is all ...
by bsellapi New Member in Splunk Search 06-21-2016
0 5
0
5
annalisefolsen
I have an app for a custom command called disabler and I am trying to call the command by: ... | disabler | ... Bu...
by annalisefolsen Explorer in Splunk Search 06-21-2016
0 1
0
1
benjaminw
My curl searches result in the output Unparsable URI-encoded request data I see that many of the curl searches on...
by benjaminw New Member in Splunk Search 06-21-2016
0 3
0
3
i111040d
For example: |stats count by src_ip src_ip count 1.1.1.1 100 2.2.2.2 200 3.3.3.3 300 |stats count by dst_ip dst...
by i111040d New Member in Splunk Search 06-21-2016
0 2
0
2
mhornste
Hi, I'm having issues calculating the average execution time of an available field in Splunk. I have searched for so...
by mhornste Path Finder in Splunk Search 06-21-2016
0 1
0
1
koushiknandan
I am trying to calculate TPS with the help of the queries below: Start Time Query host=X source=Y.log "data availab...
by koushiknandan New Member in Splunk Search 06-21-2016
0 4
0
4
smudge797
Is there a way to rename EventCodes xxxx field to "description" in timechart? Here is a sample search: Account_Name...
by smudge797 Path Finder in Splunk Search 06-21-2016
0 13
0
13
guruwells
Hi, We are using SharePoint ULS Viewer to watch SharePoint logs which are any errors, warnings, and critical things ...
by guruwells Explorer in Splunk Search 06-21-2016
0 5
0
5
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...