Splunk Search

Splunk Search
Community Activity
bluesaint
I have got a field in my log files that is storing failed login IP address "Failed password for invalid user astro fr...
by bluesaint New Member in Splunk Search 06-19-2016
0 1
0
1
belladonna
Hello. I want to make a dashboard with statistics about errors that happen in our application. I've made column cha...
by belladonna New Member in Splunk Search 06-18-2016
0 7
0
7
jrich523
I have a couple of fields, Node and NodeID, which will both have a number. Then I have NodeName which is of the forma...
by jrich523 Path Finder in Splunk Search 06-18-2016
0 1
0
1
dandaily
I am looking to run anomaly detection on failed and successful logons per user per host over a given time frame (7 da...
by dandaily Explorer in Splunk Search 06-17-2016
0 1
0
1
nravichandran
I have a multi-select dropdown which is dynamically populated. I want to show only one option to the user to choose f...
by nravichandran Communicator in Splunk Search 06-17-2016
0 2
0
2
moaf13
I have two multi value fields with delim "," (comma) field1 field2 \value\random\end, ...
by moaf13 Path Finder in Splunk Search 06-17-2016
0 2
0
2
pashtet13
I need to search through my email logs to determine who sends emails to personal accounts (e.g. gmail, yahoo, etc). R...
by pashtet13 New Member in Splunk Search 06-17-2016
0 4
0
4
dwear
I have a CSV with 3 columns; Username, AD group, Logins (Logins being total number of logins for that user). I want t...
by dwear Explorer in Splunk Search 06-17-2016
0 2
0
2
HeinzWaescher
Hi, let's say we have an event with Field1=A Field2=B and another event with Field1=B Field2=A How can I count...
by HeinzWaescher Motivator in Splunk Search 06-17-2016
0 4
0
4
rgsage
We are on Splunk 6.2.1 Every night we have Splunk email our executive staff a PDF with a bar chart showing a measure ...
by rgsage Path Finder in Splunk Search 06-17-2016
0 2
0
2
daniel333
All, I am trying to understand how I can have full queues on a heavy forwarder but have plenty of CPU and RAM avail...
by daniel333 Builder in Splunk Search 06-17-2016
0 4
0
4
TCK101
Hello I have a Top 10 query and it's run using earliest of -3mon to latest @mon So I would like to be able to return...
by TCK101 New Member in Splunk Search 06-17-2016
0 1
0
1
kranthi851
Hi How to extract these users using Regex? I need user=eerfe33, nrt123,.. file:_C:\Users\eerfe33\Documents.... fil...
by kranthi851 New Member in Splunk Search 06-17-2016
0 5
0
5
muellernc
Dear Splunk Community, In the current implementation of my dashboard, I have a scatter chart panel for which I am t...
by muellernc Engager in Splunk Search 06-16-2016
0 3
0
3
mjones414
I have data that has a watermark percentage, and a consumed percentage in a timechart. I want to determine how much ...
by mjones414 Contributor in Splunk Search 06-16-2016
0 1
0
1
icegras
I have used the dump command to extract data from production server and play with it on my local. I have 6 different ...
by icegras Explorer in Splunk Search 06-16-2016
0 2
0
2
johnraftery
Hi, I have this search: eventtype=mlc sourcetype=murex_log4j source=launchermxmlc.mxres.log | stats earliest(_time...
by johnraftery Communicator in Splunk Search 06-16-2016
1 8
1
8
smhsplunk
I have several pie charts. I would like to drilldown from each of the pie charts to the same table in a different vie...
by smhsplunk Communicator in Splunk Search 06-16-2016
0 7
0
7
tkwaller
We have a summary index called summary_site_stats, One of the saved searches that adds data to that summary index i...
by tkwaller Builder in Splunk Search 06-16-2016
0 4
0
4
tmarlette
So I am extracting fields using the standard field transforms, and many of my uri results and user agents are returni...
by tmarlette Motivator in Splunk Search 06-16-2016
0 3
0
3
chandra61446
I have search output wherein in field DB_NotBackedup has 3 values: 1- null value 2- value greater than 3 3- value le...
by chandra61446 New Member in Splunk Search 06-16-2016
0 2
0
2
bowesmana
I have two types of log entry with a common field. I am using join to get the index=web_load sourcetype=instrument ...
by SplunkTrust SplunkTrust in Splunk Search 06-16-2016
0 2
0
2
Navanitha
Hi, I have a comparatively very long search scheduled to run on the 1st of every month. This includes 2 subsearches:...
by Navanitha Path Finder in Splunk Search 06-16-2016
0 6
0
6
JScordo
I am trying to ingest the structured logs from our main Perforce server. I have the structured logs split out to mult...
by JScordo Path Finder in Splunk Search 06-16-2016
0 5
0
5
vikramphilar
My raw data consists of xml data as below: <fundTemplateName>FUND1</fundTemplateName><quantityExpression>1600</quan...
by vikramphilar New Member in Splunk Search 06-16-2016
0 4
0
4
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...