Splunk Search

Splunk Search
Community Activity
nivek000
Suppose a search returns the following data: _time Key Value 10:30:00 Key1 8 10:30:00 Key2 50 10...
by nivek000 New Member in Splunk Search 06-09-2016
0 3
0
3
jxiongjx
In my search I currently have ...| transaction startswith = "start" endswith = "end" maxspan = 10m | eval current = ...
by jxiongjx Engager in Splunk Search 06-09-2016
0 2
0
2
ejwade
Against my events, I am trying to match a long list (2000 records) of malicious URL strings (e.g., hereisavirus.com) ...
by ejwade Contributor in Splunk Search 06-09-2016
0 3
0
3
thoban
I'm looking to show the duration of logons through VDI logs. I convert _time into something better for the Start and...
by thoban Explorer in Splunk Search 06-09-2016
0 4
0
4
kranthi851
Hi, I have to get a result which is not in the lookup file. In the lookup, I have TIME and IP_PN. In the search resu...
by kranthi851 New Member in Splunk Search 06-09-2016
0 8
0
8
smhsplunk
Drilldown from a page to a new dashboard changes the app to Search & Reporting and brings the Search & Reporting navi...
by smhsplunk Communicator in Splunk Search 06-09-2016
0 2
0
2
jselvi
I have a JSON entry as follows: { [-] name: change_user_access parameters: [ [-] { [+] ...
by jselvi Explorer in Splunk Search 06-09-2016
0 4
0
4
jmaple
I'm trying to create a table of VPN connection statistics where the easiest way to see the data is to look at the tim...
by jmaple Communicator in Splunk Search 06-09-2016
0 4
0
4
shaker_ali
I have an output.csv from one of the searches and it has two fields: join_date and login_date. Is there any way I can...
by shaker_ali Engager in Splunk Search 06-09-2016
0 3
0
3
lohit
i have to set up a Archiving policy and storage requirements in SPlunk. Estimated logs per day would be 100 GB. So i...
by lohit Path Finder in Splunk Search 06-09-2016
0 5
0
5
zaphod1984
I have log messages in the following format: _time=... a_foo=10 a_bar=1 a_baz=20 _time=... a_foo=1 a_bar=2 a_baz=1 _...
by zaphod1984 Path Finder in Splunk Search 06-09-2016
1 3
1
3
user12345a_2
So I have the following search/report that I run daily: index=os_linux NOT root tag=authentication NOT tag=failure |...
by user12345a_2 Explorer in Splunk Search 06-08-2016
0 1
0
1
pdjhh
Hi. A site we are on has attemtped to migrate data from one splunk cluster to another. We've come in late to help an...
by pdjhh Communicator in Splunk Search 06-08-2016
1 2
1
2
jgbricker
I have a request to produce a table for our file sharing audit log that shows the Top Upload files listing the file t...
by jgbricker Contributor in Splunk Search 06-08-2016
0 2
0
2
servlette
Hi, Is there a way to create a search on the fly based on user input? What I have is a textfield and drop-down. Us...
by servlette Engager in Splunk Search 06-08-2016
0 2
0
2
tmarlette
I am attempting to extract 2 fields, that are structured the same in an event, however represent 2 actions. one repre...
by tmarlette Motivator in Splunk Search 06-08-2016
0 14
0
14
ManfredGrill
Hi, I basically need to lookup the field creationTime in an object log for objects that show up in a request log. Us...
by ManfredGrill Explorer in Splunk Search 06-08-2016
0 6
0
6
marcoeur5
The question is the simple case of one set of conditions. My goal is to line graph (4) variations in one chart: sum...
by marcoeur5 Engager in Splunk Search 06-08-2016
0 3
0
3
ckdoan
Hi all, So I'm working with log files, and here's a sample entry, 8:09:03 IN: "field1" "user1" 8:09:04 IN: "fi...
by ckdoan New Member in Splunk Search 06-08-2016
0 4
0
4
gustavomichels
Hey all, Using Splunk 6.0.2 across the board, I'm trying to extract key="value" pairs from WinEventLog entries prese...
by gustavomichels Path Finder in Splunk Search 06-08-2016
0 2
0
2
canar40
Newbie here so please bear with me  I created a table using stats count with 3 columns. What I also did is to dyna...
by canar40 Engager in Splunk Search 06-08-2016
0 1
0
1
alan20854
Hi, I am currently trying to find all the events that contain the phrase "ERROR" and based on their IDs, I want to s...
by alan20854 Path Finder in Splunk Search 06-08-2016
0 3
0
3
gary_richardson
Hello I need to give a lookup table search the ability to use wildcards against the values contained in the lookup f...
by gary_richardson Path Finder in Splunk Search 06-08-2016
0 1
0
1
ashish9433
Hi Team, I have a table in Splunk which is as below Name Val1 Val2 Val3 Val4 abc YES No ...
by ashish9433 Communicator in Splunk Search 06-08-2016
0 2
0
2
kiran331
Hi all, I'm trying to merge fields. I need to have each value separately, but here I can see a group value as string...
by kiran331 Builder in Splunk Search 06-07-2016
0 1
0
1
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...