| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        I have a list of hosts; I need to see if these hosts appear anywhere in my Splunked events. It is a very long list, s...
        
       
         
           by 
           
                
                    
                        lguinn2
                    
                
           
             
             
               Legend
             
           
           in
           Splunk Search
           
           
              
               05-24-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi,  
  I'm trying to get the system with the most number of logs (usage) for every hour. I did a search for: 
  even...
        
       
         
           by 
           
                
                    
                        qiaojing
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi, 
  I have found many searches using lookup files, but none works correctly for me What is the correct search to g...
        
       
         
           by 
           
                
                    
                        geantver0000
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        hi, 
  I have log with 3 columns 
  ID....TYPE...... DESC 1.......A............Member Since Year-2015 2...... B.........
        
       
         
           by 
           
                
                    
                        tp92222
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-26-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I am trying to group by text within a specific field. I'm essentially searching a message content field called event....
        
       
         
           by 
           
                
                    
                        proctormap
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-05-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I am not sure if this is feasible and done before. 
  We have anonymous users, each have their own sensors which gene...
        
       
         
           by 
           
                
                    
                        krantik
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-05-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I display two different graphs by using the following strings. 
  "Sending" earliest=-7days | eval gigabytes=((bytes/...
        
       
         
           by 
           
                
                    
                        thewho123
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I had a previous thread open, but since then I worked on the alert and refined some criteria. The alert is running of...
        
       
         
           by 
           
                
                    
                        dpanych
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-12-2016
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        If I have a search of  
  search|stats max(duration) by Action
 
  When I run the search, how can I add the time for ...
        
       
         
           by 
           
                
                    
                        Cuyose
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  10
	 
 | |||
| 
      
        When I enter this search:  
  sourcetype=win*
(EventCode=4624 OR EventCode=4634)| stats latest(eval(if(EventCode=4624...
        
       
         
           by 
           
                
                    
                        TheJagoff
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        When I try the search to create a running total out of the streamstats documentation, it doesn't work. Nothing change...
        
       
         
           by 
           
                
                    
                        ra01
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I have cache hit as well as cache miss reports, How do i get the ratio of cache hit i.e, cache hit / (cache hit + cac...
        
       
         
           by 
           
                
                    
                        spandana9
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I am collecting a PerfmonMK dataset that includes a memory value in bytes. I would like to display the value in KB. N...
        
       
         
           by 
           
                
                    
                        anewell
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-20-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I'm looking to create a report that finds expected hosts not reporting to Splunk without using the Macro. Anyone have...
        
       
         
           by 
           
                
                    
                        SecurityIsMyMid
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hi, 
  Can someone help me? I have the searches below and need to be combine the two to display the expected results:...
        
       
         
           by 
           
                
                    
                        Joshua
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I'm trying to run a search where I will get results if a field matches one of many predetermined values and I'm worri...
        
       
         
           by 
           
                
                    
                        drinkingjimmy
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-20-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hello.  
  I have a simple question: 
  I would like to have a specified index with sensitive data in it, however, I ...
        
       
         
           by 
           
                
                    
                        Fleshwriter
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        First of all I am very new to splunk!   My data can be simplified to look something like this. 
  Employee = (Unique...
        
       
         
           by 
           
                
                    
                        jojujose
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-21-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I run a daily script on the server, du -sk, against a certain directory that contains 200 subdirectories and write th...
        
       
         
           by 
           
                
                    
                        edwinmae
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-17-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I'm relatively new to Splunk queries. I have an event that contains JSON and within the JSON data is an array. There'...
        
       
         
           by 
           
                
                    
                        mbosse
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               03-15-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hi all, 
  I'm using the Splunk Field Extractor in order clean up the my search a bit, and I'm using the following re...
        
       
         
           by 
           
                
                    
                        raby1996
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-18-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  9
	 
 | |||
| 
      
        On my dashboard, I have a graph displaying how many workstations have out of date virus definitions. Several of these...
        
       
         
           by 
           
                
                    
                        grannnt
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-20-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        http://imgur.com/MbH4w37 
  Trying to recreate this chart in Splunk - can anyone assist, as I'm a bit uncertain where...
        
       
         
           by 
           
                
                    
                        Esky73
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               05-18-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        I might be going to deep here but I figured I'd give it shot... 
  I have a stats command keying off of a domain name...
        
       
         
           by 
           
                
                    
                        thisissplunk
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               05-21-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I need to join data from two (or more, ultimately) different sourcetypes based on the shared "host" field. Just a sub...
        
       
         
           by 
           
                
                    
                        thisissplunk
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               05-21-2016
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 |