Splunk Search

Splunk Search
Community Activity
snabi
Hello I am trying to set up a Splunk search which will alert on unbalanced load across hosts for a target sourcetype...
by snabi Explorer in Splunk Search 05-20-2016
0 5
0
5
pvdijssel
Hi, I have a device generating CDR's. Within this CDR file there are multiple type of CDR's. Each type start with: S...
by pvdijssel Engager in Splunk Search 05-20-2016
0 9
0
9
jedatt01
I want to create an alert that will trigger when the count of a certian type of event changes significantly from what...
by jedatt01 Builder in Splunk Search 05-20-2016
0 2
0
2
jaho_splunk
Input.conf for Template for Citrix XenApp contains interval values of -1. What does the value -1 indicate ?
by jaho_splunk Engager in Splunk Search 05-20-2016
0 3
0
3
singhh4
Hey guys, So what i am trying to do is put a list inside of a list to get an output such as the one below Comapny ...
by singhh4 Path Finder in Splunk Search 05-20-2016
0 2
0
2
chburnett
So this is going to be a little...odd. I realize I'm asking a very circumstance-specific and idiosyncratic question; ...
by chburnett New Member in Splunk Search 05-20-2016
0 1
0
1
richgalloway
I have a CSV file I'm trying to index, but the wrong timestamp field is getting selected. UTC,LOCAL,HOSTNAME,SEVERIT...
by SplunkTrust SplunkTrust in Splunk Search 05-20-2016
0 9
0
9
goodsellt
I'm attempting to us rex or a similar function that will be able to help me remove the domain identifier from a usern...
by goodsellt Contributor in Splunk Search 05-20-2016
0 4
0
4
mark_groenveld
We would like to count the number of error events in 15 minute intervals and show that number as the number of errors...
by mark_groenveld Path Finder in Splunk Search 05-20-2016
0 1
0
1
ttoine
I am working on a graph in order to identify the most pinging customer accounts (traffic optimization, security). I w...
by ttoine Explorer in Splunk Search 05-20-2016
0 2
0
2
nicocin
I'm trying to convert a string to a date. The string looks like 2016-05-20T05:16:02.007+02:00
by nicocin Path Finder in Splunk Search 05-20-2016
0 4
0
4
jamesplouffe
I have events (call them "approvedset" events) generated on a regular interval which each containing a field called l...
by jamesplouffe New Member in Splunk Search 05-19-2016
0 2
0
2
SplunkNoviceUse
Hi I need help in creating a timechart for visualization of events with multiple fields of interest in a dashboard....
by SplunkNoviceUse Explorer in Splunk Search 05-19-2016
0 3
0
3
Phil219
To make a "plain english" dashboard panel, I currently use the following search to change a duration value (SecondsSi...
by Phil219 Path Finder in Splunk Search 05-19-2016
0 1
0
1
jwalzerpitt
I'm trying to craft a search that will show the percentage of quarantined messages by country, but I'm struggling a l...
by jwalzerpitt Influencer in Splunk Search 05-19-2016
0 12
0
12
aaronkorn
Hello, We have the Splunk windows app setup to monitor the system eventlogs on our citrix server and it appears to b...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 05-19-2016
1 12
1
12
muebel
How can I make a search case-sensitive? That is to say, I search for the general term "FOO" and want to only match "...
by SplunkTrust SplunkTrust in Splunk Search 05-19-2016
10 7
10
7
jlkokko
I have a simple search parsing project activity logs to pull a list of projects and people working on those projects:...
by jlkokko Path Finder in Splunk Search 05-19-2016
0 4
0
4
UCOP
I have created a field extraction for the data I am looking for. The field looks as follows: messages_read total/in...
by UCOP New Member in Splunk Search 05-19-2016
0 8
0
8
kiran331
Hi all, I have to trigger an alert for event=1, if there is no event=2 within 30min of event=1. Search I'm using: i...
by kiran331 Builder in Splunk Search 05-19-2016
0 3
0
3
smhsplunk
index=main source=locations sourcetype=location_information | search * AND address=$token1$ OR...
by smhsplunk Communicator in Splunk Search 05-19-2016
0 4
0
4
kiran331
Hi all, I'm trying to trigger an alert when an ID occurs more than 10 times in an hour and alert should be in a tab...
by kiran331 Builder in Splunk Search 05-19-2016
0 1
0
1
muralianup
I am trying to create a graph for status history of some machine. Values I have are the name of machine & its server ...
by muralianup Communicator in Splunk Search 05-19-2016
0 1
0
1
pradeepkumarg
I want to blacklist all the lookups from the replication bundle and would like to understand what are some valid use ...
by pradeepkumarg Influencer in Splunk Search 05-19-2016
0 3
0
3
melonman
Hi, I am looking for the chart property to control the max number of data points that a chart can handle. There are ...
by melonman Motivator in Splunk Search 05-19-2016
3 10
3
10
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...