Splunk Search

Splunk Search
Community Activity
brianpreston
I'm trying to put logs which match a regex into a different index ("audit_private") than the one they come in with ("...
by brianpreston Path Finder in Splunk Search 05-15-2016
0 3
0
3
varunbiswas
Hi Team, I am trying to extract fields out of my log files. Even though the files are generated by the same source a...
by varunbiswas New Member in Splunk Search 05-15-2016
0 1
0
1
Bhagyashri
I want to search a string "hello welcome to splunk how to use splunk? pipeline splunk" but splunk doesnt ...
by Bhagyashri Explorer in Splunk Search 05-14-2016
0 2
0
2
techn0gichida
I see a lot of searches when using top or htop on the Splunk server, but I don't see them when trying to search for a...
by techn0gichida Explorer in Splunk Search 05-13-2016
0 1
0
1
jedatt01
I'm trying to create an alert that will trigger when the count of events is changed drastically from one time bucket ...
by jedatt01 Builder in Splunk Search 05-13-2016
0 2
0
2
kranthi851
Hi All, We are running out of drive space. How can I check space consumption of certain logs for last 60 days and ho...
by kranthi851 New Member in Splunk Search 05-13-2016
0 1
0
1
aelluru
I have an existing field named source which has a sample format of: /home/user/script.schema.table.date-time.log ...
by aelluru New Member in Splunk Search 05-13-2016
0 3
0
3
chrisprangnell
Hello, I've been reading a lot of posts here, but I seem to be missing something because I'm not understanding. Se...
by chrisprangnell Path Finder in Splunk Search 05-13-2016
0 4
0
4
annakeuchenius
I would like to search the history of one specific app. It is irrelevant which user performed the search. How can I g...
by annakeuchenius Engager in Splunk Search 05-13-2016
1 3
1
3
johnmccash
Hi, I'd like to be able to write a search to identify processes that are children or grandchildren of MS Office appl...
by johnmccash Explorer in Splunk Search 05-13-2016
0 1
0
1
yuwtennis
Hi! I would like to know if it is possible to add outputlookup and inputlookup in same search. My purpose is to crea...
by yuwtennis Communicator in Splunk Search 05-13-2016
0 3
0
3
markwymer
Hi, I'm trying to get a table of all the Session_ID values when the count of Logon_IDs is more than 2, but since th...
by markwymer Path Finder in Splunk Search 05-13-2016
0 1
0
1
Aaron_Fogarty
My search events contain a userID e.g. 'b1234'. I am using a lookup file to show the name, manager and department of ...
by Aaron_Fogarty Path Finder in Splunk Search 05-13-2016
0 6
0
6
harald_leitl
Hello, Is there a way to count the series of consecutive identical events that are interrupted by another event? So...
by harald_leitl Path Finder in Splunk Search 05-13-2016
1 10
1
10
MattQ
I am returning query results that give a list of IPs on which an event has occurred. I want to create an alert to fi...
by MattQ Explorer in Splunk Search 05-12-2016
0 6
0
6
geelsu
Newbie here. I was exploring Dashboard setup, so started doing some searches to create one with. I started eliminat...
by geelsu New Member in Splunk Search 05-12-2016
0 3
0
3
Phil219
Hello, my search basesearch|transaction attribute|table username, attribute As expected, this returns a table with gr...
by Phil219 Path Finder in Splunk Search 05-12-2016
0 8
0
8
vil505
This is probably simple, but how can I use the text input in a form to narrow down my results? I'm building a form t...
by vil505 Explorer in Splunk Search 05-12-2016
0 4
0
4
guillecasco
Hey, I have something like this for a drop-down in a Splunk dashboard: <input type="dropdown" token="trouID" searc...
by guillecasco Path Finder in Splunk Search 05-12-2016
0 2
0
2
olheiser01
I am trying to return a result when one field contains another. For example, field1="ABCDEFG" field2="CDE" Match= T...
by olheiser01 New Member in Splunk Search 05-12-2016
0 2
0
2
hcorleyss
Hi, is there a best practice to achieve the following? I am looking to search for events and then to output them to ...
by hcorleyss New Member in Splunk Search 05-12-2016
0 2
0
2
jreddy
Currently, my line chart is showing predict vales for the given subnets i.e when the subnets will run out of Free add...
by jreddy New Member in Splunk Search 05-12-2016
0 2
0
2
smhsplunk
I have two dropdowns, first one selects T1, T2 or T3. Depending on the first selection the second dropdown will ...
by smhsplunk Communicator in Splunk Search 05-12-2016
0 2
0
2
n179911
In Splunk, how can I search for a range of numbers (e.g. from "Test213" to "Test220")? I tried 'test2[13-20]" or 'te...
by n179911 New Member in Splunk Search 05-12-2016
0 4
0
4
cmahan
I need a search that will return details regarding a partitioned volume. For example: The  volume on a server was ...
by cmahan Path Finder in Splunk Search 05-12-2016
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...