Thread Info | |||||
---|---|---|---|---|---|
Should be easy enough, but not working for me. I am trying to pull a hostname of a log. I am terrible at regex and tr...
by
daniel333
Builder
in
Splunk Search
02-09-2016
|
0
|
5
| |||
Hi, I wonder whether someone could help me please.
I'm trying to create a search which identifies inactive users o...
by
IRHM73
Motivator
in
Splunk Search
02-10-2016
|
0
|
6
| |||
Hi,
I have this code:
|rex max_match=0 field=values "value\":\"(?<example>(.*?))\""
|eval example=mvindex(examp...
by
dkeck
Influencer
in
Splunk Search
02-09-2016
|
0
|
5
| |||
Hi Splukers,
I cannot get a search to produce what I want. Please help me. I tried the following search and got re...
by
sunrise
Contributor
in
Splunk Search
02-09-2016
|
0
|
4
| |||
We have a lot of searches that run to ensure we are receiving data from a Splunk forwarder and that it is still runni...
by
mookiie2005
Communicator
in
Splunk Search
02-09-2016
|
0
|
2
| |||
Search:
index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id)
When s...
by
LWilliamson1
Explorer
in
Splunk Search
02-09-2016
|
0
|
1
| |||
How do we add users or groups to roles in a Splunk search head cluster or create new roles?
by
sat94541
Communicator
in
Splunk Search
04-22-2015
|
2
|
5
| |||
Hi,
I have events with the below format:
"phone":{"areaCode":"732","prefix":"986","lineNumber":"0245",
Is t...
by
splunker9999
Path Finder
in
Splunk Search
02-09-2016
|
0
|
4
| |||
Hi,
There is a web app that has an 'init' event on load. It carried current 'version' and 'sessionId'. All other e...
by
maclun
New Member
in
Splunk Search
02-08-2016
|
0
|
1
| |||
Hello Experts,
I have 2 different sources
source 1 has hostname, ip address source 2 has hostname, os, os ver...
by
chaseto
Explorer
in
Splunk Search
02-08-2016
|
0
|
8
| |||
Hi,
I'm pretty new to spluk, I'm looking for some help with malware detection. What would the search expression...
by
zabarai
Engager
in
Splunk Search
04-01-2013
|
2
|
1
| |||
We need to find the most talkative indexers within Splunk for the last 24 hour period.
by
mattholt
New Member
in
Splunk Search
02-09-2016
|
0
|
1
| |||
I am indexing JSON data. I need to be able to do stats based "by patches" and "by admin". I can't get spath or mvexpa...
by
lyndac
Contributor
in
Splunk Search
02-08-2016
|
2
|
3
| |||
Hi All,
I am trying to link 2 indexes using join.
I have tried the following code:
index=index1| join Id[in...
by
diliptmonson
Explorer
in
Splunk Search
02-09-2016
|
0
|
3
| |||
I need to create an outputlookup file with more than 10,000 results. I've looked through the limits.conf examples and...
by
jambajuice
Communicator
in
Splunk Search
01-12-2011
|
3
|
5
| |||
Persistent queues are not available for splunktcp, I use several Forwarders on networks n, sending to a central forw...
by
SylviaB
New Member
in
Splunk Search
02-22-2012
|
0
|
2
| |||
Hi Guys,
What is the difference between user and author fields along with the fields below as well?
title, auth...
by
taraksinha
New Member
in
Splunk Search
02-09-2016
|
0
|
1
| |||
Hi
I have the below json file in Splunk. How do I extract based on api calls? Eg.
apiname coun...
by
anasar
New Member
in
Splunk Search
02-03-2016
|
0
|
3
| |||
I don't know if this has been answered in another question, but I'm trying to run a report for external IPs that have...
by
ststephe
Engager
in
Splunk Search
02-02-2016
|
0
|
6
| |||
Hello
I enter in the search:
index =main | timechart count by sourcetype
And I "save as" a dashboard pane...
by
Hindoo
Path Finder
in
Splunk Search
04-19-2015
|
1
|
11
| |||
I have a couple logins (user) and the ip addresses (c_ip) in a lookup table. As a true test to make a search to compa...
by
vesug
New Member
in
Splunk Search
02-08-2016
|
0
|
2
| |||
I'm trying to calculate Total count and avg(count) of users on a specific file...
I don't think it's the right way...
by
prakash007
Builder
in
Splunk Search
02-08-2016
|
0
|
5
| |||
When I issue 'splunk status' on Linux, the exit code is 0 even when splunk is not running. This makes it hard to use ...
by
ianformanek
Explorer
in
Splunk Search
11-30-2011
|
2
|
9
| |||
I have a log that records a transaction name, channel, and timing information, and need to calculate the maximum rate...
by
bowesmana
SplunkTrust
in
Splunk Search
02-07-2016
|
0
|
4
| |||
We use inputlookup to run large numbers (thousands) of indicators against network traffic in our org. This has worked...
by
rgonzale6
Path Finder
in
Splunk Search
02-05-2016
|
0
|
1
|