Splunk Search

Splunk Search
Community Activity
the_wolverine
What is the syntax, please?
by the_wolverine Champion in Splunk Search 04-20-2016
1 5
1
5
sureshsala
I need help with the regular expression for field extraction of login status: Successful: source="/var/log/secure"...
by sureshsala Explorer in Splunk Search 04-20-2016
0 4
0
4
BaptVe
Hello, I'm searching to show all source from indexes on a search form. I'm able to extract the list of indexes with...
by BaptVe Path Finder in Splunk Search 04-19-2016
0 4
0
4
xiangtaner
Hi, I have two pieces of data: 1. a list of IP addresses stored in a lookup table host2ips.csv; 2. a source where IP...
by xiangtaner Path Finder in Splunk Search 04-19-2016
0 2
0
2
HattrickNZ
this is my search: | makeresults count=2 | eval start=relative_time(now(),"@d") | eval start_string=strftime(star...
by HattrickNZ Motivator in Splunk Search 04-19-2016
0 2
0
2
Kukkadapu
Hi, I have multiple columns (number of columns may vary) and wanted to search a string if it exists in any of the c...
by Kukkadapu Path Finder in Splunk Search 04-19-2016
0 6
0
6
ramaswamy
From Splunk Web, when I run a search, I receive the following message Search not executed: The minimum free disk spa...
by ramaswamy New Member in Splunk Search 04-19-2016
0 4
0
4
ddrillic
I have a large results set of a search which I would like to store as a lookup table. How can I do that?
by ddrillic Ultra Champion in Splunk Search 04-19-2016
0 6
0
6
rickgeorge
I want to create a custom chart from js_charts that extends the verticalfillerGauge chart. This chart would use SVG ...
by rickgeorge Explorer in Splunk Search 04-19-2016
1 2
1
2
socalvin
I read this but this was almost two years ago: http://splunk-base.splunk.com/answers/49/does-each-splunk-event-have-...
by socalvin New Member in Splunk Search 04-19-2016
0 2
0
2
sfellin
I am trying to use an eval object as the basis of a search pattern along with a wildcard and Splunk is not happy with...
by sfellin Engager in Splunk Search 04-19-2016
0 2
0
2
boddunan
Hi, I am searching for some way to extract count of each file type which is successfully processed. The logs contain...
by boddunan Engager in Splunk Search 04-19-2016
0 3
0
3
garinapavan
Hi , Request any help for the below questions: 1) I have two different searches: sourcetype=bcd "JMS-120: Dequeu...
by garinapavan Explorer in Splunk Search 04-19-2016
0 2
0
2
janiceb
Greetings, I am looking for a way to search through 2 sourcetypes: sourcetype=bro_http AND sourcetype=McAfee to find...
by janiceb Path Finder in Splunk Search 04-19-2016
0 7
0
7
reachskhm
I have log events which are little different, but each event has a unique name which I am interested in. However, thi...
by reachskhm New Member in Splunk Search 04-19-2016
0 4
0
4
David_Hodgson
I need to add a maximum column for a set of fields on each row (created using chart ... OVER ... BY ... ), and then a...
by David_Hodgson Engager in Splunk Search 04-19-2016
0 1
0
1
djce
Splunk recently fell over because the dispatch directory (on an ext2 filesystem) hit 32000 directory entries, so the ...
by djce Engager in Splunk Search 04-19-2016
3 5
3
5
OD_jfraher
This is the criteria I'm using: index=bcoat_logs sc_filter_result!=DENIED cs_host!="-" | stats count(cs_host) by cs_...
by OD_jfraher New Member in Splunk Search 04-18-2016
0 1
0
1
Catie_Carmody
The below returns the correct results, but I only get the RequestOne, RequestTwo, and meetscriteria fields when field...
by Catie_Carmody Engager in Splunk Search 04-18-2016
0 2
0
2
xvxt006
Hi, i have a simple query where i am getting response times by host. i want to get the sum of hosts as a filed. I ha...
by xvxt006 Contributor in Splunk Search 04-18-2016
0 7
0
7
monteirolopes
Hi, In my log, I have the same name field for three distinct values in the same event. For example: ... Security ID...
by monteirolopes Communicator in Splunk Search 04-18-2016
0 5
0
5
rafamss
Hi guys, I'm having a problem with my environment, we have 15 machines, 1 Master, 1 Deploy, 1 Universal Forwarder, 6...
by rafamss Contributor in Splunk Search 04-18-2016
5 4
5
4
LCM
As a note: 17:30 CET - 4,825 questions, 1,069 unanswered!?! There are so many answered questions still "open" / unti...
by LCM Contributor in Splunk Search 04-18-2016
5 7
5
7
Branden
Hello! I have some Windows event log data with 5 different event codes. I need to count by each of the event codes a...
by Branden Builder in Splunk Search 04-18-2016
0 2
0
2
helpmejesus
Hey fellow Splunkers, I have a very complex problem which I am attempting to solve and thought it couldn't hurt to a...
by helpmejesus Explorer in Splunk Search 04-18-2016
0 5
0
5
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors