| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Hello, 
  Like the title says, I have the search criteria pretty nailed down, however, I would like to do a count so ...
        
         
           by 
           
                
                    
                        Makinde
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               04-06-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi, 
  Here are the three sources that I have for the below query that I need to optimize : a) tech_detail.gz b) grou...
        
         
           by 
           
                
                    
                        amoldesai
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-06-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have a CSV file uploaded as a lookup. I am using the userID from my search with the lookup, but for some reason, th...
        
         
           by 
           
                
                    
                        Aaron_Fogarty
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I am capturing events every minute. Within the events, there is a continuously compounding field: "FlowTotal_Running_...
        
         
           by 
           
                
                    
                        waldez
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               04-08-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I am trying to test a sedcmd command, inline, that Im going to add. I am finding a string and replacing it with a fie...
        
         
           by 
           
                
                    
                        tkwaller
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               04-08-2016
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        Good afternoon All, 
  I am having a hard time trying to understand the difference between "lookup", "inputlookup", a...
        
         
           by 
           
                
                    
                        janiceb
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-08-2016
             
           
         
        | 
		
		6
   | 
	  
	  3
	 | |||
| 
        I'm not sure if I can get any help here, but I am going to try cause I've been wrestling with this search/data for a ...
        
         
           by 
           
                
                    
                        EricLloyd79
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               04-05-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hello Splunkers 
  Hope you are doing good, appreciate beforehand all the time you take helping us out here. 
  So I'...
        
         
           by 
           
                
                    
                        benjillaz
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-05-2016
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I will try and explain my problem to the best of my ability. I am attempting to create a saved search from which I ho...
        
         
           by 
           
                
                    
                        helpmejesus
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have to take a logfile and extract certain fields to present as a percentage of availability ("UP" host_names).  I ...
        
         
           by 
           
                
                    
                        mikebarry
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I want to replace (" ") in my xml file to single (").Since there is some misplace of double codes in my whole file.So...
        
         
           by 
           
                
                    
                        john
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-15-2012
             
           
         
        | 
		
		1
   | 
	  
	  7
	 | |||
| 
        I need to fill missing values from search items as NULL (not the string, but actual NULL values) 
  I see options to ...
        
         
           by 
           
                
                    
                        abhijitp
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-04-2016
             
           
         
        | 
		
		1
   | 
	  
	  10
	 | |||
| 
        i have the last sync time for my activesync clients going to splunk via powershell input.  ex: LastSyncAttemptTime = ...
        
         
           by 
           
                
                    
                        gdavid
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Is there a working example of the use of color_field in the new Treemap visualization?  
  I have tried the form that...
        
         
           by 
           
                
                    
                        raoul
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-08-2016
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I am pulling syslogs and attempting to count IPs that are blocked for abuse. My counts are coming up 0. the IP used h...
        
         
           by 
           
                
                    
                        hermeslxxv
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               04-03-2016
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I'd like to have a simple XML dropdown that selects, as an example a Device Name. 
  deviceName,Vendor,Model
mainfw,C...
        
         
           by 
           
                
                    
                        esix_splunk
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               04-08-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am trying to have a single value panel. The search for the same is given below: 
  index=* host="prodserver-*" sour...
        
         
           by 
           
                
                    
                        sunilkumarpk
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               04-04-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I want to extract the field names from a URL's parameters. For example my raw event might look like this: 
  action=a...
        
         
           by 
           
                
                    
                        DPWSplunkPOC
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I would like to use the value of a field as a keyword search. For example, if I have field like dest_ip="1.1.1.1", ho...
        
         
           by 
           
                
                    
                        davidhake
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        My requirement is to monitor files daily, weekly, monthly, and quarterly and I have to search during a specific time ...
        
         
           by 
           
                
                    
                        prakashbhanu407
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I'm trying to build a simple SPL query to display the max, min, range (difference), and percent of the difference to ...
        
         
           by 
           
                
                    
                        dcascione
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello, 
  I'm trying to write a splunk query but dont know where to start with. Is it possible to write a query to se...
        
         
           by 
           
                
                    
                        nlrdy
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I looked through the docs and other Splunk Answers, but it still isn't making sense to me, so please bear with me.  ...
        
         
           by 
           
                
                    
                        aferone
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I have 3 Ticket groups A, B, and C. And multiple users. My system logs every ticket purchased under each ticket group...
        
         
           by 
           
                
                    
                        cseuser
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               04-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I would like to see the following for each index 
  limit (maximum size) Mbcurrent size Mbavg. Mb indexed per day las...
        
         
           by 
           
                
                    
                        lguinn2
                    
                
           
             
             
               Legend
             
           
           in
           Splunk Search
           
           
              
               04-23-2010
             
           
         
        | 
		
		6
   | 
	  
	  6
	 |