| Background: My windows AD users are in index "windersAD". All of their web traffic is logged in index "wsa". I would... by ronj_clark Explorer in Splunk Search 04-11-2016 0 3 | 0 | 3 | ||
| This should be an easy one, how do I get a list of my top users accessing Splunk? by tedder Communicator in Splunk Search 04-11-2016 1 4 | 1 | 4 | ||
| Here is an example of the log I am dealing with: <123 Main St> <456 Center St.> I'd like to simply extract the nam... by olheiser01 New Member in Splunk Search 04-11-2016 0 4 | 0 | 4 | ||
| Each log entry contains some json. There is a field that is an array. I want to count the items in that array. Exa... by yahoohunk Explorer in Splunk Search 04-11-2016 0 2 | 0 | 2 | ||
| Hi, I need to run a compare against the count of two different searches - how would I do that? I'm counting the num... by a212830 Champion in Splunk Search 04-11-2016 0 14 | 0 | 14 | ||
| I need to change sharing and permissions for a lookup table file using the REST API. I have been searching high and ... by polymorphic Communicator in Splunk Search 04-11-2016 3 23 | 3 | 23 | ||
| Is there a way to dynamically assign chart labels using a search? My search ends with a timechart values(foo) as bar,... by mszebenyi_splun Splunk Employee 2 3 | 2 | 3 | ||
| Hello Everyone, With my current search I am able to display results in three rows, however, I need two of the rows t... by RogueMrSmith Engager in Splunk Search 04-11-2016 0 2 | 0 | 2 | ||
| For example: source = D:\Users\ABC\Desktop\splunk\abc.log I have extracted the part of string I wanted using (?\w+... by apurva1707 New Member in Splunk Search 04-11-2016 0 1 | 0 | 1 | ||
| I have a submit button module containing search module and I want to execute the search only when user clicks on the ... by asingla Communicator in Splunk Search 04-10-2016 0 6 | 0 | 6 | ||
| Hi there, My external program is retrieving the data and creating lookup table every night. The files are stored lik... by kuga_mbsd New Member in Splunk Search 04-10-2016 0 7 | 0 | 7 | ||
| Why does my query blow-up in size with a join? I have a query which without a join (for further analysis) runs in 2M... by NickJLange Explorer in Splunk Search 04-10-2016 0 4 | 0 | 4 | ||
| Hello dear splunkers, Can anyone tell me why these two commands give different results ? sourcetype=shopping date="... by DavidHourani Super Champion in Splunk Search 04-09-2016 0 12 | 0 | 12 | ||
| hi, I would like to build a graph with these values: a 100 b 97,56 c 99,34 my issue is when i try to see a graph.. ... by tissparkle Explorer in Splunk Search 04-09-2016 0 4 | 0 | 4 | ||
| Hi we are using fs_notification and monitoring a specific path. I have a field called path which has the following v... by athorat Communicator in Splunk Search 04-09-2016 0 3 | 0 | 3 | ||
| This should be an easy thing to do but obviously, I am missing it. I need to extract "cannot be located" c.f.a.k.m.... by ibekacyril Explorer in Splunk Search 04-09-2016 0 7 | 0 | 7 | ||
| Hello, Like the title says, I have the search criteria pretty nailed down, however, I would like to do a count so on... by Makinde New Member in Splunk Search 04-09-2016 0 6 | 0 | 6 | ||
| Hi, Here are the three sources that I have for the below query that I need to optimize : a) tech_detail.gz b) group_... by amoldesai Explorer in Splunk Search 04-08-2016 0 2 | 0 | 2 | ||
| I have a CSV file uploaded as a lookup. I am using the userID from my search with the lookup, but for some reason, th... by Aaron_Fogarty Path Finder in Splunk Search 04-08-2016 0 6 | 0 | 6 | ||
| I am capturing events every minute. Within the events, there is a continuously compounding field: "FlowTotal_Running... by waldez Engager in Splunk Search 04-08-2016 0 3 | 0 | 3 | ||
| I am trying to test a sedcmd command, inline, that Im going to add. I am finding a string and replacing it with a fie... by tkwaller Builder in Splunk Search 04-08-2016 0 7 | 0 | 7 | ||
| Good afternoon All, I am having a hard time trying to understand the difference between "lookup", "inputlookup", and... by janiceb Path Finder in Splunk Search 04-08-2016 6 3 | 6 | 3 | ||
| I'm not sure if I can get any help here, but I am going to try cause I've been wrestling with this search/data for a ... by EricLloyd79 Builder in Splunk Search 04-08-2016 0 6 | 0 | 6 | ||
| Hello Splunkers Hope you are doing good, appreciate beforehand all the time you take helping us out here. So I'm in... by benjillaz Explorer in Splunk Search 04-08-2016 1 2 | 1 | 2 | ||
| I will try and explain my problem to the best of my ability. I am attempting to create a saved search from which I ho... by helpmejesus Explorer in Splunk Search 04-08-2016 0 3 | 0 | 3 |