Splunk Search

Splunk Search
Community Activity
ahogbin
Hello.. I am attempting to extract a string of varying format using regex. I have successfully extracted part of the...
by ahogbin Communicator in Splunk Search 03-06-2016
0 16
0
16
Bstylee303
So the basic idea of this is I have an event that has multiple entries within the same Data field. I need to join inf...
by Bstylee303 New Member in Splunk Search 03-06-2016
0 2
0
2
akanno
Hi All. I want to extract fields from the following log data. headerName=Host, Connection, Accept, headerValue=splu...
by akanno Communicator in Splunk Search 03-06-2016
0 1
0
1
usha_nittala
Hi All, I am getting below error for every search I am rinning for Summary indexing. Search process did not exit cl...
by usha_nittala New Member in Splunk Search 03-06-2016
0 2
0
2
cbrownlee
I have a sourcetype that contains application (SYS_ID) information. I also have a table that contains the responsible...
by cbrownlee New Member in Splunk Search 03-05-2016
0 2
0
2
saibhaskarammu
why we need to extract fields from machine data?
by saibhaskarammu New Member in Splunk Search 03-05-2016
0 3
0
3
seriouscat
Hi All, I'm currently working on a Splunk search that will show me DHCP leases for specific hosts and how long a hos...
by seriouscat Explorer in Splunk Search 03-05-2016
0 1
0
1
lakromani
I am testing using Splunk to index a minecraft server, but have some problem with user name. Lines look like this: F...
by lakromani Builder in Splunk Search 03-05-2016
0 3
0
3
jdjdjdjd
I am trying to create a view that merges log records from various files, ordered by their timestamps. This works nic...
by jdjdjdjd Engager in Splunk Search 03-04-2016
0 8
0
8
mrpaul
I am looking for a way to identify the start and end of a burst of events that has hundreds of thousands of events in...
by mrpaul Explorer in Splunk Search 03-04-2016
1 2
1
2
changux
Hi all. I have a field called src with values like: 348 55666 77666 95670 23456 I want to create a new field th...
by changux Builder in Splunk Search 03-04-2016
0 1
0
1
marcosrios
Hello, I have an event like this: 2016-03-04 00:02:05,546 DEBUG [net.ussouth.aps.shared.util.SysLogUtil] <?xml ve...
by marcosrios Explorer in Splunk Search 03-04-2016
0 1
0
1
ianbruton
I am not sure exactly how to ask this question, so I will try to just dive right in. Background: I work for a compan...
by ianbruton Explorer in Splunk Search 03-04-2016
1 5
1
5
digital_alchemy
I would like to create a search to show the number of IDS alerts per host. The problem I'm having is that I'm unable...
by digital_alchemy Path Finder in Splunk Search 03-04-2016
0 3
0
3
Shan
Sample data: <id>WGBSTH8180T</id> <sytems> <sys_Id>14502</sys_Id> <name>GYS<...
by Shan Builder in Splunk Search 03-04-2016
0 5
0
5
tgdvopab
I have the following search: index=main_index sourcetype=Perfmon:InboundPSTNCalls | timechart span=5min avg(Value) ...
by tgdvopab Path Finder in Splunk Search 03-04-2016
0 2
0
2
erichard
Hello, I have a list of assets like this: date,material,username,status 01/12/15,"IPad #4654654",eric,lent 01/12/...
by erichard Explorer in Splunk Search 03-04-2016
0 4
0
4
saravanababumr
How to show the duration on the Time Chart as tool tip in Simple XML? Do we have any parameter? I know that works i...
by saravanababumr New Member in Splunk Search 03-04-2016
0 1
0
1
johnraftery
I have inputs configured to allow for multiline events, representing groups of log lines. I'm then using it to build ...
by johnraftery Communicator in Splunk Search 03-04-2016
0 7
0
7
tp92222
I have 2 indexes: index=report and index=fixed Both have the same field ticket. When a ticket is reported, it goes i...
by tp92222 Explorer in Splunk Search 03-03-2016
0 4
0
4
Urao
Hi , I would like to write a search for logon failure on active directory and results should include the columns lik...
by Urao Engager in Splunk Search 03-03-2016
0 1
0
1
lbogle
Hello Splunkers, I am trying to take the values from an existing field/value pair and put them into new fields. host...
by lbogle Contributor in Splunk Search 03-03-2016
0 2
0
2
HattrickNZ
I have a search ...|table measInfoId that gives output in 1 column with the values e.g. measInfoId 1x 2x 3x ... I ...
by HattrickNZ Motivator in Splunk Search 03-03-2016
0 21
0
21
HattrickNZ
I am working with append and appendcols in a search, but getting an invalid timestamp. My search looks like this, bu...
by HattrickNZ Motivator in Splunk Search 03-03-2016
0 5
0
5
pkeller
I've constructed a lookup table containing some key data sources that I expect to see events from on a daily basis. ...
by pkeller Contributor in Splunk Search 03-03-2016
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...