Splunk Search

Splunk Search
Community Activity
cesar_tomas
Hello Everyone, I have a problem with Splunk 6.3 when I am trying to run the rex statement: | rex "WTIDCCN[-_]\d\d\...
by cesar_tomas Explorer in Splunk Search 03-03-2016
0 3
0
3
rtestu_splunk
Hi! I know there are many topics on XML field extractions, but did not see one that matches my requirement! I recei...
by rtestu_splunk Splunk Employee Splunk Employee in Splunk Search 03-03-2016
0 2
0
2
joxley
I have a column of seconds, some of which are negative (representing an outage). I want to use tostring(duration, "d...
by joxley Path Finder in Splunk Search 03-03-2016
1 1
1
1
Greggis
We were running Splunk 6.2.2. When looking for jobs that ran, under "Activity - Jobs", it shows the first 10 results...
by Greggis New Member in Splunk Search 03-03-2016
0 1
0
1
raduonica
Hello, I have two different types of data inputs, both having a field that represents an IP (let's call the list of ...
by raduonica New Member in Splunk Search 03-03-2016
0 2
0
2
steveskinner
Hi, I'm trying to add a trend line to my splunk line chart, but no trend line is appearing. Original search string:...
by steveskinner New Member in Splunk Search 03-03-2016
0 2
0
2
bugnet
Hi everyone, I have the following event: "... src=218.2.3.256 act=block app=ips rt=1433065461040 ...." The rt field...
by bugnet Path Finder in Splunk Search 03-03-2016
0 8
0
8
Rotema
Hello, I'm trying to run this search in order to range the values: index=prod GetClientStateNotFound | rex "Account...
by Rotema Path Finder in Splunk Search 03-03-2016
0 8
0
8
trunghung
I am trying to write a search that reports the percentage of total users impacted from log data. // All users will...
by trunghung Path Finder in Splunk Search 03-03-2016
0 7
0
7
HattrickNZ
Can I control which y-axis is on the left and which is on the right? for instance in the below can i have percent o...
by HattrickNZ Motivator in Splunk Search 03-02-2016
0 3
0
3
watkinst
If you wish to Search the API via command line (using the Splunk Binary included in the Forwarder package for example...
by watkinst Engager in Splunk Search 03-02-2016
0 1
0
1
ceng
Hi, Is there a way to merge 2 messages into 1 message? For example I have a sequence of messages: TestingData numT...
by ceng New Member in Splunk Search 03-02-2016
0 4
0
4
mprreddy51
Hi , Here is my requirement: In my search, _time is showing 1 hour difference to _raw. Why it is _time is not picki...
by mprreddy51 Explorer in Splunk Search 03-02-2016
0 1
0
1
HattrickNZ
I have a search that gives me a number of columns in the stats field. max(col1) max(col2) ... 1 2 ... Can I repla...
by HattrickNZ Motivator in Splunk Search 03-02-2016
0 5
0
5
skoelpin
I'm going through the limits.conf specs to see what the defaulted fields are and noticed that the default for max val...
by SplunkTrust SplunkTrust in Splunk Search 03-02-2016
0 5
0
5
pdoconnell
I have an alert designed to examine Windows event logs (event 560 or 4663) for file access by unauthorized users. The...
by pdoconnell Path Finder in Splunk Search 03-02-2016
0 6
0
6
HattrickNZ
I have 2 searches that I am appending that looks something like search1 | append [search search2] and basically se...
by HattrickNZ Motivator in Splunk Search 03-02-2016
0 1
0
1
HattrickNZ
I have 2 searches that I am appending that looks something like search1 | append [search search2] and basically s...
by HattrickNZ Motivator in Splunk Search 03-02-2016
0 5
0
5
spammenot66
My logs currently capture username and a session id. Keep in mind that 1 session can have multiple hits to different ...
by spammenot66 Contributor in Splunk Search 03-02-2016
0 5
0
5
johnraftery
I have a table where sometimes the value of a field can be a very, very long string. I want this to be shown in a tru...
by johnraftery Communicator in Splunk Search 03-02-2016
0 5
0
5
packet_hunter
Scenario: Looking at email logs and want to check the sender domain (sender@domain.tld) against a watch list. The wa...
by packet_hunter Contributor in Splunk Search 03-02-2016
0 5
0
5
gmelasecca
I just recently started running into issues with my activeMQ server. I convinced the business to allow me to push the...
by gmelasecca Engager in Splunk Search 03-02-2016
0 2
0
2
AaronMoorcroft
Hey Guys So I have a sourcetype of syslog, but under that sourcetype seems to be a whole bunch of hosts. What's the...
by AaronMoorcroft Communicator in Splunk Search 03-02-2016
0 5
0
5
pradeepkumarg
I don't have a single column to configure as rising column in DB Connect. But I have two columns one of which is date...
by pradeepkumarg Influencer in Splunk Search 03-02-2016
1 9
1
9
btd0000
Hi all, I'm fairly new to splunk so I hope you can help me. I have two searches that retrieve two columns of taskids...
by btd0000 Engager in Splunk Search 03-02-2016
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...