| Thread Info | |||||
|---|---|---|---|---|---|
| 
        We have a field extraction in apps/search/local/props.conf like this: 
  [my_glog_kv]
...
EXTRACT-my_glog_kv = ^(?<se...
        
         
           by 
           
                
                    
                        rgsage
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-07-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I have events that detect compliance of machines via forescout data (we don't have the app installed) and I'd like to...
        
         
           by 
           
                
                    
                        tristamaltizo
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi at all, 
  I have to separate the results of a transaction to separately show each event. I'd like to do this beca...
        
         
           by 
           
                
                    
                        gcusello
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		2
   | 
	  
	  4
	 | |||
| 
        For example: 
  Message: An attempt was made to change the password
Subject: 
        Security ID:  ABC/DEF
        A...
        
         
           by 
           
                
                    
                        pandeyashish
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-13-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello all, 
  I'm making an alerts report and by now, I have the total number of Alerts for a month, let's set it as ...
        
         
           by 
           
                
                    
                        marina_rovira
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        I have following values in a field(CPU) 
  000 00:00:00.00 
  000 00:00:00.03 
  000 00:00:43.18 
  000 00:00:20.69 
...
        
         
           by 
           
                
                    
                        asifhj
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-21-2014
             
           
         
        | 
		
		1
   | 
	  
	  6
	 | |||
| 
        Hi, 
  I would like to do a transformation like this: 
  
    
  Can you help how to achieve this? 
  Thanks in advan...
        
         
           by 
           
                
                    
                        HeinzWaescher
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		1
   | 
	  
	  4
	 | |||
| 
        Hello, 
  I have an output table like below from a streamstats call on my events: 
  period    total   cummulative_to...
        
         
           by 
           
                
                    
                        dimoklis
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		1
   | 
	  
	  7
	 | |||
| 
        Hi everyone, 
  I am trying to do the following in Splunk, but it's not working: 
  index=MRM eventtype=MRM_ERROR |
e...
        
         
           by 
           
                
                    
                        tkasim
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Blacklisting works to blacklist a file or directory... but is there an easy way using blacklisting in inputs.conf to ...
        
         
           by 
           
                
                    
                        TobiasBoone
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Dear experts, 
  I defined the below mentioned pivot to generate a monthly report of the most frequently used URL pat...
        
         
           by 
           
                
                    
                        el_ster
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               12-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        My Event: 
  Directory: /var/tmp/.X11-unix
  Mtime    : 2015-01-06 06:26:36 +0000        | 2016-01-04 15:31:39 +0000
...
        
         
           by 
           
                
                    
                        ejharts2015
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I want to add a column "FinalType" in a statistical table, so when the EventType=ScoreLock and TxnType=Renewal, it sh...
        
         
           by 
           
                
                    
                        athorat
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I'm running Splunk Enterprise on my Windows machine and am facing an issue in loading my dashboard fully. The dashboa...
        
         
           by 
           
                
                    
                        kevinreese
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        With Hunk, we're getting an invalid Kerberos principal when we try to run a search that triggers MapReduce. The strea...
        
         
           by 
           
                
                    
                        eangeles
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-25-2015
             
           
         
        | 
		
		0
   | 
	  
	  11
	 | |||
| 
        I am running a search to identify all users and the URLs they have connected to. The result includes duplicate users,...
        
         
           by 
           
                
                    
                        Presh
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi There, 
  I have a field that identifies users, e.g. userID. I also have a field that is common in every log, e.g....
        
         
           by 
           
                
                    
                        bspier1
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I am currently trying to group together unique products, and have the username listed under each product, however, I ...
        
         
           by 
           
                
                    
                        emamedov
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               01-07-2016
             
           
         
        | 
		
		2
   | 
	  
	  3
	 | |||
| 
        Hello everyone 
  I'm trying to track down the reason my Data Summary in the Search app is reporting BILLIONS of even...
        
         
           by 
           
                
                    
                        tkwaller
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        HI, 
  I have a search in which I am interested in three fields: 
  index=my_computer sorucetype=asia_data message="N...
        
         
           by 
           
                
                    
                        jagdeepgupta813
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        172.22.220.15 - XXX@XXX.com [05/Jan/2016:01:19:36 -0600] "GET HTTPS://XXX.allianceweb2.XXXX.com/AERWEB/dwr/interface/...
        
         
           by 
           
                
                    
                        manjunathin
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-05-2016
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        This is my expected result: 
  Exceptions  Day1  Day2  Day3  Day4  Day5
Abc          5     4     3     1     0
Start ...
        
         
           by 
           
                
                    
                        Madhan45
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        I'm new to Splunk and trying to configure an alert so when Windows Event ID 4760 occurs. I have the basic syntax crea...
        
         
           by 
           
                
                    
                        dmittel
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi,  
  I wonder whether someone may be able to help me please. 
  I have the following two searches: 
  index=main a...
        
         
           by 
           
                
                    
                        IRHM73
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               01-12-2016
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi helpful people, 
  I wish to display on a column graph an average line for my search. My current search is as foll...
        
         
           by 
           
                
                    
                        SecureIA
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-11-2016
             
           
         
        | 
		
		1
   | 
	  
	  4
	 |