Splunk Search

Splunk Search
Community Activity
anirban_nag
I have one index as foo. In this index there are messages like Bar Baz Hello...., Bar Baz Blah..., Bar Hi.... I want ...
by anirban_nag Explorer in Splunk Search 12-22-2015
0 1
0
1
dantu
Hi Guys, I have the following data set that i retrieve using a search : host calltype count pc4b...
by dantu Explorer in Splunk Search 12-22-2015
0 4
0
4
FunPolice
I have some pie charts on a dashboard: <dashboard> <label>Mail Gateway Summary</label> <row>` <chart> ...
by FunPolice Path Finder in Splunk Search 12-22-2015
0 3
0
3
kavu_vr
Hi, I am a newbie to splunk and would like to know how to solve the following problem. I have a SharePoint dump whic...
by kavu_vr Engager in Splunk Search 12-22-2015
1 11
1
11
athorat
index=aap_prod sourcetype="HDP:PROD:OOZIE" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Actio...
by athorat Communicator in Splunk Search 12-22-2015
0 12
0
12
ewanbrown
Hi, I have a list of IPs, and I want to create a chart showing traffic from them, but I also want a version which ex...
by ewanbrown Path Finder in Splunk Search 12-22-2015
0 2
0
2
mjd555
Problem I want to be able to create a timechart that outlines the company's incident count by week. The issue I hav...
by mjd555 Path Finder in Splunk Search 12-22-2015
0 8
0
8
mcrawford44
Example data; (This is one run of a DBX dump input to an index.) ComputerName1, Application1, _time1 ComputerName1, ...
by mcrawford44 Communicator in Splunk Search 12-22-2015
2 6
2
6
nbonner
I am looking to build a dashboard where a user can submit a session number & retrieve the entire history of a session...
by nbonner Explorer in Splunk Search 12-22-2015
0 4
0
4
madsurfer
Hi, Is it possible to use ".exe" as an External Lookup? Everything I make a lookup in a search I receive the follow...
by madsurfer Explorer in Splunk Search 12-22-2015
0 1
0
1
aniketb
Hi, Can someone help me extract the time in MS from the following log line? Dec 15, 2015 9:35:08 PM org.apache.cata...
by aniketb Path Finder in Splunk Search 12-22-2015
0 3
0
3
daniel_augustyn
Is there a way in Splunk to tag some specific logs and keep them for longer retention time? So for example, I want to...
by daniel_augustyn Contributor in Splunk Search 12-22-2015
0 2
0
2
epacke
Hi! Is it possible and/or advisable to host a lookup file on a Windows share? We are considering putting it on a ce...
by epacke Path Finder in Splunk Search 12-22-2015
0 2
0
2
horsefez
Hi there, I'm into correlation searches now and I'm stuck on a problem combining tree tables, while certain conditio...
by horsefez Motivator in Splunk Search 12-21-2015
0 2
0
2
Wiggy
How can someone add a custom search command to the list that search help pops up? I have already added a new custom ...
by Wiggy Splunk Employee Splunk Employee in Splunk Search 12-21-2015
2 4
2
4
Bagaboo
Hello, I am using Splunk Light to create a proof of concept with Splunk. I have imported a .csv file. One of the ...
by Bagaboo Engager in Splunk Search 12-21-2015
0 2
0
2
CREVITCH
I have logs that do not use the default name value format for the user field. When I add a field extractor for my us...
by CREVITCH Path Finder in Splunk Search 12-21-2015
0 3
0
3
johnboldt
I'm receiving the following error message on a search: Error in 'eval' command: Failed to parse the provided argument...
by johnboldt Explorer in Splunk Search 12-21-2015
0 6
0
6
rakesh_498115
Hi Team, I have a forwarder installed and configured to forward logs that it is receiving daily. The timestamp in th...
by rakesh_498115 Motivator in Splunk Search 12-21-2015
0 5
0
5
sarfarajsayyad
We have an inner join on two indexes. When we are querying with time controller its not showing data properly with To...
by sarfarajsayyad New Member in Splunk Search 12-21-2015
0 8
0
8
kamaleshwar
I want to get the combined result of two events. E.g The first event have reference ID, Name & IP and the second even...
by kamaleshwar Explorer in Splunk Search 12-20-2015
0 1
0
1
i2sheri
I have implemented a custom rest end point and it's working. Now I have another requirement to run Splunk searches in...
by i2sheri Communicator in Splunk Search 12-20-2015
0 3
0
3
i2sheri
Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for...
by i2sheri Communicator in Splunk Search 12-20-2015
0 10
0
10
clearslide_cwon
i have splunkforwarder running but once a while we run into issue with the following error about file being binary - ...
by clearslide_cwon New Member in Splunk Search 12-19-2015
0 5
0
5
jbarto
I have two sourcetypes that have URL fields. I am attempting to remove the . so that both fields are just letters an...
by jbarto New Member in Splunk Search 12-19-2015
0 7
0
7
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors