Splunk Search

Splunk Search
Community Activity
YoungDaniel
Hi, My issue is I have two different searches, first: index=test user=test document=* second: index=test2 user=tes...
by YoungDaniel Path Finder in Splunk Search 12-17-2015
0 4
0
4
sunil_bansal
Instance_ID is one extracted field in code *. If there is a value in the $ID$ field, then result should list only fo...
by sunil_bansal New Member in Splunk Search 12-17-2015
0 2
0
2
cyndiback
Blackboard has changed the format of the bb-access-logs to include session information. With the new data the logs a...
by cyndiback Path Finder in Splunk Search 12-17-2015
1 7
1
7
EricLloyd79
This is probably going to be a simple answer, but I've racked my brain over it for more time than I should have. I h...
by EricLloyd79 Builder in Splunk Search 12-17-2015
0 5
0
5
echojacques
The objective of this search is to count the number of events in a search result. This is the current search logic t...
by echojacques Builder in Splunk Search 12-17-2015
6 4
6
4
jfeitosa
I am attempting to identify users who are sharing access to systems from 2 or more IPs within a given amount of time ...
by jfeitosa Path Finder in Splunk Search 12-17-2015
0 5
0
5
SridharS
Hi, I have a 3 different log files and there are 8 different formats in them. All formats have the same fields in t...
by SridharS Path Finder in Splunk Search 12-17-2015
1 4
1
4
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the search below to extract a field call Match...
by IRHM73 Motivator in Splunk Search 12-17-2015
0 7
0
7
sdaruna
Hi, How can I wrap a cell data in a Splunk Statitics Table to one line? I have a lot of data for one field and beca...
by sdaruna Explorer in Splunk Search 12-17-2015
1 2
1
2
john_dagostino
I've got a lookup table that consists of two columns; "Description" and "PCRE". What I'm looking to do is search my ...
by john_dagostino Path Finder in Splunk Search 12-17-2015
0 5
0
5
andy_lee
Hi My auditors are questioning and requiring that each event we log into Splunk has a unique identifier added by Sp...
by andy_lee New Member in Splunk Search 12-16-2015
0 4
0
4
amit97ee354
I am trying to perform the join on different multi search for a set of time called "Before" and set of time called "A...
by amit97ee354 Explorer in Splunk Search 12-16-2015
1 3
1
3
nidhiagrawal
I'm using Splunk to build some of the basic metrics. Events which are returned run in millions. I have to look for da...
by nidhiagrawal Explorer in Splunk Search 12-16-2015
1 5
1
5
melodyqu2015
I want to extract fields. This is the log: country=us,name = [peter, susan, jack],city=nyc When I do this: | ...
by melodyqu2015 New Member in Splunk Search 12-16-2015
0 4
0
4
Securitas
I have been trying to figure out on how to do a search for IP addresses that were hit on more than one Port in a shor...
by Securitas Engager in Splunk Search 12-16-2015
0 2
0
2
greg
I have a simple search like: sourcetype="A" | timechart span="1h" avg(x) as AvgCode and the resulting visualizatio...
by greg Communicator in Splunk Search 12-16-2015
0 3
0
3
abbam
Hi, I'm trying to run this search: index="proxy" [|inputlookup TEST.csv | return 2 $IPs $dates] My TEST.csv file ...
by abbam Explorer in Splunk Search 12-16-2015
0 6
0
6
sistemistiposta
Hello, I would like to run a scheduled report once. A very log time search, I don't care about performance or time t...
by sistemistiposta Path Finder in Splunk Search 12-16-2015
1 4
1
4
soniquella
Good morning. I hope you can help. I have been tasked with creating a chart for the top 25 users who spend the longe...
by soniquella Path Finder in Splunk Search 12-16-2015
0 3
0
3
syks
I am trying to craft a search which will display the users who have failed logins more than 2 times against a server....
by syks New Member in Splunk Search 12-16-2015
0 1
0
1
rusty009
I am looking to search for a given value (an IP in this case) between a specific time range. This is easy to do as a ...
by rusty009 Path Finder in Splunk Search 12-16-2015
0 2
0
2
proylea
I am trying to pass the numeric result of a subsearch to the head command with no success, can anyone see what I am d...
by proylea Contributor in Splunk Search 12-16-2015
0 7
0
7
manhuang
index=app sourcetype=epcpromotionsevent | stats count as num by eventName,hotelId The search above will display co...
by manhuang Explorer in Splunk Search 12-16-2015
0 4
0
4
tfaqir99
Hi, I'm trying to use the Cluster Command to list our Authentication API used by Client IP's. Through searching the ...
by tfaqir99 New Member in Splunk Search 12-16-2015
0 5
0
5
dstark75
I'm monitoring log files and want to generate reports using the most recent event types I'm seeing an inconsistent n...
by dstark75 New Member in Splunk Search 12-15-2015
0 1
0
1
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...