Splunk Search

Splunk Search
Community Activity
joarsvensson
I want to do an automatic lookup from a CSV file on index time, and add new fields to the event. I got this working, ...
by joarsvensson New Member in Splunk Search 10-31-2015
0 5
0
5
m_vivek
I am doing a simple search: index=pqr host=xyz* NOT TYPE="*ABCDE*" | fields X, Y | timechart limit=0 span=10m count,...
by m_vivek Path Finder in Splunk Search 10-31-2015
0 9
0
9
alaking
I am trying to audit bandwidth usage. The following search works as expected, except the URLS flood the URL field. I ...
by alaking Explorer in Splunk Search 10-31-2015
0 1
0
1
markwymer
Hi all, I'm trying to extract the filename and file ext of a windows path into to different fields. The sourcetype i...
by markwymer Path Finder in Splunk Search 10-30-2015
0 5
0
5
a212830
Hi, I need a detailed report on search concurrency, for both scheduled and interactive searches. How would I get th...
by a212830 Champion in Splunk Search 10-30-2015
0 2
0
2
mkatz
I have a search that results in an IP address as the result with the field name clientIP: host=hostname SSL=TLSv1.2 ...
by mkatz New Member in Splunk Search 10-30-2015
0 6
0
6
aashish_122001
Can we put or in 2 regex conditions? If no, is there any alternative? for example index = idx1 | regex name = ^Aa ...
by aashish_122001 Explorer in Splunk Search 10-30-2015
0 3
0
3
chlily
The abclogs index contains a field call "userid" and there is similar field "identity" in the file totalname.csv. Now...
by chlily New Member in Splunk Search 10-30-2015
0 3
0
3
gcusello
I have to identify processes not running on a list of hosts. To do this, I have a lookup table with all the processes...
by SplunkTrust SplunkTrust in Splunk Search 10-30-2015
0 1
0
1
dmccabe2
Hi, We have a large amount of data in the Apache log files, and we do not want images to be indexed. How do I match...
by dmccabe2 New Member in Splunk Search 10-30-2015
0 3
0
3
pmcfadden91
Hi, I posted this question before, but was unable to attach the picture later in the thread. I am looking to add a c...
by pmcfadden91 Path Finder in Splunk Search 10-29-2015
0 5
0
5
DDerck
I would like to know if search performance could be increased by moving buckets from warm to cold? My main index cont...
by DDerck New Member in Splunk Search 10-29-2015
0 1
0
1
reswob4
So after reviewing a number of Q&As on this site, I created the following search to track currently logged on VPN use...
by reswob4 Builder in Splunk Search 10-29-2015
0 2
0
2
HattrickNZ
How do i assign a value to a variable in a splunk search and then use that variable in the search? something like v...
by HattrickNZ Motivator in Splunk Search 10-29-2015
0 5
0
5
bharathkumarnec
Hello All, I have created a bar graph in Splunk, Is there a possibility to show count(numeric value) on top of each ...
by bharathkumarnec Contributor in Splunk Search 10-29-2015
0 1
0
1
omuelle1
Hi Splunk Users, I created an alert using a field that I created and I only want to receive alerts where that field ...
by omuelle1 Communicator in Splunk Search 10-29-2015
0 4
0
4
ProudDevil
Hello, I need your help in making a search where I can group lines before and after a matching event in Splunk, same...
by ProudDevil New Member in Splunk Search 10-29-2015
0 4
0
4
raby1996
Hello all, I have two searches (shown below) where in the first, I extract two fields Code and Serial, and in the se...
by raby1996 Path Finder in Splunk Search 10-29-2015
0 5
0
5
smudge797
We have a way of calculating the percentage of time the status is in the “OK” state by using transaction to find the ...
by smudge797 Path Finder in Splunk Search 10-29-2015
0 2
0
2
rncjq0
My search displays this, but I when I change my search to this to get a clearer picture, I miss the time stamps - thi...
by rncjq0 New Member in Splunk Search 10-29-2015
0 6
0
6
daniel333
Does anyone have a data curation search that I snag? Looking for logs and values which are not currently done in key ...
by daniel333 Builder in Splunk Search 10-29-2015
0 2
0
2
hqw
Hi all, I want to name the column name based on condition as below snapshot, for example, if Q1=A, then rename row 1...
by hqw Path Finder in Splunk Search 10-29-2015
0 2
0
2
smudge797
Using Splunk Enterpise 6.2, I'm trying to get the fields extracted using search-time props.conf / transforms.conf and...
by smudge797 Path Finder in Splunk Search 10-28-2015
0 4
0
4
stwong
Hi all, I tried to find log entries of same mail using queue id from sendmail log. However, for the same time span...
by stwong Communicator in Splunk Search 10-28-2015
1 14
1
14
digital_alchemy
I'm searching for specific GET requests for example: GET /wddyr.php?id=41576619113845C1EE http/1.1 User-Agent: Mozil...
by digital_alchemy Path Finder in Splunk Search 10-28-2015
0 1
0
1
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors