Splunk Search

Splunk Search
Community Activity
rsimmons
How to extract fields from a specific field instead of raw data using the conf files? Can it be done with EXTRACT-<cl...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 11-02-2015
0 2
0
2
landen99
How do I take a time field with multiple human-readable formats and get the epoch time at search-time?
by landen99 Motivator in Splunk Search 11-02-2015
0 6
0
6
mikechu
Hi Our data is stored in the following directories. Each directory contains 1 day of data. s3n://rcs-cms-event/cep/...
by mikechu New Member in Splunk Search 11-02-2015
0 3
0
3
edrivera3
Hi Is it possible to do something like this: [MONITOR:///some directory/WE\d{8}.log] for indexing the following f...
by edrivera3 Builder in Splunk Search 11-02-2015
1 3
1
3
Abilan1
Hi, Sample log file: STD QBATCH:P GRAUT 77718 R5609812_S0000001_5847829 I want to create that highlight...
by Abilan1 Path Finder in Splunk Search 11-02-2015
0 13
0
13
Laya123
Hi, I have some transactions which have taken 3 hours to complete. When I use maxspan=90m, my transaction is breakin...
by Laya123 Communicator in Splunk Search 11-02-2015
1 9
1
9
payal23
Column1 Column2 28 28 46 46-28 58 58-(28+46) 89 89-(28+46+58) Is this possible? ...
by payal23 Path Finder in Splunk Search 11-02-2015
0 2
0
2
keithyap
IS there a way I can create a new field with a cumulative count of a unique ID? For example, currently i have create...
by keithyap Path Finder in Splunk Search 11-01-2015
0 2
0
2
Bliide
I am trying to remove the header from a log file. I know that I need to put a stanza in props.conf on the forwarder ...
by Bliide Path Finder in Splunk Search 11-01-2015
0 3
0
3
jhayIV
How would I divide each value in this row by the count(CMDB SERVER) calc?
by jhayIV Engager in Splunk Search 10-31-2015
0 2
0
2
joarsvensson
I want to do an automatic lookup from a CSV file on index time, and add new fields to the event. I got this working, ...
by joarsvensson New Member in Splunk Search 10-31-2015
0 5
0
5
m_vivek
I am doing a simple search: index=pqr host=xyz* NOT TYPE="*ABCDE*" | fields X, Y | timechart limit=0 span=10m count,...
by m_vivek Path Finder in Splunk Search 10-31-2015
0 9
0
9
alaking
I am trying to audit bandwidth usage. The following search works as expected, except the URLS flood the URL field. I ...
by alaking Explorer in Splunk Search 10-31-2015
0 1
0
1
markwymer
Hi all, I'm trying to extract the filename and file ext of a windows path into to different fields. The sourcetype i...
by markwymer Path Finder in Splunk Search 10-30-2015
0 5
0
5
a212830
Hi, I need a detailed report on search concurrency, for both scheduled and interactive searches. How would I get th...
by a212830 Champion in Splunk Search 10-30-2015
0 2
0
2
mkatz
I have a search that results in an IP address as the result with the field name clientIP: host=hostname SSL=TLSv1.2 ...
by mkatz New Member in Splunk Search 10-30-2015
0 6
0
6
aashish_122001
Can we put or in 2 regex conditions? If no, is there any alternative? for example index = idx1 | regex name = ^Aa ...
by aashish_122001 Explorer in Splunk Search 10-30-2015
0 3
0
3
chlily
The abclogs index contains a field call "userid" and there is similar field "identity" in the file totalname.csv. Now...
by chlily New Member in Splunk Search 10-30-2015
0 3
0
3
gcusello
I have to identify processes not running on a list of hosts. To do this, I have a lookup table with all the processes...
by SplunkTrust SplunkTrust in Splunk Search 10-30-2015
0 1
0
1
dmccabe2
Hi, We have a large amount of data in the Apache log files, and we do not want images to be indexed. How do I match...
by dmccabe2 New Member in Splunk Search 10-30-2015
0 3
0
3
pmcfadden91
Hi, I posted this question before, but was unable to attach the picture later in the thread. I am looking to add a c...
by pmcfadden91 Path Finder in Splunk Search 10-29-2015
0 5
0
5
DDerck
I would like to know if search performance could be increased by moving buckets from warm to cold? My main index cont...
by DDerck New Member in Splunk Search 10-29-2015
0 1
0
1
reswob4
So after reviewing a number of Q&As on this site, I created the following search to track currently logged on VPN use...
by reswob4 Builder in Splunk Search 10-29-2015
0 2
0
2
HattrickNZ
How do i assign a value to a variable in a splunk search and then use that variable in the search? something like v...
by HattrickNZ Motivator in Splunk Search 10-29-2015
0 5
0
5
bharathkumarnec
Hello All, I have created a bar graph in Splunk, Is there a possibility to show count(numeric value) on top of each ...
by bharathkumarnec Contributor in Splunk Search 10-29-2015
0 1
0
1
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors