Splunk Search

Splunk Search
Community Activity
ruhjuh
Is it possible to remove an asterisk from the returned data for a table? I tried to use: rex "Data=(?<Message>[^C]...
by ruhjuh Explorer in Splunk Search 10-22-2015
0 7
0
7
jcorominas
Dear all, Data is indexed from a CSV file. I am trying to calculate the amount of seconds between a couple of times...
by jcorominas Explorer in Splunk Search 10-22-2015
0 6
0
6
ADTJedi
I am conducting the following search (account names have been hidden): sourcetype=WinEventLog:Security EventCode=474...
by ADTJedi Engager in Splunk Search 10-21-2015
0 7
0
7
adamtech1
I'm trying to query the event log and iis logs at the same time. I would like to correlate application pool crashes/...
by adamtech1 New Member in Splunk Search 10-21-2015
0 2
0
2
raby1996
Hi all I've been trying to separate the values of a stats table that looks similar to what i have below. I've used d...
by raby1996 Path Finder in Splunk Search 10-21-2015
0 2
0
2
Sampathu
Hi, When I run the searches below separately, they give me exact result, but when I tried joining them, it was not ...
by Sampathu Explorer in Splunk Search 10-21-2015
0 1
0
1
balach
How to write a regular expression for capturing elapsed time of requests, with a log in this format. .......status=[...
by balach New Member in Splunk Search 10-21-2015
0 4
0
4
mctester
Where do we actually get user ended search history from to fill the Search Assistant “My Search History”? (4.1) See ...
by mctester Communicator in Splunk Search 10-21-2015
1 2
1
2
clopes
Hi all, I'm trying to create a sum of fields inside a row, but I can't figure how to do it. This is my scenario: I ...
by clopes Engager in Splunk Search 10-21-2015
0 2
0
2
BlueSocket
Dear All, I am using the Splunk App for Windows and I am trying to get a chart out looking something like: Computer...
by BlueSocket Contributor in Splunk Search 10-21-2015
0 1
0
1
amljohnson
This is probably a very basic Splunk question, but as I move beyond basic searches, these are the kinds of use cases ...
by amljohnson Explorer in Splunk Search 10-21-2015
0 4
0
4
joxley
I have a sourcetype that represents transactions. On the sourcetype are 3 fields of importance to this question,:an ...
by joxley Path Finder in Splunk Search 10-21-2015
0 2
0
2
jsven7
Hello Data example: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; MDDRJS) I have to int...
by jsven7 Communicator in Splunk Search 10-21-2015
0 4
0
4
rroberts
I upgraded to Splunk 6.3 and it's working beautifully, however, I no longer get "matching terms" as I type in the sea...
by rroberts Splunk Employee Splunk Employee in Splunk Search 10-21-2015
0 3
0
3
Murali2888
Hi All, I have a search query like below. [search A | fields B,C] | search (D OR E) | fields F | table, B,C,F. Sea...
by Murali2888 Communicator in Splunk Search 10-21-2015
0 3
0
3
gbronner_rbc
This command does not work. index=grb_test sourcetype=QServiceManagerFormat | source="\\\\netapp4\\Quants\\ST\logs\...
by gbronner_rbc Explorer in Splunk Search 10-21-2015
0 2
0
2
jawebb
I have a field of names from two indexes and wish to find the unique values between them. I thought I should have to ...
by jawebb Explorer in Splunk Search 10-21-2015
0 6
0
6
lquinn
The data that I would like to graph consists of start events and stop events. Sessions consist of one start event and...
by lquinn Contributor in Splunk Search 10-21-2015
1 2
1
2
indianhans
I wish to extract any number between "cmdbRequest" & "- Transaction" . For Example from below string ERROR 21 C...
by indianhans Engager in Splunk Search 10-21-2015
0 2
0
2
thomas_forbes
I have successfully downloaded and installed the Sophos Add-on for Splunk. Now I am attempting to configure it and a...
by thomas_forbes Communicator in Splunk Search 10-20-2015
0 4
0
4
ruhjuh
Is it possible to get everything after a carriage return? Example Bills to pay: Car House Boat etc I tried to use...
by ruhjuh Explorer in Splunk Search 10-20-2015
2 4
2
4
woodcock
Does anybody have any creative ways to join search outputs together and avoid subsearch limits?
by Esteemed Legend in Splunk Search 10-20-2015
1 5
1
5
Mitchellsch
I have a list of privileged users from my inputlookup table and I want to know their dest ip. This is why I want to s...
by Mitchellsch Explorer in Splunk Search 10-20-2015
0 4
0
4
mflippin
I need to write a search to report on what devices are sending logs to my heavy forwarders using syslog-ng to the /va...
by mflippin New Member in Splunk Search 10-20-2015
0 1
0
1
dustinhartje
Hello fellow Splunkers! I'm trying to recreate an existing report for my firewall guy within Splunk with hopes of re...
by dustinhartje Explorer in Splunk Search 10-20-2015
2 5
2
5
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors