Splunk Search

Splunk Search
Community Activity
keithcoyle
Hey everyone We updated to Splunk 6.2.6 and now some of our searches don't work anymore, and I was wondering if som...
by keithcoyle New Member in Splunk Search 10-20-2015
0 6
0
6
HeinzWaescher
Hi, I would like to group the daily users by their number of active days during the last 2 weeks. My current search ...
by HeinzWaescher Motivator in Splunk Search 10-20-2015
0 10
0
10
bworrellZP
Yesterday I was asked if I can swap out time chart, so that the time is on the top, and user name is on the left. Ba...
by bworrellZP Communicator in Splunk Search 10-20-2015
0 2
0
2
hartfoml
I have this search host=MyIndeders sourcetype=cpu | multikv fields CPU pctUser | timechart span=5m avg(pctUser) AS "...
by hartfoml Motivator in Splunk Search 10-20-2015
1 10
1
10
IRHM73
Hi, I wonder whether someone could help me please. I'm extracting a time stamp in the format 2015-01-31T23:59:55.281...
by IRHM73 Motivator in Splunk Search 10-20-2015
0 2
0
2
clorne
Hello, I have the following data (this is the result of a transaction): Date Hour Paypload ev...
by clorne Communicator in Splunk Search 10-20-2015
0 9
0
9
msudhindra
Hello, I have a CURL script that generates a CSV file, and I would like to use that CSV file as a lookup for some se...
by msudhindra Path Finder in Splunk Search 10-19-2015
2 1
2
1
jamesar
Hi Splunkers, I’m having problems with slow queries when returning a fixed number of events starting from a specifie...
by jamesar Explorer in Splunk Search 10-19-2015
0 1
0
1
peetchow
I have dbdump from my vulnerability software RetinaCS and dbdump from McAfee. I want to compare the assetNames field...
by peetchow Loves-to-Learn Lots in Splunk Search 10-19-2015
0 1
0
1
tmarlette
So I have a search that I am building, though the results must be output into a table, due to not all fields being pr...
by tmarlette Motivator in Splunk Search 10-19-2015
0 6
0
6
splunknewbieste
Assume each event includes 2 fields: path and duration among other fields. Path can have values: (i) type1 = /x/y/,...
by splunknewbieste New Member in Splunk Search 10-19-2015
0 3
0
3
a212830
Hi, Is it possible to get the data of the most recent event per sourcetype when using tstats? I have a search - |ts...
by a212830 Champion in Splunk Search 10-19-2015
0 2
0
2
OMohi
What does normalized search in the job inspector do. How is it different from an actual search? Please let me know. ...
by OMohi Path Finder in Splunk Search 10-19-2015
0 1
0
1
harish_ka
After the transaction command, I got a set of events as one event. Now I want to filter the logs from this transactio...
by harish_ka Communicator in Splunk Search 10-19-2015
0 10
0
10
matt4321
Are there any issues with Splunk 6.3 and the top command? I am trying to run a query that works fine in 6.2 and belo...
by matt4321 Explorer in Splunk Search 10-19-2015
0 1
0
1
mitchabaza
I've created a summary index that counts transactions by customer, transaction type, and hour. I'd like to create we...
by mitchabaza Explorer in Splunk Search 10-19-2015
0 4
0
4
spetzd1
So, I have a very basic report I am trying to generate that takes an extracted field called MatchesFound and sums up ...
by spetzd1 Engager in Splunk Search 10-19-2015
0 2
0
2
lovenyberg
Connecting to the mobile server via a web browser works, but not from within the Splunk Mobile IOS app. We are getti...
by lovenyberg New Member in Splunk Search 10-19-2015
0 2
0
2
rjuliani
Hi everyone! I'm trying to get some useful stats on my logged data. I have 3 attributes in each log entry, HARVEST_D...
by rjuliani New Member in Splunk Search 10-19-2015
0 10
0
10
yasaracar
I need to see which questions a user answered. It is a multiple value field. Possible values: question="1" or questi...
by yasaracar Explorer in Splunk Search 10-19-2015
0 2
0
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I've put together this regex which works perfectly in Re...
by IRHM73 Motivator in Splunk Search 10-19-2015
0 3
0
3
clorne
Hello, I would like to define a MACRO that converts hexadecimal field into a binary fields because I often have to p...
by clorne Communicator in Splunk Search 10-19-2015
0 3
0
3
hemalalli
I need to insert some records to lookup table and make sure that the lookup table should not allow the duplicate inse...
by hemalalli Explorer in Splunk Search 10-18-2015
0 1
0
1
sankalpsah
I am extracting the type of node: "namenode" or "workernode". Then I get the value of another field say "idle time" f...
by sankalpsah New Member in Splunk Search 10-18-2015
0 3
0
3
muralianup
Have this problem with linebreaks in the logs from McAFee database mon tool. Tried a couple of configs on props.conf,...
by muralianup Communicator in Splunk Search 10-18-2015
0 4
0
4
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...