Splunk Search

Splunk Search
Community Activity
brent_weaver
Hello all! I am a Splunk "newb" when it comes to parsing out files for ingestion. Here is my situation. I have a CE...
by brent_weaver Builder in Splunk Search 09-09-2015
0 5
0
5
pinVie
Hi all, I have a search that returns a table with only one line and four int values. What I'd like to do, is to cre...
by pinVie Path Finder in Splunk Search 09-09-2015
0 1
0
1
dkoops
I want to use R to train a machine learning model, export it using saveRDS(), and then importing it again within Splu...
by dkoops Path Finder in Splunk Search 09-09-2015
1 2
1
2
matt_cunningham
If I can see a pattern forming that will help me track users in my environment, how can I set up a search to serve t...
by matt_cunningham New Member in Splunk Search 09-09-2015
0 1
0
1
jameskerivan
Hi, This is kind of a silly question, but currently my application is logging the session id as two separate fields,...
by jameskerivan Explorer in Splunk Search 09-08-2015
0 2
0
2
matt_cunningham
An group of IP Addresses, continue to hit a set of 5 uri stems. If they change their IP Address, I would still like t...
by matt_cunningham New Member in Splunk Search 09-08-2015
0 4
0
4
akawacz
Hi, I would like to use something different instead of join index=test STATUS=Closed | stats dc(ID) as TOTAL by PE...
by akawacz Path Finder in Splunk Search 09-08-2015
0 6
0
6
rubeniturrieta
Hi to everyone I have a "Distributed Environment", with two indexers, and two search heads. In the Master Node Index...
by rubeniturrieta Communicator in Splunk Search 09-08-2015
0 7
0
7
Michael_Schyma1
Hey fellow Splunker's. I am trying to figure out what i am doing wrong in the transforms.conf to create the proper fi...
by Michael_Schyma1 Contributor in Splunk Search 09-08-2015
0 11
0
11
wpreston
I report on a count of events by week number, it displays like this: Week Number Count ----------- -...
by wpreston Motivator in Splunk Search 09-08-2015
3 7
3
7
idab
Hello everyone, Need your help. I have this dashboard to display some counter information for each host over a certa...
by idab Path Finder in Splunk Search 09-08-2015
0 1
0
1
splunk0
Hi, Best way for me to explain is by example. example search: host=*guac* sourcetype="syslog" | rex field=_raw "gu...
by splunk0 Path Finder in Splunk Search 09-08-2015
0 2
0
2
sfatnass
Hi, I want to add icons that replace the cell.value on my table without using range map. How can I do that? thx
by sfatnass Contributor in Splunk Search 09-08-2015
2 2
2
2
skender27
Hi, I need to extract a field from another field, no metadata fields. The existing field (let's call it existing_fi...
by skender27 Contributor in Splunk Search 09-08-2015
0 15
0
15
bfernandez
Is there any way to use a variable on the bucketing start option? It only works if you use an explicit numeric value....
by bfernandez Communicator in Splunk Search 09-08-2015
0 5
0
5
jkponnuri
I tried providing a csv file location in inputs.conf, [monitor:///path/to/*.csv.gz] source = testcsv sourcetype = t...
by jkponnuri Explorer in Splunk Search 09-07-2015
0 8
0
8
varad_joshi
I need to find various information (counts, last and first event received time, etc) on indexes listed in a CSV file....
by varad_joshi Communicator in Splunk Search 09-07-2015
0 2
0
2
sajumulakkal
field1,field2,field3 1, a, b 1, b, c 1, c, d 2, r, s 2, s, k 2, k, l 2, l, m field 1 is the key based on above dat...
by sajumulakkal New Member in Splunk Search 09-07-2015
0 3
0
3
hkhat5
Sample data set user, pc, logon, logoff, durationOfLogon User11, HNA1E8I, 01-06-15 13:49:09, 01-06-15 13:49:11, 0:00...
by hkhat5 New Member in Splunk Search 09-07-2015
0 2
0
2
Masa
How can I keep only first 6k bytes of single line event. I have syslog type of data. They are single line and someti...
by Masa Splunk Employee Splunk Employee in Splunk Search 09-07-2015
0 7
0
7
arungeorge09
I have a splunk join between a synchornous event and an asynchornous event. The only join condition between these are...
by arungeorge09 Path Finder in Splunk Search 09-07-2015
0 1
0
1
Madhan45
We can use \ as an escape sequence for special characters ",",(,),[,] and so on. How to use for * character?
by Madhan45 Path Finder in Splunk Search 09-07-2015
0 3
0
3
isedrof
Hi everybody, I need your help please, i want to convert a numeric field to a date. Ex: "20150223" >> "2015-02-23" ...
by isedrof Engager in Splunk Search 09-07-2015
0 3
0
3
raindrop18
I have this string and I want the output for this result to be combined on one line and also sum the results index="...
by raindrop18 Communicator in Splunk Search 09-06-2015
0 2
0
2
HattrickNZ
I want to just look at 1 hour for yesterday, but I want it to be relative to today so no matter when I look at it in ...
by HattrickNZ Motivator in Splunk Search 09-05-2015
0 4
0
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...