Splunk Search

Splunk Search
Community Activity
andrewjgriffin
I have message data similar to as follows, which is the count of active user processes on a host: host=hostA user1:0...
by andrewjgriffin Engager in Splunk Search 09-03-2015
0 4
0
4
ahattrell_splun
When adding an _meta entry into inputs.conf such as: [monitor:///tmp/fwdtest] sourcetype = sun_jvm _meta env::prd W...
by ahattrell_splun Splunk Employee Splunk Employee in Splunk Search 09-03-2015
0 4
0
4
zackh123
I have a saved search in splunk which has a default start time of 7 days. I have a curl command that works perfectly ...
by zackh123 Path Finder in Splunk Search 09-03-2015
0 3
0
3
RVDowning
If I run the following search for the previous month, the number of days that appears next to Sunday is 8? If I look ...
by RVDowning Contributor in Splunk Search 09-03-2015
0 3
0
3
muralianup
Is there a way I can hardcode a search to 2 drilldown values? Basically this is what I am trying to achieve: Drilldow...
by muralianup Communicator in Splunk Search 09-03-2015
0 3
0
3
mjshoaf
We have a network load balancer (NLB) that generates syslog messages when servers fail to respond to health probes fr...
by mjshoaf New Member in Splunk Search 09-03-2015
0 10
0
10
vrmandadi
2015-09-02T14:01:02.228 Name=UPS6Z444706F2 Chkd_Out=Y DomID="Upstreamaccts\\racantr" Model="ProLiant WS460c Gen8 WS B...
by vrmandadi Builder in Splunk Search 09-03-2015
0 2
0
2
ng87
So I have web logs  , weblogs contain source IP, destination IP and other info. I am trying to write a search that w...
by ng87 Path Finder in Splunk Search 09-03-2015
0 2
0
2
tondapi
Hi, How can I concatenate Start time and duration in below format. Right now I am using this, but it is only half wo...
by tondapi New Member in Splunk Search 09-03-2015
0 1
0
1
tondapi
Hi, How to convert seconds to HH:MM format. thanks
by tondapi New Member in Splunk Search 09-03-2015
0 1
0
1
marees123
Hi All, I need helping writing a search. If HTTP status for error codes is more than 5% of the overall request (exc...
by marees123 Path Finder in Splunk Search 09-03-2015
0 4
0
4
faramarz
I've broken my events up into transactions to determine whether a user purchased and subscribed, and once narrowed do...
by faramarz Path Finder in Splunk Search 09-02-2015
1 3
1
3
dstaulcu
I would like to be able to rename a field to the value associated with another specified field. Can anyone think of ...
by dstaulcu Builder in Splunk Search 09-02-2015
4 6
4
6
skoelpin
I have an alert set which will compare the errors for the current day's previous hour to yesterday's previous hour.. ...
by SplunkTrust SplunkTrust in Splunk Search 09-02-2015
1 7
1
7
idab
Hi , Is there an easier way to write a search to separate and display stats values within a 1min interval/bucket for...
by idab Path Finder in Splunk Search 09-02-2015
0 9
0
9
RVDowning
I have the following search: source="c:\\logs\\aaaa" | transaction bbbb startswith=("CCCC STARTED") endswith=("CCC...
by RVDowning Contributor in Splunk Search 09-02-2015
1 1
1
1
theouhuios
Hello I am trying to implement an inline chart whose search criteria will change based on the $click.value$ on the t...
by theouhuios Motivator in Splunk Search 09-02-2015
0 2
0
2
skoelpin
I have 2 tax calls (CalculateTax and LookupTax) and want to count their errors for the previous day's hour. I then ad...
by SplunkTrust SplunkTrust in Splunk Search 09-02-2015
0 10
0
10
sam_jacob
I'm trying to do a strptime on this time, 2015-09-01T01:03:22. This is the query I'm running, index=[redacted] sour...
by sam_jacob Path Finder in Splunk Search 09-02-2015
0 2
0
2
PierreE
Hello, My problem is that I have ironports mail logs splitted like this : Jun 8 13:51:21 my_server: Mon Jun 8 13:...
by PierreE Path Finder in Splunk Search 09-02-2015
1 8
1
8
ashokqos
Hi, I have created a table something like this. Name, Place , Business, Value Bob, NY, Retail, 1000 Alice, Boston, T...
by ashokqos Path Finder in Splunk Search 09-02-2015
0 2
0
2
idab
Hi guys, I'm trying to create a bar chart that shows the min, avg, and max for five specific servers. The chart sho...
by idab Path Finder in Splunk Search 09-02-2015
1 9
1
9
nk-1
Using Splunk v6.2.0 The default field-extraction ( sourcetype=csv ) from a CSV logfile worked fine, but it incorrect...
by nk-1 Path Finder in Splunk Search 09-02-2015
0 4
0
4
shakermaker
Hi, I am doing an analysis on malware infections in our company, more precisely per department. Working with total n...
by shakermaker Explorer in Splunk Search 09-02-2015
0 6
0
6
DanielFordWA
Hi, I have a parameter system_mem that records the memory usage of an application. I am trying to do analysis by us...
by DanielFordWA Contributor in Splunk Search 09-02-2015
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...