Thread Info | |||||
---|---|---|---|---|---|
The data I'm sending to my Splunk Index is made of a number of KV records. A subset of a record data looks like:
t...
by
mzorzi
Splunk Employee
in
Splunk Search
07-06-2010
|
4
|
2
| |||
Hi,
In my application, i use a file to store problems: when happen and when resolve. When a problem happen, more t...
by
dianbo_1
Path Finder
in
Splunk Search
07-14-2010
|
0
|
3
| |||
Inputs.conf: The stanza [monitor:///app/fao/dittradeflow/servers/.../logs] will look at all folders and subfolders wi...
by
Josh
Path Finder
in
Splunk Search
04-21-2010
|
1
|
4
| |||
Is there a way to enforce case-sensitivity on a field by field basis?
Example:
myid="0ZP0YFS5Rl7pACDD1K002"
...
by
maverick
Splunk Employee
in
Splunk Search
06-09-2010
|
3
|
5
| |||
I have asked almost the same question here. I will try to explain my question better here
My command looks like th...
by
hmahendrakumar
Path Finder
in
Splunk Search
08-31-2010
|
3
|
3
| |||
So trying to figure out if using rex is the best way to do this.
When you search for say "blah one", in the result...
by
skippylou
Communicator
in
Splunk Search
09-04-2010
|
0
|
4
| |||
Hey,
I'm having difficulty getting my Splunk instance to extract the part of the timestamp that I want Splunk to s...
by
Ant1D
Motivator
in
Splunk Search
09-03-2010
|
1
|
5
| |||
Hi all,
We have a need to correlate IPS, application, and firewall logs based solely on their timestamps.
The r...
by
fervin
Path Finder
in
Splunk Search
09-02-2010
|
0
|
4
| |||
Hi! I'm trying to replace parts of a string, in order to make it more human-readable. Our logs contains strings like ...
by
hbazan
Path Finder
in
Splunk Search
09-03-2010
|
2
|
3
| |||
Hey,
I am trying to produce a form that does not require the use of a search button in order to execute a search a...
by
Ant1D
Motivator
in
Splunk Search
09-02-2010
|
0
|
4
| |||
I am attempting to add CSV-formatted events to my index through the REST API. I've got it working mostly correctly, b...
by
zenmoto
Path Finder
in
Splunk Search
09-02-2010
|
0
|
3
| |||
Hi all, i need to select IP address from a search query that "are not" in another search query. How can i do this? th...
by
pinzer
Path Finder
in
Splunk Search
09-01-2010
|
0
|
8
| |||
So I have an application that auto-rotates its config files every time it is changed, and uses the following structur...
by
adamw
Communicator
in
Splunk Search
09-02-2010
|
0
|
1
| |||
Is there any weird issues with using multiple searchmatch() expressions within a single eval command?
I have a tra...
by
Lowell
Super Champion
in
Splunk Search
09-02-2010
|
4
|
2
| |||
Is there anyway of emulating a nested subsearch? I know its sometimes possible to rewrite a search to factor-out a su...
by
Lowell
Super Champion
in
Splunk Search
09-02-2010
|
0
|
5
| |||
I have a small DTrace app that monitors ARP requests and replies, producing output like this:
2010 Sep 1 03:10:0...
by
pde
Path Finder
in
Splunk Search
09-01-2010
|
0
|
2
| |||
Hi everyone.
I'm trying to use the date_hour and date_minute fields (which reads perfectly the hours and minutes o...
by
vtrujillo
Explorer
in
Splunk Search
08-31-2010
|
0
|
2
| |||
Search fails to correctly return all matching events when performing outer joins. The search below illustrates the pr...
by
Jaci
Splunk Employee
in
Splunk Search
07-23-2010
|
1
|
3
| |||
Splunk understands old school BSD-style syslog events effortlessly. For RFC 5424-style events, multiple data structur...
by
hulahoop
Splunk Employee
in
Splunk Search
01-23-2010
|
0
|
3
| |||
In a chart, I need to set major unit to be one week (i.e adjacant tick marks need to be one week apart). How do I do ...
by
sriram_sathyamo
New Member
in
Splunk Search
08-31-2010
|
0
|
1
|