Splunk Search

Splunk Search
Community Activity
rshaik26
Hi I am getting this error on search Search not executed: The minimum free disk space (1000MB) reached for /opt/s...
by rshaik26 Engager in Splunk Search 08-30-2015
0 1
0
1
thor046
Hello The issue is that the search that I am using will not pull the IP address and list of IP addresses that are t...
by thor046 New Member in Splunk Search 08-29-2015
0 3
0
3
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm using the following searches: Search 1 - "EI Auth"...
by IRHM73 Motivator in Splunk Search 08-29-2015
0 9
0
9
adamblock2
We are currently forwarding Windows security event 4698 to Splunk, and would like to be able to parse/extract a numbe...
by adamblock2 Path Finder in Splunk Search 08-29-2015
0 2
0
2
arkonner
Hi, I have three different indexes with a common field. I know how to use of the join command with two indexes with ...
by arkonner Path Finder in Splunk Search 08-28-2015
0 2
0
2
alanxu
This is a table I created using the timechart command. Now, I am trying to make a line graph with this information wi...
by alanxu Communicator in Splunk Search 08-28-2015
0 31
0
31
HattrickNZ
What is the advantage of using rex in a search V saving it as an extracted field? Example of using rex in a search: ...
by HattrickNZ Motivator in Splunk Search 08-28-2015
0 3
0
3
roshannon
I have a mixed output log that contains XML and non-XML data. I am looking to extract the XML data into a field that...
by roshannon New Member in Splunk Search 08-28-2015
0 1
0
1
ctwbear
We would like to have the splunk clean command unavailable to our Splunk administrators. The other idea would be to t...
by ctwbear New Member in Splunk Search 08-28-2015
0 2
0
2
ghannemann
Sorry for the lengthy question...... Here is what I am trying to achieve: For a event, containing the following data...
by ghannemann Engager in Splunk Search 08-28-2015
0 4
0
4
mcvr
Hi All, source="/export/home/logs/access_log" | rex ".*?HTTP\/\d+\.\d+\" (?<status_code>\d+)"|chart count by status_...
by mcvr New Member in Splunk Search 08-28-2015
0 2
0
2
tkadale
I have a parent graph showing maximum swap memory for all hosts. I have a drill down graph showing maximum swap memo...
by tkadale Path Finder in Splunk Search 08-27-2015
3 2
3
2
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm trying to get to grips with 'Report Acceleration' a...
by IRHM73 Motivator in Splunk Search 08-27-2015
1 4
1
4
Murali2888
Hi All, Can you let me know how we can use a named backreference in the subsequent rex command? That is pass the val...
by Murali2888 Communicator in Splunk Search 08-27-2015
0 2
0
2
twinspop
More and more I'm getting reports of bad queries, or queries that don't match results from a separate run. In most ca...
by twinspop Influencer in Splunk Search 08-27-2015
1 4
1
4
alanxu
Hello, I am trying to create a chart where each row has a different search. I am trying to obtain the completion tim...
by alanxu Communicator in Splunk Search 08-27-2015
0 7
0
7
omuelle1
Hi guys, I am fairly new to splunk, and I am trying to get it to monitor a couple of log files on some app servers. ...
by omuelle1 Communicator in Splunk Search 08-27-2015
0 4
0
4
theouhuios
Hello What I am trying to do is to literally chart the values over time. Now the value can be anything. It can be a ...
by theouhuios Motivator in Splunk Search 08-27-2015
1 11
1
11
Runals
This is designed to be a self answering question based on our experience. We've configured indexer clustering with a...
by Runals Motivator in Splunk Search 08-27-2015
1 1
1
1
kirkbates
I am new to Splunk and am working with DTS Compliant formatted logs generated from Microsoft Network Policy Server an...
by kirkbates New Member in Splunk Search 08-27-2015
0 2
0
2
alanxu
Hello, I extracted the time with the variable TIME. I am trying to create a line graph where it shows the latest tim...
by alanxu Communicator in Splunk Search 08-27-2015
0 27
0
27
szabados
Little strange issue I got... I ingest files into an index. I want to add a yes/no field to my events, based on if th...
by szabados Communicator in Splunk Search 08-27-2015
0 3
0
3
hartfoml
I segregate my data using indexes for each group. I have a csv with a list of hosts that cross several indexes. I c...
by hartfoml Motivator in Splunk Search 08-27-2015
0 4
0
4
reswob4
So we have both Snort and Sourcefire in our environment. I'm using a simple search to create a table of the top hits...
by reswob4 Builder in Splunk Search 08-27-2015
0 8
0
8
msalaverry
Hi, I have this search: host="myhost.com" NOT source=*access_log* AND "SearchA" | timechart span=1d dc(App) as Not...
by msalaverry New Member in Splunk Search 08-27-2015
0 4
0
4
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...