Splunk Search

Splunk Search
Community Activity
kearaspoor
I have a list of 200+ IPs that I need to search against source addresses in our firewall data. The search needs to ...
by SplunkTrust SplunkTrust in Splunk Search 08-26-2015
0 3
0
3
mrg2k8
Hello, I have a search returning some results that look like this: sourcetype="somesourcetype" [ search sourcetype=...
by mrg2k8 Explorer in Splunk Search 08-26-2015
1 2
1
2
michwii
Hi all, I'm struggling these days with regular expressions and field extractions with events that contain multiple r...
by michwii New Member in Splunk Search 08-26-2015
0 3
0
3
cdupuis123
Anyone else seen this before? I'm building a search, then telling Splunk to NOT or using field!=something and Splunk ...
by cdupuis123 Path Finder in Splunk Search 08-26-2015
0 2
0
2
marees123
Hi All, I'm using the search below for getting the avg response time that is greater than 500. index=web <data> | t...
by marees123 Path Finder in Splunk Search 08-26-2015
0 2
0
2
Splunk_Shinobi
ログの中のメッセージに含まれる日本語のカタカナのみ、漢字のみを抽出したい場合、正規表現等で抽出する方法はありますか? 形態素解析器を導入してもいいのですが、単純な単語抽出だけやりたい場合に簡単に実現する方法をさがしています。
by Splunk_Shinobi Splunk Employee Splunk Employee in Splunk Search 08-26-2015
1 1
1
1
caili
The raw data is like : FieldA | FieldB | FieldC | FieldD 14-51-P-1216;14-52-P-0258;14-52-P-0053;14-52-P-0054 | 99DF-...
by caili Path Finder in Splunk Search 08-25-2015
3 5
3
5
imanpoeiri
Hi Splunkers, I understand we can re-write _time with particular timefield with this formula eval _time=strptime(tim...
by imanpoeiri Communicator in Splunk Search 08-25-2015
1 3
1
3
kalyani_y
Is there any way to create fields and assign values to them while my script is being executed for custom search?
by kalyani_y Explorer in Splunk Search 08-25-2015
0 1
0
1
strangelaw
I need to fetch some external data from various sources. WIth curl on command line this is relatively simple to do ag...
by strangelaw Explorer in Splunk Search 08-25-2015
1 3
1
3
msackett
I have multiple fields with different values (error messages) from the same log. I am trying to get a count per field...
by msackett New Member in Splunk Search 08-25-2015
0 2
0
2
edroche3rd
good morning all So I have a table chart with a drop-down that selects a user and this works fine. When I select a u...
by edroche3rd Explorer in Splunk Search 08-25-2015
0 5
0
5
arkadyz1
I'm getting the above error message ( 'searchmanager' received some positional argument(s) after some keyword argumen...
by arkadyz1 Builder in Splunk Search 08-25-2015
0 6
0
6
mshea
Hi, I have a very simple line of trace which indicates the end of a timer that runs at the completion of an importan...
by mshea New Member in Splunk Search 08-25-2015
0 2
0
2
jravida
Hi folks, I have some new logs coming in, and I took a look at the fieldname that has a Windows filename in it, and ...
by jravida Communicator in Splunk Search 08-25-2015
0 3
0
3
splunkman341
Hi guys, I currently have a search set up that searches for the most active OOIDs( Organization ID Folder) with the ...
by splunkman341 Communicator in Splunk Search 08-25-2015
0 4
0
4
keithcoyle
We were using an old version of Splunk (ver 5) and have since updated to the ver 6.2.4 and now our failed login attem...
by keithcoyle New Member in Splunk Search 08-25-2015
0 5
0
5
nicox77
Is it possible for Splunk to manage "live" Arduinos sensors datas like : Rain Data 1.00mm; 0s; Temp reading = 23.73 ...
by nicox77 New Member in Splunk Search 08-25-2015
0 4
0
4
jackiewkc
Hi, In my inputs.conf I have a number of monitors. I would like to create a custom field called logtypevalue with va...
by jackiewkc Path Finder in Splunk Search 08-25-2015
0 9
0
9
asherman
Hi, I'm experiencing some strangeness with the following query: index=main_index | dedup _raw | sort _raw | rename ...
by asherman Path Finder in Splunk Search 08-25-2015
0 6
0
6
ErraticIncome93
For example, I want to run the following search and have splunk output IPs that do NOT show up in the results. index...
by ErraticIncome93 Explorer in Splunk Search 08-25-2015
0 6
0
6
sfatnass
Hi, I want to know if it's possible to get rare and top value on the same table search. index=_internal |top limit...
by sfatnass Contributor in Splunk Search 08-25-2015
0 3
0
3
robburns
I have a requirement to filter out events based on: the USER running the search and FIELD VALUES contained in the ev...
by robburns Engager in Splunk Search 08-25-2015
0 4
0
4
DanielFordWA
Hi, I have a number of timecharts displaying KPIs over the last 30 days. What would be the most efficient way to ad...
by DanielFordWA Contributor in Splunk Search 08-25-2015
1 1
1
1
TheMilkMan
Do you know why I get the following error message? vols{}.Instrument is a valid field but it doesn't like the {}. i...
by TheMilkMan New Member in Splunk Search 08-25-2015
0 6
0
6
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...