Thread Info | |||||
---|---|---|---|---|---|
The following query...
index=os host=* (source=cpu NOT cpu="all") OR source=vmstat OR source=df | stats max(cpu) a...
by
ohlafl
Communicator
in
Splunk Search
08-11-2015
|
0
|
6
| |||
Hi everyone,
I'm struggling with this rex expression:
query | rex field=source "/var/syslog*(?<remote_source...
by
Federica_92
Communicator
in
Splunk Search
08-11-2015
|
0
|
4
| |||
Hi,
Stats count does not count all instances of variables when I use it with transactions.
Search string:
i...
by
DanPederEriksen
New Member
in
Splunk Search
08-11-2015
|
0
|
6
| |||
Here is my search manager:
var search1 = new SearchManager({
id: "rtCPUDaySearch",
earlies...
by
josefa123
Explorer
in
Splunk Search
08-11-2015
|
0
|
1
| |||
I have this specific issue where I'm trying to calculate percentage of online time for a set of devices.
I create...
by
thechivalrous
New Member
in
Splunk Search
08-10-2015
|
0
|
4
| |||
How can I take a value from the base search an pass it to a map search like so:
<base search> | map "search index=...
by
romedome
Path Finder
in
Splunk Search
08-11-2015
|
0
|
5
| |||
I'm currently trying to generate a report describing "what's changed" since the last report. Currently, my idea is to...
by
chustar
Path Finder
in
Splunk Search
08-11-2015
|
0
|
6
| |||
Hello All
I am looking to search a number of fields (31) that may have the same value then count the number of tim...
by
edroche3rd
Explorer
in
Splunk Search
08-03-2015
|
0
|
14
| |||
I have some .xml files at a location say: C/test/logs
How can I configure Splunk to fetch those xml files and show...
by
rakeshcse2
New Member
in
Splunk Search
08-10-2015
|
0
|
11
| |||
OK this one might be a challenge
I 7 services that restart at midnight. I have a report that comes out at 7 AM tha...
by
hartfoml
Motivator
in
Splunk Search
11-16-2012
|
0
|
4
| |||
Hi guys,
So I currently have a search which has "the five most active OOID's by folder activity". The OOID (Organi...
by
splunkman341
Communicator
in
Splunk Search
08-11-2015
|
0
|
5
| |||
I have a csv file as a lookup, named "resources.csv." Looking at the actual file, it has about 30,000 lines. In the S...
by
jizzmaster
Path Finder
in
Splunk Search
08-11-2015
|
0
|
11
| |||
I am running the following search:
index=_internal source=*metrics.log
earliest=07/01/2015:00:00:0
latest=08/10/...
by
OldManEd
Builder
in
Splunk Search
08-11-2015
|
0
|
2
| |||
Hi,
I am testing a feed, and it appears to be working properly, but I'm getting a "Regex: missing terminating ] fo...
by
a212830
Champion
in
Splunk Search
08-11-2015
|
0
|
1
| |||
I need to extract date from the log file name as my logs only have a timestamp and no date available.
The date for...
by
tkmads1
Explorer
in
Splunk Search
08-11-2015
|
0
|
1
| |||
I've read up on delete and am familiar with the implications, but I'm having trouble figuring out how to mark events ...
by
kmcarrol
Path Finder
in
Splunk Search
08-10-2015
|
1
|
9
| |||
I have logs from two apps to analyze. General a session of app interaction (as it is represented in logs) looks like ...
by
Maxim_Kirov
Engager
in
Splunk Search
07-28-2015
|
0
|
3
| |||
How can I add a row into a table either manually or through a look-up table? I would like to insert the row right bel...
by
jyamie
Explorer
in
Splunk Search
08-10-2015
|
0
|
6
| |||
Having issues getting field extraction on Cisco ASA lines to work consistently without getting invalid information. F...
by
donaldwayne1975
Path Finder
in
Splunk Search
08-10-2015
|
0
|
5
| |||
I have a dashboard with pie chart, line charts etc., I can see the values by hovering the mouse on the charts. If I e...
by
Krishna_Sridhar
New Member
in
Splunk Search
07-28-2015
|
0
|
5
| |||
I have an index which processes around 10 million events per day. I did a few field extractions which had lookaheads ...
by
skoelpin
SplunkTrust
in
Splunk Search
08-10-2015
|
0
|
4
| |||
Hi all,
I am going to simplify my problem. I have two indexes with the following variables:
index 1: time_in us...
by
vbarna
Engager
in
Splunk Search
08-10-2015
|
0
|
4
| |||
Hello,
Since we upgraded from Splunk 5 to Splunk 6.2.4, some of our searches run 10 to 20 times slower than before...
by
knielsen
Contributor
in
Splunk Search
08-06-2015
|
0
|
6
| |||
Hello,
My data looks like:
I currently have this search:
source=myapp test123 | stats count by type
T...
by
abovebeyond
Communicator
in
Splunk Search
08-11-2015
|
0
|
4
| |||
Hi guys,
I am ingesting Windows event logs including event code 5156 which is chewing up a lot of license. I have ...
by
pdjhh
Communicator
in
Splunk Search
08-10-2015
|
0
|
13
|