Splunk Search

Splunk Search
Community Activity
snehalk
Hello All, I want to have one report/search string which states how much data was indexed for particular eventcode s...
by snehalk Communicator in Splunk Search 08-12-2015
0 1
0
1
snehalk
Hello All, I have one requirement where an alert needs to be triggered after three continuous search results reach a...
by snehalk Communicator in Splunk Search 08-12-2015
0 5
0
5
ramani2383
index="logmon_logs" |top useother=f limit=10 CHKOUTErrorMSG by _time|timechart count by CHKOUTErrorMSG |inputlookup ...
by ramani2383 New Member in Splunk Search 08-12-2015
0 1
0
1
wojtek_emca
Main search lists all events from sourcetype=A, there is a field CID. The second search list all events from sourcety...
by wojtek_emca New Member in Splunk Search 08-12-2015
0 3
0
3
ohlafl
The following query... index=os host=* (source=cpu NOT cpu="all") OR source=vmstat OR source=df | stats max(cpu) as ...
by ohlafl Communicator in Splunk Search 08-12-2015
0 6
0
6
Federica_92
Hi everyone, I'm struggling with this rex expression: query | rex field=source "/var/syslog*(?<remote_source>\w+...
by Federica_92 Communicator in Splunk Search 08-12-2015
0 4
0
4
DanPederEriksen
Hi, Stats count does not count all instances of variables when I use it with transactions. Search string: index=a...
by DanPederEriksen New Member in Splunk Search 08-12-2015
0 6
0
6
josefa123
Here is my search manager: var search1 = new SearchManager({ id: "rtCPUDaySearch", earliest_...
by josefa123 Explorer in Splunk Search 08-11-2015
0 1
0
1
thechivalrous
I have this specific issue where I'm trying to calculate percentage of online time for a set of devices. I created ...
by thechivalrous New Member in Splunk Search 08-11-2015
0 4
0
4
romedome
How can I take a value from the base search an pass it to a map search like so: <base search> | map "search index=a ...
by romedome Path Finder in Splunk Search 08-11-2015
0 5
0
5
chustar
I'm currently trying to generate a report describing "what's changed" since the last report. Currently, my idea is to...
by chustar Path Finder in Splunk Search 08-11-2015
0 6
0
6
edroche3rd
Hello All I am looking to search a number of fields (31) that may have the same value then count the number of times...
by edroche3rd Explorer in Splunk Search 08-11-2015
0 14
0
14
rakeshcse2
I have some .xml files at a location say: C/test/logs How can I configure Splunk to fetch those xml files and show ...
by rakeshcse2 New Member in Splunk Search 08-11-2015
0 11
0
11
hartfoml
OK this one might be a challenge I 7 services that restart at midnight. I have a report that comes out at 7 AM that ...
by hartfoml Motivator in Splunk Search 08-11-2015
0 4
0
4
splunkman341
Hi guys, So I currently have a search which has "the five most active OOID's by folder activity". The OOID (Organiza...
by splunkman341 Communicator in Splunk Search 08-11-2015
0 5
0
5
jizzmaster
I have a csv file as a lookup, named "resources.csv." Looking at the actual file, it has about 30,000 lines. In the S...
by jizzmaster Path Finder in Splunk Search 08-11-2015
0 11
0
11
OldManEd
I am running the following search: index=_internal source=*metrics.log earliest=07/01/2015:00:00:0 latest=08/10/20...
by OldManEd Builder in Splunk Search 08-11-2015
0 2
0
2
a212830
Hi, I am testing a feed, and it appears to be working properly, but I'm getting a "Regex: missing terminating ] for ...
by a212830 Champion in Splunk Search 08-11-2015
0 1
0
1
tkmads1
I need to extract date from the log file name as my logs only have a timestamp and no date available. The date forma...
by tkmads1 Explorer in Splunk Search 08-11-2015
0 1
0
1
kmcarrol
I've read up on delete and am familiar with the implications, but I'm having trouble figuring out how to mark events ...
by kmcarrol Path Finder in Splunk Search 08-11-2015
1 9
1
9
Maxim_Kirov
I have logs from two apps to analyze. General a session of app interaction (as it is represented in logs) looks like ...
by Maxim_Kirov Engager in Splunk Search 08-11-2015
0 3
0
3
jyamie
How can I add a row into a table either manually or through a look-up table? I would like to insert the row right bel...
by jyamie Explorer in Splunk Search 08-11-2015
0 6
0
6
donaldwayne1975
Having issues getting field extraction on Cisco ASA lines to work consistently without getting invalid information. ...
by donaldwayne1975 Path Finder in Splunk Search 08-11-2015
0 5
0
5
Krishna_Sridhar
I have a dashboard with pie chart, line charts etc., I can see the values by hovering the mouse on the charts. If I e...
by Krishna_Sridhar New Member in Splunk Search 08-11-2015
0 5
0
5
skoelpin
I have an index which processes around 10 million events per day. I did a few field extractions which had lookaheads ...
by SplunkTrust SplunkTrust in Splunk Search 08-11-2015
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...