Splunk Search

Splunk Search
Community Activity
Justin_Grant
I saw this in \etc\system\README\transforms.conf.example: REGEX = (?m)^(.*)SessionId=\w+(\w{4}[&"].*)$ What does t...
by Justin_Grant Contributor in Splunk Search 07-17-2015
5 4
5
4
ride76
I have been searching Splunk answers and read the documentation and not sure it is something simple I am missing. but...
by ride76 Explorer in Splunk Search 07-17-2015
0 8
0
8
splunk_zen
Hi. http://docs.splunk.com/Documentation/Hunk/latest/Hunk/Searchavirtualindex Explicitly states " The following c...
by splunk_zen Builder in Splunk Search 07-17-2015
0 1
0
1
Stevelim
For example in a field "customer", I have the following events and values: Event 1: abc Event 2 :abc pte ltd I want ...
by Stevelim Communicator in Splunk Search 07-17-2015
0 4
0
4
minkyuk
Hello, I have a question regarding timecharting multiple lines on one chart by Datacenter, but x-axis being Metric ti...
by minkyuk Explorer in Splunk Search 07-17-2015
0 6
0
6
kelambert
I have an external lookup using a python script. It is in its own app, but is shared to all apps with R/W access. The...
by kelambert Explorer in Splunk Search 07-17-2015
0 2
0
2
kmccowen
the errors messages in my logs have different formatting so I'm wondering if there is a way to combine the below two ...
by kmccowen Path Finder in Splunk Search 07-17-2015
0 1
0
1
djfang
Hi, I would like to know how to show all fields in the search even when results are all empty for some of the field...
by djfang Explorer in Splunk Search 07-17-2015
0 3
0
3
skoelpin
I'm doing a project to detect click fraud. I created several extractions to take out the IP address, Web Request from...
by SplunkTrust SplunkTrust in Splunk Search 07-17-2015
0 3
0
3
echalex
Hi, I'm getting this warning every hour, on top of the hour, when apparently quite a few scheduled searches are trig...
by echalex Builder in Splunk Search 07-17-2015
0 6
0
6
zd00191
index=ko_autosys sourcetype=autosys_applog_scheduler_events host="usatlb98" OR host="usatlb91" System="*" | transacti...
by zd00191 Communicator in Splunk Search 07-17-2015
0 10
0
10
splunk_zen
I want to have an alert being raised when any of our top sourcetypes hourly indexing rises above a given monthly aver...
by splunk_zen Builder in Splunk Search 07-17-2015
0 3
0
3
DanielFordWA
Is it possible to find the earliest time for all users over all time. Then do a distinct count of users by month usin...
by DanielFordWA Contributor in Splunk Search 07-17-2015
0 2
0
2
ewanbrown
Hi, I have a search query like the one below index=beacon BeaconType=userevent type=addonselected | join INID TE...
by ewanbrown Path Finder in Splunk Search 07-17-2015
0 7
0
7
sushmitha_mj
I created a data model "Aggregate". I added an object which is a root search object named "usage". There is a search ...
by sushmitha_mj Communicator in Splunk Search 07-17-2015
0 6
0
6
ismarslomic
I have the following log statement, which uses semicolon delimiter and where i want to extract columns as specific fi...
by ismarslomic Path Finder in Splunk Search 07-17-2015
0 13
0
13
sieutruc
Hello, When i did a search on my SQL data, there are a lot of empty-value fields, which don't contain anything, i wa...
by sieutruc Contributor in Splunk Search 07-17-2015
1 4
1
4
gonzalogasca
Splunk Version 6.2.0 Splunk Build 237341 (MacOSX Yosemite) This is the line I'm looking to extract fields using rege...
by gonzalogasca New Member in Splunk Search 07-17-2015
0 3
0
3
roguepacket
I need help with a REGEX that needs to match multiple conditions in a log event. The event looks like this: 02:02:0...
by roguepacket Engager in Splunk Search 07-17-2015
2 4
2
4
sunnyparmar
Hi, My question is divided into 2 parts - 1.) I have a log file in which there are about 20-22 columns but i want t...
by sunnyparmar Communicator in Splunk Search 07-17-2015
0 7
0
7
vinchakov_a
Why splunk adds the date and time to the beginning of a log. How to clean it? Jul 15 09:27:20 172.16.19.1 Jul 15 201...
by vinchakov_a Path Finder in Splunk Search 07-16-2015
0 5
0
5
mistergreen28
I've got a KeywordList.csv lookup table with 3 columns (URI, URI_Keyword, URI_KeywordType). URI is a pre-existing fi...
by mistergreen28 New Member in Splunk Search 07-16-2015
0 3
0
3
RVDowning
I have a file: racf_username.csv located in /opt/splunk/etc/system/lookups which looks like; racf,username A123456,A ...
by RVDowning Contributor in Splunk Search 07-16-2015
0 4
0
4
BITSIntern
Hi guys, I need to have multiple searches running that pull up a word from the same field and replace it with anothe...
by BITSIntern Path Finder in Splunk Search 07-16-2015
0 10
0
10
mgianola
Is there any way to run Splunk queries from the RStudio IDE rather than from within the search bar?
by mgianola Explorer in Splunk Search 07-16-2015
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...