Splunk Search

Splunk Search
Community Activity
skender27
Hi, I am trying to capture the multiline events from a Weblogic-similar log which satisfies all three conditions bel...
by skender27 Contributor in Splunk Search 07-13-2015
0 2
0
2
vitorvmiguel
Hi folks, I need help. I'm trying to do a search that extracts one list of Unique Session ID's and then performs wit...
by vitorvmiguel Explorer in Splunk Search 07-13-2015
0 15
0
15
OMohi
Hi: I am unable to get proper result for the Average Field. Here is my search: index=entloggingnonprod_catchall_ba...
by OMohi Path Finder in Splunk Search 07-13-2015
0 3
0
3
mrmc
I'm attempting to craft an alert that notifies myself and the user that requested access that they haven't revoked th...
by mrmc Explorer in Splunk Search 07-13-2015
0 6
0
6
deepthi5
Hi Team, Again an urgent requirement. I have got a couple csv files with source name c:\\budapest.csv, c:\\singapore...
by deepthi5 Path Finder in Splunk Search 07-13-2015
0 1
0
1
etaga
I installed and configured Universal Forwarder in AIX but it does not send data to splunk server. I configured index ...
by etaga New Member in Splunk Search 07-13-2015
0 2
0
2
rsathish47
Hi all, I found blogs on IIS logs and Spunk 6. I didn't use the INDEXED_EXTRACTIONS, but why are fields still gettin...
by rsathish47 Contributor in Splunk Search 07-13-2015
0 3
0
3
HeinzWaescher
Hi, My search looks like this: base search... | timechart span=1d dc(user_id) AS daily_customers | timechart span=...
by HeinzWaescher Motivator in Splunk Search 07-13-2015
0 5
0
5
vbumgarn
Given the events: 2012-03-06 01:02:00 a=1 b=2 2012-03-06 02:03:00 a=2 b=3 and the query: * | stats count latest(a...
by vbumgarn Path Finder in Splunk Search 07-12-2015
4 9
4
9
splunker12er
How does data model acceleration help in generating a report faster? Creating a new data model from a 'root event' -...
by splunker12er Motivator in Splunk Search 07-12-2015
0 4
0
4
marcoscala
Hi All, I'm trying to parse multiline structured tabular events like this: CPU Schedule Job ...
by marcoscala Builder in Splunk Search 07-12-2015
0 5
0
5
splunker12er
Search job Inspector: This search has completed and has returned 31232 results by scanning 434213123 events in 47.20...
by splunker12er Motivator in Splunk Search 07-12-2015
0 1
0
1
clomeli
This may be a silly question, but how does one manage memory while returning data from a search? The results are bei...
by clomeli Engager in Splunk Search 07-11-2015
0 1
0
1
hartfoml
I am doing a search from two databases and comparing data from both. I am using the appenccols command to get the da...
by hartfoml Motivator in Splunk Search 07-11-2015
0 2
0
2
zd00191
tag="*" LocID="-7" SbuID="-7" | dedup tag |eval x=substr(ResponseDisplay,1,3) |eval y=substr(AvailabilityDisplay,1,3)...
by zd00191 Communicator in Splunk Search 07-11-2015
0 1
0
1
zd00191
tag="*" LocID="-7" SbuID="-7" | dedup tag |rename ResponseDisplay AS "Application Response", AvailabilityDisplay AS ...
by zd00191 Communicator in Splunk Search 07-10-2015
0 5
0
5
Raghav2384
Experts, I am tired of trying to make this work  . We have two instances, one is a distributed search with (1SH and...
by Raghav2384 Motivator in Splunk Search 07-10-2015
1 6
1
6
kholleran
Hello, Disk space on a series of servers is monitored every 10 minutes. What I want to do is run a search that says...
by kholleran Communicator in Splunk Search 07-10-2015
0 4
0
4
purva13
I am new to Splunk and trying to know more about it. I have a dashboard where I am taking inputs from user in the for...
by purva13 Explorer in Splunk Search 07-10-2015
0 4
0
4
heilman
Hello, I am attempting to run a search that will only include data occurring before 6 AM or after 6 PM, then group t...
by heilman New Member in Splunk Search 07-10-2015
0 1
0
1
mikesangray
I was looking at the Data Summary information on the Search page and noticed that there doesn't seem to be a way to e...
by mikesangray Path Finder in Splunk Search 07-10-2015
0 3
0
3
Dallastek
sourcetype=mysource Name=web_access `myfilter` | stats count(Source_Host) as temp by Source_Host, Dest_Host | sort -t...
by Dallastek Explorer in Splunk Search 07-10-2015
0 6
0
6
lys1030
My stats contain an entry called "index". How to get the head K of each index type? For example I want the top 10 in ...
by lys1030 Explorer in Splunk Search 07-10-2015
0 2
0
2
xvxt006
Hi i have this query - sourcetype=access_combined_cookie uri="xxxxx" jsession!=- | bucket _time span=5m | stats c...
by xvxt006 Contributor in Splunk Search 07-10-2015
0 7
0
7
stephenlclarke
I have two queries that I want to merge into one. First query: <pre> sourcetype="sourceType1" rex "Application=...
by stephenlclarke New Member in Splunk Search 07-10-2015
0 5
0
5
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...