Splunk Search

Splunk Search
Community Activity
borgy95
I have two type of files i am inputted into splunk. Both reside at /var/data/proxy/isolde.2015060812.log or mimi.20...
by borgy95 Path Finder in Splunk Search 07-09-2015
0 2
0
2
szaboszilard
Hi everyone, I have several oracle audit logs received via syslog-ng + splunk file inputs: Jul 8 14:44:04 192.168....
by szaboszilard Path Finder in Splunk Search 07-08-2015
0 5
0
5
kabiraj
Hi All, I am facing some problem with my below search: sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UN...
by kabiraj Path Finder in Splunk Search 07-08-2015
0 3
0
3
HattrickNZ
I have something like this in the stats view in splunk. field NE1 NE1-L NE2 NE2-1 field-alt KPI1 30251 1...
by HattrickNZ Motivator in Splunk Search 07-08-2015
0 2
0
2
sympatiko
Hi splunkers, I need to gather the success and failed attempts from my linux servers, but when I forward all my auth...
by sympatiko Communicator in Splunk Search 07-08-2015
0 2
0
2
satoru0130
インデックス作成されたwarm・coldデータのバックアップを採取したいのですが、 一時的にhotdbからwarmdbへのロールを止めることは可能でしょうか? splunk自体を停止することができない環境の為、 indexes.co...
by satoru0130 Engager in Splunk Search 07-08-2015
1 2
1
2
rameshlpatel
Hi, I have an issue with percentile functions provided by SPLUNK. Example: I am getting count by last 7 days as : ...
by rameshlpatel Communicator in Splunk Search 07-08-2015
1 1
1
1
karan1337
I wish to keep only _time and _raw fields in the export output file. I read in the documentation that | fields - _* r...
by karan1337 Path Finder in Splunk Search 07-08-2015
0 5
0
5
ebailey
I need to produce an extract to use as a data source for a third party application. The application needs the data in...
by ebailey Communicator in Splunk Search 07-08-2015
0 2
0
2
watsm10
Hi Splunkers, I've been asked to create a command centre for our business. The main requirement is to have a single ...
by watsm10 Communicator in Splunk Search 07-08-2015
0 4
0
4
zd00191
The following searches' results contain events with the field, FUNCTIONAL_AREA_NAME="Minute Maid" index=ko_autosys s...
by zd00191 Communicator in Splunk Search 07-08-2015
0 2
0
2
Neiby
We often do a search for device configuration changes on Cisco devices in a specific IP range in a certain time frame...
by Neiby Explorer in Splunk Search 07-08-2015
1 5
1
5
lstewart_splunk
What is the difference (performance? limitations in later pipes?) between these two searches where one renames a fiel...
by lstewart_splunk Splunk Employee Splunk Employee in Splunk Search 07-08-2015
5 1
5
1
minkyuk
Hello- I'll jump into the main part. Here is a snippet: Tue 2015 15:00:23 ZGD-OCU-QQQ POS-BKD-AKD COK-ZPP-AKF DIS...
by minkyuk Explorer in Splunk Search 07-08-2015
0 3
0
3
michaelgardner
We have a fairly complex search page in our web app which has many search field options. We're trying to determine w...
by michaelgardner Explorer in Splunk Search 07-08-2015
0 4
0
4
jg3
Given I have some input with a bunch of fields that are not automatically extracted and I used the Field Extractor in...
by jg3 New Member in Splunk Search 07-08-2015
0 5
0
5
ErikaE
When I run a transaction command to group events together, I lose the _time information originally associated with th...
by ErikaE Communicator in Splunk Search 07-08-2015
0 23
0
23
gesman
I have /my-app/local/limits.conf with the following content: [subsearch] maxtime = 600 [join] subsearch_maxtime = 6...
by gesman Communicator in Splunk Search 07-08-2015
0 3
0
3
jwhit
I am trying to run a query that takes the average runtime of log files and compares them to the current run time of l...
by jwhit Engager in Splunk Search 07-08-2015
0 5
0
5
Hartmannish
I'm trying to make visualizations appear. A simple column or bar chart. My search works exactly as intended (a series...
by Hartmannish Explorer in Splunk Search 07-08-2015
0 3
0
3
oliverj
Hello. I am investigating SPLUNK, and am trying to accomplish a task I was hoping would be simple: I have a "group"...
by oliverj Communicator in Splunk Search 07-08-2015
0 13
0
13
splunker12er
Is there any built-in command to fetch events before and after (for a specific time-duration) a particular keyword/ev...
by splunker12er Motivator in Splunk Search 07-08-2015
0 6
0
6
tweaktubbie
Just wondering when looking into performance improvements... After logging in to Splunk (...app/launcher/home), you s...
by tweaktubbie Communicator in Splunk Search 07-08-2015
0 1
0
1
kavyaa
Hi, I want to get top 10 src_ip . I have selected descending order for recv_bytes column . Please help me. Query as ...
by kavyaa Explorer in Splunk Search 07-08-2015
0 2
0
2
landen99
I am looking at how to see the details of the events which drive dashboard panels when the results are brought in thr...
by landen99 Motivator in Splunk Search 07-08-2015
0 10
0
10
Get Updates on the Splunk Community!

Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...

Session 2 | Beyond the Thread: Operationalizing AI with Confidence

Session 2   Beyond the Thread: Operationalizing AI with Confidence    The true power of the Cisco Data Fabric ...
Top Solution Authors