Thread Info | |||||
---|---|---|---|---|---|
Hi
I want to drop all Windows Security Events (4624, 4625, etc) with Logon Type:3 My first idea is to make filter...
by
kalianov
Path Finder
in
Splunk Search
02-19-2016
|
0
|
1
| |||
I have a data source that is pipe delimited, but some of the fields contain no data or even a blank space. I've creat...
by
jedatt01
Builder
in
Splunk Search
02-18-2016
|
0
|
4
| |||
At the indexer, we are trying to exclude event records from incoming windows logs that have Logon_Type=3.
Below i...
by
aportela
New Member
in
Splunk Search
09-04-2013
|
0
|
4
| |||
Hi, I wonder whether someone may be able to help me please for which may seem a really dumb question.
I'm using th...
by
IRHM73
Motivator
in
Splunk Search
02-19-2016
|
0
|
6
| |||
I have a url, by hitting which, i get some data. Is it possible in splunk to read that data and process it and displa...
by
ma_anand1984
Contributor
in
Splunk Search
12-19-2012
|
0
|
2
| |||
This is my search:
index="test" sourcetype="Cisco_Users"
| rex field=_raw "(?<Host>\w+-\w+-\w+-\w+-?\d?\.\w+\.\w+...
by
rfiscus
Path Finder
in
Splunk Search
02-18-2016
|
0
|
1
| |||
I have managed to get our linux hosts' lastlog data in our Splunk> (version 5.0.2, build 149561) easily enough, but w...
by
JJ_of_c9
Engager
in
Splunk Search
06-05-2013
|
1
|
4
| |||
Hi,
We have few appliances spread across various data centers feeding logs into Splunk. Each Data center has 2 or ...
by
att35
Builder
in
Splunk Search
02-18-2016
|
0
|
3
| |||
I have a json object (see below). I need to take the value of payload.chan (15 in this case) and using 15 select payl...
by
dbcase
Motivator
in
Splunk Search
02-16-2016
|
0
|
5
| |||
Scenario: I am extracting sender domains with the following code:
index=mail sourcetype=xemail
[search index=...
by
packet_hunter
Contributor
in
Splunk Search
02-18-2016
|
0
|
1
| |||
Hi,
I need to search for an element A present in one of the fields let's say field 1.
Some of the values presen...
by
diliptmonson
Explorer
in
Splunk Search
02-17-2016
|
0
|
2
| |||
Hi,
Can someone please advise, how we can set different colors in a dashboard for each single row?
Our data lo...
by
splunker9999
Path Finder
in
Splunk Search
02-17-2016
|
0
|
3
| |||
We have certain source types where there is only data from months ago. When putting this into a timechart, the chart ...
by
johnraftery
Communicator
in
Splunk Search
02-17-2016
|
0
|
4
| |||
I want to create a stacked bar graph showing 2 columns stacked by department: 1 column is the total time and the seco...
by
timgirgis
Explorer
in
Splunk Search
02-17-2016
|
1
|
2
| |||
My search :
index=test
| where Value>=95
| stats count(Value) as Events by Host
The result :
if ther...
by
andrei1bc
Communicator
in
Splunk Search
02-18-2016
|
0
|
4
| |||
In my search, I calculate some values, but if I reach the 10000 result limit, I get wrong results. I would like chang...
by
nikkkc
Path Finder
in
Splunk Search
02-18-2016
|
0
|
6
| |||
Hi Splunk Support,
I'm trying to create a table based on certain fields from the Output Results:
Search String...
by
dwin02
Explorer
in
Splunk Search
02-17-2016
|
0
|
13
| |||
Hi Everyone,
Our setup is a universal forwarder --> heavy forwarder --> indexer. I am looking to modify a universa...
by
nickleli
New Member
in
Splunk Search
02-17-2016
|
0
|
5
| |||
Hello,
Could someone please delineate the difference between these two earliest commands:
earliest=-2d
earli...
by
MichaelCohen829
Explorer
in
Splunk Search
04-28-2014
|
0
|
8
| |||
Want to extract only /ubi-v2/api/scoresummary from the below mentioned event in a field. Rex used:
`| rex "(?<rem...
by
athorat
Communicator
in
Splunk Search
02-17-2016
|
0
|
1
|