Splunk Search

Splunk Search
Community Activity
pkeller
One of my users is having an issue with timechart ... (host=aaa6* OR host=bbb24*) "[string to filter search]" (E=005...
by pkeller Contributor in Splunk Search 04-27-2015
1 6
1
6
PrinceOfEval
The app seems to extract the CLM hostname as the host field. I think it would be better to extract the firewall ip o...
by PrinceOfEval Path Finder in Splunk Search 04-27-2015
0 4
0
4
Gchouane
Hello, I would like create a search based on variables. My current search: | stats count | eval search="index=c...
by Gchouane Engager in Splunk Search 04-27-2015
0 2
0
2
jebabin
Hello, I have the following event entries: NAME=A;VAL=15; NAME=A;VAL=5; NAME=B;VAL=15; NAME=C;VAL=15; NAME=C;VAL=15...
by jebabin Engager in Splunk Search 04-27-2015
0 6
0
6
jitendrasingh12
Hi experts I have one search where I am extracting username from a Windows event and using a static lookup table to ...
by jitendrasingh12 Explorer in Splunk Search 04-27-2015
0 2
0
2
ramavadde
Basic search source="outdb.json" sym=TSCO.L returns the below records: Time Event 01/08/2014 00:00:00.000 { ...
by ramavadde New Member in Splunk Search 04-27-2015
0 8
0
8
seanel
So I need to get the latest sales stats by country over many different timescales (like right now, so far today, last...
by seanel Path Finder in Splunk Search 04-26-2015
0 3
0
3
David
I have a custom search command that goes and hits the splunkd API. This works great in my dev environment where I can...
by David Splunk Employee Splunk Employee in Splunk Search 04-26-2015
1 4
1
4
adi2ky
We have splunk spit out log statements like latency=1,840 . Splunk identifies latency = 1 latency=524 . Splunk identi...
by adi2ky New Member in Splunk Search 04-26-2015
0 1
0
1
sabithanitg
rex command to extract fields from Message=Document 345, Microsoft Word Text owned by first.last on abc1234 was some ...
by sabithanitg New Member in Splunk Search 04-25-2015
0 6
0
6
gesman
I run transaction command in the following manner: ... | transaction tlsid maxpause=15m maxevents=-1 keepevicted=1 mv...
by gesman Communicator in Splunk Search 04-25-2015
1 2
1
2
joydeep741
index=dotcom source=*system* *exception* earliest = -7d NOT [search index=dotcom source=*system* *exception* earliest...
by joydeep741 Path Finder in Splunk Search 04-25-2015
0 10
0
10
chustar
I'm currently building a report using Pivot tables. I'm trying to get my data model to look like this: GroupName ...
by chustar Path Finder in Splunk Search 04-24-2015
0 1
0
1
CatherineLiu007
I'm trying to calculate duration of stepAStart to stepAEnd and display them as columns with sequence number (eg Step...
by CatherineLiu007 Explorer in Splunk Search 04-24-2015
0 3
0
3
dang
I'm looking to build some reports around error counts in our system. I've got a splunk search which returns an error...
by dang Path Finder in Splunk Search 04-24-2015
0 6
0
6
gmelasecca
I have a custom file which we don't have problems searching certain "strings" within, but what I cannot figure out is...
by gmelasecca Engager in Splunk Search 04-24-2015
0 4
0
4
akhanVG
I have a search I'm running which now works fine index="ecom" eventName=pageLoad | regex referrer="^http://www.examp...
by akhanVG Path Finder in Splunk Search 04-24-2015
0 5
0
5
Bliide
I am trying to get regex working for a field extraction on some SSRS logs I have indexed in our deployment. My goal ...
by Bliide Path Finder in Splunk Search 04-24-2015
0 2
0
2
Sakthi
Below is the Message I get from Search Results: 2015-04-23T15:39:28.3177658-04:00 0049 (Handler #32, Sync/TEST1.xml)...
by Sakthi New Member in Splunk Search 04-24-2015
0 3
0
3
akhanVG
Not sure how best to word the question but below is what I am trying to do - feel free to edit the question header. ...
by akhanVG Path Finder in Splunk Search 04-24-2015
0 4
0
4
Smith_Splunk
Hi All, I have a lookup file which contains 2 columns such as "hour (HH:MM)" and "job" hour job ----------...
by Smith_Splunk Explorer in Splunk Search 04-24-2015
0 4
0
4
Thomas_Aneiro
I am trying to pull in Windows DNS logs, but drop all internal requests. I have been able to get the logs in, and hav...
by Thomas_Aneiro Explorer in Splunk Search 04-24-2015
0 7
0
7
natefly5
earliest=-30d@d latest=@m sourcetype=Apps (sub_source!="'A'" AND sub_source!="'B'") AND (((Hosted="TEST") A...
by natefly5 Explorer in Splunk Search 04-24-2015
0 3
0
3
Laya123
Hi , How to get number of concurrent sessions per minute. My transaction started with beginning session and ends wit...
by Laya123 Communicator in Splunk Search 04-24-2015
0 2
0
2
lassel
All my log files are in foldes named: c:\blah\something\myapp_test\logs\somelogfile.log => app=myapp => env=tes...
by lassel Communicator in Splunk Search 04-24-2015
0 14
0
14
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...