Splunk Search

Splunk Search
Community Activity
dineshp
I have a scenario like this: Login logs are created when users ( both admin and normal) logs in the website with a v...
by dineshp Explorer in Splunk Search 04-12-2015
0 4
0
4
dtilly
I am using Splunk to log all data from a firewall. I get records that contain MAC addresses and timestamps among man...
by dtilly New Member in Splunk Search 04-12-2015
0 9
0
9
sc0tt
I would like to count unique users by day, week, and month. I'm not really sure what's the preferred Splunk method to...
by sc0tt Builder in Splunk Search 04-12-2015
1 3
1
3
rpattison
We are currently indexing data from several SQL Server DBs in Splunk. All of the connections are currently configured...
by rpattison Explorer in Splunk Search 04-11-2015
0 1
0
1
wang
I have a stats command that correctly formats the count field. stats count by method client | fieldformat count=tos...
by wang Path Finder in Splunk Search 04-11-2015
1 4
1
4
sfrazer
Our nginx access logs use a quoted string when dumping cookies. It ends up looking something like this: "cookie_a=va...
by sfrazer Explorer in Splunk Search 04-11-2015
0 1
0
1
xvxt006
Hi, I need to run 2 different search queries based on the drop-down value on the same panel. Is there an example to ...
by xvxt006 Contributor in Splunk Search 04-11-2015
0 2
0
2
LintuMathews
can you please advise a rex for domain\username example windows\mathews Below is sample of event I am trying to ext...
by LintuMathews Explorer in Splunk Search 04-10-2015
0 5
0
5
splunkman341
Hi guys! So I am building on some of the previous anwsers I got, but I want to get even more specific now and can't ...
by splunkman341 Communicator in Splunk Search 04-10-2015
0 8
0
8
blurblebot
Following the example described on http://www.splunk.com/base/Documentation/4.1/User/RealtimeSearch#Expected_performa...
by blurblebot Communicator in Splunk Search 04-10-2015
3 2
3
2
skoelpin
I have 4 strings which are inside these tags OrderMessage 1) "Missed Delivery cut-off, Redated to <>" 2) "Existing...
by SplunkTrust SplunkTrust in Splunk Search 04-10-2015
1 14
1
14
roryhewitt
I'm new-ish to Splunk, so forgive me if I'm not sure of the best way to do this. Basically, I'm trying to find out t...
by roryhewitt New Member in Splunk Search 04-10-2015
0 6
0
6
andra_pietraru
Right now, Splunk indexes events that looks like this: Msg1=... time=... val=... id=... @ Msg2=... time=... val=... ...
by andra_pietraru Path Finder in Splunk Search 04-10-2015
1 11
1
11
krishananth
Hello, I'm evaluating splunk to capture data for raising data alerts, raising technical alerts etc. Most of data gen...
by krishananth Explorer in Splunk Search 04-10-2015
1 3
1
3
lassel
I am trying to correlate a event with a kvstore lookup, but I don't have a common key besides the username. So I want...
by lassel Communicator in Splunk Search 04-10-2015
0 1
0
1
will4t
I have a web_log with _time, src_ip, dst_ip, dst_hostname, url, url_path, file_extension. I tried to run a search on...
by will4t Explorer in Splunk Search 04-10-2015
0 2
0
2
vtsguerrero
Hello guys! I needed to use a single panel to show three status, green, yellow and red. But the problem is, a row wi...
by vtsguerrero Contributor in Splunk Search 04-10-2015
0 1
0
1
Norling80
Hi Guys. We have a Jboss instance from which we index AccessLogs from, and we expect a fair amount of processes req...
by Norling80 Path Finder in Splunk Search 04-10-2015
1 3
1
3
DavidHourani
Hello, I have two indexes one containing a list of webpages that has been accessed (Index A) and another containing ...
by DavidHourani Super Champion in Splunk Search 04-10-2015
0 4
0
4
Barty001
What would be the syntax to search for registry key creation?
by Barty001 Engager in Splunk Search 04-10-2015
0 2
0
2
lassel
I hope this is an easy question, but I can't figure out how to get this to work. I am still in a learning process. T...
by lassel Communicator in Splunk Search 04-10-2015
0 4
0
4
melonman
Hi I am looking for a sample external lookup script or custom command that takes one field value from evens and co...
by melonman Motivator in Splunk Search 04-10-2015
0 4
0
4
samuelrey
The field extractor wizard came up with the following: (?=[^f]*(?:firewall:|f.*firewall:))^(?:[^"\n]*"){2}\s+(?P[^ ]...
by samuelrey New Member in Splunk Search 04-09-2015
0 2
0
2
otman01
Hi, I want to create a dashboard using these 2 searches: 1) the first one index='text' | count, will give a result...
by otman01 Communicator in Splunk Search 04-09-2015
1 9
1
9
skoelpin
I currently have a 4 different phrases which are between the fixed words "a:OrderMessage and a/:OrderMessage" . I hav...
by SplunkTrust SplunkTrust in Splunk Search 04-09-2015
0 10
0
10
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...
Top Solution Authors