Splunk Search

Splunk Search
Community Activity
rpattison
We are currently indexing data from several SQL Server DBs in Splunk. All of the connections are currently configured...
by rpattison Explorer in Splunk Search 04-11-2015
0 1
0
1
wang
I have a stats command that correctly formats the count field. stats count by method client | fieldformat count=tos...
by wang Path Finder in Splunk Search 04-11-2015
1 4
1
4
sfrazer
Our nginx access logs use a quoted string when dumping cookies. It ends up looking something like this: "cookie_a=va...
by sfrazer Explorer in Splunk Search 04-11-2015
0 1
0
1
xvxt006
Hi, I need to run 2 different search queries based on the drop-down value on the same panel. Is there an example to ...
by xvxt006 Contributor in Splunk Search 04-11-2015
0 2
0
2
LintuMathews
can you please advise a rex for domain\username example windows\mathews Below is sample of event I am trying to ext...
by LintuMathews Explorer in Splunk Search 04-10-2015
0 5
0
5
splunkman341
Hi guys! So I am building on some of the previous anwsers I got, but I want to get even more specific now and can't ...
by splunkman341 Communicator in Splunk Search 04-10-2015
0 8
0
8
blurblebot
Following the example described on http://www.splunk.com/base/Documentation/4.1/User/RealtimeSearch#Expected_performa...
by blurblebot Communicator in Splunk Search 04-10-2015
3 2
3
2
skoelpin
I have 4 strings which are inside these tags OrderMessage 1) "Missed Delivery cut-off, Redated to <>" 2) "Existing...
by SplunkTrust SplunkTrust in Splunk Search 04-10-2015
1 14
1
14
roryhewitt
I'm new-ish to Splunk, so forgive me if I'm not sure of the best way to do this. Basically, I'm trying to find out t...
by roryhewitt New Member in Splunk Search 04-10-2015
0 6
0
6
andra_pietraru
Right now, Splunk indexes events that looks like this: Msg1=... time=... val=... id=... @ Msg2=... time=... val=... ...
by andra_pietraru Path Finder in Splunk Search 04-10-2015
1 11
1
11
krishananth
Hello, I'm evaluating splunk to capture data for raising data alerts, raising technical alerts etc. Most of data gen...
by krishananth Explorer in Splunk Search 04-10-2015
1 3
1
3
lassel
I am trying to correlate a event with a kvstore lookup, but I don't have a common key besides the username. So I want...
by lassel Communicator in Splunk Search 04-10-2015
0 1
0
1
will4t
I have a web_log with _time, src_ip, dst_ip, dst_hostname, url, url_path, file_extension. I tried to run a search on...
by will4t Explorer in Splunk Search 04-10-2015
0 2
0
2
vtsguerrero
Hello guys! I needed to use a single panel to show three status, green, yellow and red. But the problem is, a row wi...
by vtsguerrero Contributor in Splunk Search 04-10-2015
0 1
0
1
Norling80
Hi Guys. We have a Jboss instance from which we index AccessLogs from, and we expect a fair amount of processes req...
by Norling80 Path Finder in Splunk Search 04-10-2015
1 3
1
3
DavidHourani
Hello, I have two indexes one containing a list of webpages that has been accessed (Index A) and another containing ...
by DavidHourani Super Champion in Splunk Search 04-10-2015
0 4
0
4
Barty001
What would be the syntax to search for registry key creation?
by Barty001 Engager in Splunk Search 04-10-2015
0 2
0
2
lassel
I hope this is an easy question, but I can't figure out how to get this to work. I am still in a learning process. T...
by lassel Communicator in Splunk Search 04-10-2015
0 4
0
4
melonman
Hi I am looking for a sample external lookup script or custom command that takes one field value from evens and co...
by melonman Motivator in Splunk Search 04-10-2015
0 4
0
4
samuelrey
The field extractor wizard came up with the following: (?=[^f]*(?:firewall:|f.*firewall:))^(?:[^"\n]*"){2}\s+(?P[^ ]...
by samuelrey New Member in Splunk Search 04-09-2015
0 2
0
2
otman01
Hi, I want to create a dashboard using these 2 searches: 1) the first one index='text' | count, will give a result...
by otman01 Communicator in Splunk Search 04-09-2015
1 9
1
9
skoelpin
I currently have a 4 different phrases which are between the fixed words "a:OrderMessage and a/:OrderMessage" . I hav...
by SplunkTrust SplunkTrust in Splunk Search 04-09-2015
0 10
0
10
Splunk2016
I would appreciate any comments: 1) Added "Total" as one of my Selected Fields from the following search (this worke...
by Splunk2016 Path Finder in Splunk Search 04-09-2015
0 2
0
2
bshelton_soleo
I have a set of XML logs that were all consumed by Splunk at the same time. I believe I have the timestamps from the ...
by bshelton_soleo Engager in Splunk Search 04-09-2015
0 2
0
2
jizzmaster
I want to perform a CIDR match on a list of IPs and a list of subnets. In a lookup table I have a list of subnets in...
by jizzmaster Path Finder in Splunk Search 04-09-2015
0 3
0
3
Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...