Splunk Search

Splunk Search
Community Activity
harshavmb
I have a file which gets created daily. My requirement is to get the size of the file using a splunk search. The file...
by harshavmb New Member in Splunk Search 04-08-2015
0 2
0
2
Ledion_Bitincka
I'm running into an issue with Hunk searches that spawn a MapReduce job in my EMR cluster. The MR job seems to be kil...
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 3
0
3
jgcsco
I have this search: [search] | stats count by Status Errors | eventstats sum(count) as StatusCount by Status| events...
by jgcsco Path Finder in Splunk Search 04-08-2015
1 4
1
4
jgcsco
I have following event: <...>Status1, StateA<....> <...>Status2,<...> <...>Status3<...> <...>Status1, StateB<...> <....
by jgcsco Path Finder in Splunk Search 04-08-2015
3 3
3
3
AWED
With splunk 4.1.6 : a user has defined a custom field extraction in the "search" app. As as admin, I have changed the...
by AWED Engager in Splunk Search 04-08-2015
1 5
1
5
ndoshi
I have the following types of events in FIX format. This is what they look like in vi or emacs: M|219620|0|i|I|20100...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 04-08-2015
0 10
0
10
mrfredman
Hi, I'm using postgres regex to pull two sets of values into my search. I've got all the data I want, but it seems t...
by mrfredman Path Finder in Splunk Search 04-08-2015
0 2
0
2
edrivera3
Hi I extracted a multivalue field called error_number which contains all errors in each event. I would like to make ...
by edrivera3 Builder in Splunk Search 04-08-2015
1 5
1
5
metersk
I am trying to get counts of all certain events that happened before a user purchased on our site and so far, I am wo...
by metersk Path Finder in Splunk Search 04-08-2015
1 4
1
4
alexl1
hi, how do I re-run a search that I typed in previously? Thanks,
by alexl1 Path Finder in Splunk Search 04-08-2015
0 5
0
5
jeffreyjewitt
Hi: This is an odd question, but it pops up every so often. Is it possible to have a dashboard that is populated with...
by jeffreyjewitt Explorer in Splunk Search 04-07-2015
0 3
0
3
venkatv1520
I have a csv file indexed containing the fields "Timestamp" and "Event1" Sample data is as follows Timestamp Eve...
by venkatv1520 Engager in Splunk Search 04-07-2015
0 3
0
3
HattrickNZ
I have the following search And I add this column row to show the row numbers but it positions in as the right most c...
by HattrickNZ Motivator in Splunk Search 04-07-2015
0 5
0
5
HattrickNZ
I have the following search | inputlookup msckpr_test_trunkgroups95_lookup_define | stats values(TG_NAME) as TG_NAM...
by HattrickNZ Motivator in Splunk Search 04-07-2015
0 3
0
3
mohitab
This could be a premature question and a bit hypothetical too. I have a visual analytics based webapp based on Splu...
by mohitab Path Finder in Splunk Search 04-07-2015
0 2
0
2
wang
Let say I have a chart that reports the count of what user has purchased what item. I can create a nice table using ...
by wang Path Finder in Splunk Search 04-07-2015
0 2
0
2
hcheang
Hello I've been using metadata command for many reports and alarms for new host added, eps and reporting status and ...
by hcheang Path Finder in Splunk Search 04-07-2015
0 1
0
1
hagjos43
Is there any suggestions on how to improve search time on this particular search? This search literally takes 12-15 h...
by hagjos43 Contributor in Splunk Search 04-07-2015
1 9
1
9
jodros
I have the Mobile Access Server up and running. I am able to log in and view dashboards and reports. I have a basic...
by jodros Builder in Splunk Search 04-07-2015
0 3
0
3
jamesvz84
Given the following log format, is it possible to store the consecutive GROUPED/GROUPED_DET lines into one event whil...
by jamesvz84 Communicator in Splunk Search 04-07-2015
0 1
0
1
d29priyanka
I have a splunk search which has multikv and regex. index=os OR index=advantage sourcetype="*nmon*" |multikv|rex fie...
by d29priyanka New Member in Splunk Search 04-07-2015
0 9
0
9
edrivera3
Hi After a search I extracted the field "test_number". Now I would like to use those extracted field values to make ...
by edrivera3 Builder in Splunk Search 04-07-2015
0 1
0
1
darthsplunk
Hi, I'm having problems using mvfilter to filter out NULL strings. This is my search: index=nmap* | eval state=mvf...
by darthsplunk Explorer in Splunk Search 04-07-2015
2 7
2
7
moiezuddin
How to get the details of field app=sencer, when it not shown in the values for the app field?
by moiezuddin Explorer in Splunk Search 04-07-2015
0 5
0
5
mzorzi
The events collected from the MVM have multiline fields, I would like to extract vendor_description,vendor_observatio...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 04-07-2015
0 4
0
4
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors