| Beginner here, I'm trying to do the following in one query 1) Get all unique users and the count of users 2) Using... by therockhead Path Finder in Splunk Search 03-24-2015 0 14 | 0 | 14 | ||
| I have a field, Count, which is adding up to several thousand. I don't care that it is 74,743, though. I just want to... by jizzmaster Path Finder in Splunk Search 03-24-2015 0 1 | 0 | 1 | ||
| Hello, I try to create stats to have all countries and cities that communicate with my servers. I made this search:... by danje57 Path Finder in Splunk Search 03-24-2015 1 4 | 1 | 4 | ||
| Hello, I want to exclude all the WinEventLogs for service C:\Windows\System32\svchost.exe which doesnt contain the d... by kestasm Path Finder in Splunk Search 03-24-2015 0 10 | 0 | 10 | ||
| Hi, I'm trying to determine the span parameter for timechart dynamically, but I can't find a way to get it to work. ... by Sloefke Path Finder in Splunk Search 03-24-2015 1 8 | 1 | 8 | ||
| How does splunk work with multiple sub-searches? If I want to have two sub-searches which one is evaluated first? Is ... by tb5821 Communicator in Splunk Search 03-23-2015 3 4 | 3 | 4 | ||
| I am thinking of using lookups for categorizing field values into certain categories, as below. Using lookups is prob... by HattrickNZ Motivator in Splunk Search 03-23-2015 0 13 | 0 | 13 | ||
| Hello Guys, I am new to Splunk so please bear with me. I am having an issue and couldn't find any resolution yet. I... by sohnaeo New Member in Splunk Search 03-23-2015 0 8 | 0 | 8 | ||
| Hi, To make a long story short i have some logs that are key value pairs, like so: foo="bar" dog="cat" frog="bat" Un... by ccollord Explorer in Splunk Search 03-23-2015 1 2 | 1 | 2 | ||
| I am trying to track email sending logs, using information that we adjust in the message_id while sending a message. ... by dfenko Explorer in Splunk Search 03-23-2015 0 8 | 0 | 8 | ||
| Hi. I'd like to rex a field that starts with another field value. EX: ****Data UA=Mozilla/5.0 (Linux; Android 4.0... by pedromvieira Communicator in Splunk Search 03-23-2015 1 2 | 1 | 2 | ||
| I am attempting to extract fields from a file which was created to be human readable, so it has fields aligned at cer... by tjohnson341 Explorer in Splunk Search 03-23-2015 0 4 | 0 | 4 | ||
| Any ideas around this? When I use the fields command in this search: some search | fields Activity1, Activity2... ... by bheemireddi Communicator in Splunk Search 03-23-2015 0 4 | 0 | 4 | ||
| The two queries: search sourcetype="access*" host="www*" | timechart count by host and search sourcetype="access*" ho... by phuehne Explorer in Splunk Search 03-23-2015 1 8 | 1 | 8 | ||
| Hi, after updating to 6.2.2 I tried to set up a new automatic lookup. I've created the lookup definition, but I can'... by HeinzWaescher Motivator in Splunk Search 03-23-2015 0 2 | 0 | 2 | ||
| Hi, I have a tcp data stream that has embedded hosts that I need to transform, and I'm hoping to get some regex help... by a212830 Champion in Splunk Search 03-22-2015 0 1 | 0 | 1 | ||
| Hi, I have defined a macro that returns an amount of seconds with "s" appended to it, based on a start and end time... by Sloefke Path Finder in Splunk Search 03-22-2015 0 5 | 0 | 5 | ||
| I have splunk monitoring on a network port, a remote application logs an ASCII number to that port. How do I create ... by seanh71 New Member in Splunk Search 03-22-2015 0 1 | 0 | 1 | ||
| I am collecting group membership data daily into Splunk and I need to know how to search for changes that occur over ... by jturnervbs Engager in Splunk Search 03-22-2015 1 1 | 1 | 1 | ||
| Can anyone recommend a search to audit when an eventtype definition is changed? by adylent Path Finder in Splunk Search 03-22-2015 0 3 | 0 | 3 | ||
| Displaying outside temperature with timechart. The graph show 0~100, but my entire data set is 70~90. Is there a wa... by talbot7 Path Finder in Splunk Search 03-22-2015 5 2 | 5 | 2 | ||
| Now I have a table like below. ID, Result, SerNum, Place 1, success, AAAAA, XXXXX 2, success, BBBBB, YYYYY 3, failur... by SY715 Explorer in Splunk Search 03-21-2015 2 3 | 2 | 3 | ||
| Just moved to a new 6.2.2 Search Head Cluster (SHC) from a Search Head Pool (SHP) which had mounted bundles enabled. ... by ckurtz Path Finder in Splunk Search 03-20-2015 0 1 | 0 | 1 | ||
| I have two different network sensors - Sensor A and Sensor B. Each has their own event format that I aggregate in Sp... by IngloriousSplun Communicator in Splunk Search 03-20-2015 2 10 | 2 | 10 | ||
| Hi, I have a csv file as shown below: DATE VALUE 1-Jan 2 02-Jan 3 04-Jan 5 05-Jan ... by harshal_chakran Builder in Splunk Search 03-20-2015 0 2 | 0 | 2 |