Splunk Search

Splunk Search
Community Activity
sbattista09
is there a XML setting i do not know about because bar graphs show the current month stats and when i pic line, they ...
by sbattista09 Contributor in Splunk Search 03-09-2015
0 1
0
1
vtsguerrero
I have a dynamic field that is the length of an event, it's currently generated by the eval length = (end_time - star...
by vtsguerrero Contributor in Splunk Search 03-09-2015
0 1
0
1
hagjos43
I'm using the following regex to extract KB numbers in the windowsupdate.log | rex "\((?<KB>KB\d+)\)" It works, bu...
by hagjos43 Contributor in Splunk Search 03-09-2015
0 2
0
2
ltrand
So I've been having a difficult time with doing field extractions and not getting the results I expect. In a single ...
by ltrand Contributor in Splunk Search 03-09-2015
0 3
0
3
Sig1nt
Hi, I am kind of new to regex and trying to figure out how to construct a regex to match pattern from the web access ...
by Sig1nt New Member in Splunk Search 03-09-2015
0 5
0
5
simonattardGO
Hi all, I have an intersect search which tries to intersect two search queries with a field. This is the command: (O...
by simonattardGO Path Finder in Splunk Search 03-09-2015
0 2
0
2
lattar
We have a macro set up under 'Advanced search » Search macros', it takes 3 parameters (host, neighborIP, days). To ru...
by lattar Engager in Splunk Search 03-09-2015
1 2
1
2
sunil_sharma
I want to search 2 strings in log file, like "A string" & "B String", A string should be treated as successful and B ...
by sunil_sharma New Member in Splunk Search 03-09-2015
0 5
0
5
stephen123
Hi, given the following columns c1, c2 and time c1 c2 time a 1 10.01 a 2 10.02 a 3 10.03 b 4 10.04 b 5 10.05 b...
by stephen123 Path Finder in Splunk Search 03-08-2015
0 4
0
4
sc0tt
I have a lookup file that is recreated daily and the last field is the current date. item id 2015-03-08 item1 1 ite...
by sc0tt Builder in Splunk Search 03-08-2015
0 2
0
2
trevorsplunky
From a performance perspective, am I better to increase mem_table_bytes in limits.conf to encompass my (very large) l...
by trevorsplunky Engager in Splunk Search 03-07-2015
0 1
0
1
LuiesCui
Hey guys, I'm new to splunk and I need ur help!!! A .log file is loaded by forwarder to Splunk and is setting the wr...
by LuiesCui Communicator in Splunk Search 03-06-2015
0 3
0
3
jedatt01
I want to count the number of times the value of a field called "Node_Group" has changed for a stream of events over ...
by jedatt01 Builder in Splunk Search 03-06-2015
0 5
0
5
shazenbroek
Hi, I'm struggling trying to produce a query and I hope someone here can help out. What I'm trying to do is the foll...
by shazenbroek New Member in Splunk Search 03-06-2015
0 2
0
2
psharkey
Splunk Enterprise v6.0.4 (build 207768). Search works inside the Search & Reporting app and a few other apps. By tha...
by psharkey Explorer in Splunk Search 03-06-2015
1 3
1
3
mikaelbje
I just created a new app on a Splunk search head that was initially configured with version 4.3 but has been upgraded...
by mikaelbje Motivator in Splunk Search 03-06-2015
0 7
0
7
sieutruc
Hello, When i monitored a file , at first its content is forwarded from forwarder to indexer in text format, so i ca...
by sieutruc Contributor in Splunk Search 03-06-2015
0 7
0
7
HattrickNZ
with the following search index=core host="hostname" elementType=ET1 | stats values(randomField) my output looks s...
by HattrickNZ Motivator in Splunk Search 03-05-2015
0 3
0
3
abhayneilam
Hi, I have a chart overlay based on one field, but it is coming as line graph (by default ) . I want this to be in "...
by abhayneilam Contributor in Splunk Search 03-05-2015
1 5
1
5
rodrigorsilva
Hello everyone, I'm trying to set up a manage CheckPoint OPSEC performed using the procedure as the documentation: ...
by rodrigorsilva Communicator in Splunk Search 03-05-2015
1 2
1
2
ashishpok79
All, I have tried many options mentioned in the community answers but none of them seem to work. I need to overlay ...
by ashishpok79 Explorer in Splunk Search 03-05-2015
1 3
1
3
mikegdlw
I have a logline that is extracted in multiple fields already. 1 of those fields contain multiple strings on differen...
by mikegdlw New Member in Splunk Search 03-05-2015
0 3
0
3
Premkumarpalani
i wanna know how to display the result after specifying an if condition. the sample search is like : index=xyz | ord...
by Premkumarpalani New Member in Splunk Search 03-04-2015
0 1
0
1
newbiesplunk
Hi, I wish to do a comparison of the field in the event with the lookup to determine the occurrence of the field in ...
by newbiesplunk Path Finder in Splunk Search 03-04-2015
0 7
0
7
milande
Hi, I am trying to display some test results and by using following search string I am getting what I want: … | ch...
by milande Path Finder in Splunk Search 03-04-2015
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...