| Thread Info | |||||
|---|---|---|---|---|---|
|
I am working on a search that will take a massive list of user groups and table the servers under such group. An exa...
by
herndona
Engager
in
Splunk Search
02-12-2015
|
0
|
1
| |||
|
Let's say that I do an outputlookup after a timechart command. Now I have a csv file that should be formatted for the...
by
landen99
Motivator
in
Splunk Search
02-11-2015
|
0
|
17
| |||
|
Basically I have a field "Name" and I want to keep all events with duplicate "Name"s. So exactly the opposite of dedu...
by
rlough
Path Finder
in
Splunk Search
02-12-2015
|
1
|
4
| |||
|
I have problem with saving regex for extracting class name Here is my regex (?i)\[([0-9a-zA-Z\.\s\-]*(\[[0-9]*\])?[0-...
by
broman
Explorer
in
Splunk Search
02-12-2015
|
0
|
6
| |||
|
Hi guys
I have a CSV file with following structure:
+--------+-----------+------------+
| DEV_ID | attr_name | ...
by
Muryoutaisuu
Communicator
in
Splunk Search
02-10-2015
|
0
|
3
| |||
|
Is it possible to set field name and value with rex - or some other command - on the search bar?
I have a large X...
by
Jason
Motivator
in
Splunk Search
03-06-2013
|
1
|
4
| |||
|
I have a bash script which list the Application name and its version as follows in a file which is indexed by Splunk ...
by
VikasSinha
New Member
in
Splunk Search
02-11-2015
|
0
|
2
| |||
|
Attached is some data that you should be able to use to reproduce what I am trying to achieve.
Events.csv – extrac...
by
himynamesdave
Contributor
in
Splunk Search
02-11-2015
|
0
|
2
| |||
|
Hi , I have this query : sourcetype= Filed=X [search sourcetype= Filed=X | iplocation IPAddress | stats dc(Country) ...
by
shayfa
Path Finder
in
Splunk Search
02-11-2015
|
1
|
4
| |||
|
{%searchmanager id="test" search='eventcount summarize=false index=$input_index$ | fields index | map search="|metada...
by
freeofwind
New Member
in
Splunk Search
02-11-2015
|
0
|
1
| |||
|
Hello,
I have two log sources (AD logs and approval logs) which I am performing a correlation on (via a join). Eac...
by
pjb2160
Path Finder
in
Splunk Search
02-05-2015
|
0
|
5
| |||
|
I am looking for a tool to perform text mining searches, adhoc and based on lookup criteria/table, and the ability to...
by
OMohi
Path Finder
in
Splunk Search
02-11-2015
|
0
|
2
| |||
|
I am logging something like: Foo=123|456 When I query Splunk to get me Foo, it only prints 123 and it ignores |456.
...
by
servlette
Engager
in
Splunk Search
02-11-2015
|
0
|
5
| |||
|
I'm sorry, I am not even sure how to ask this question or whether the subject line really explains what I am after.
...
by
ccsfdave
Builder
in
Splunk Search
02-11-2015
|
0
|
2
| |||
|
So my question is based on something I am trying to do, but my splunk-foo is not powerful enough to figure this out! ...
by
jewettg
Explorer
in
Splunk Search
02-04-2015
|
0
|
1
| |||
|
I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on Janu...
by
sugitime
Explorer
in
Splunk Search
02-11-2015
|
1
|
1
| |||
|
I have two sets of data that I'm trying to join. Both data sets have a field for SystemMessageId value, but in the se...
by
redc
Builder
in
Splunk Search
02-09-2015
|
0
|
7
| |||
|
Hi Guys
I am trying to automatically create a lookup table based on results from searches, part of the search will...
by
darrend
Path Finder
in
Splunk Search
11-12-2013
|
0
|
4
| |||
|
I want to disable these searches that run automatically when a user is in the search view or launcher view.
by
the_wolverine
Champion
in
Splunk Search
09-30-2014
|
3
|
2
| |||
|
Hello Everyone,
I have a file containing Account ="xxx/\xxx/\xxx/\xx" value and this needs to be concatenated with...
by
snehal8
Path Finder
in
Splunk Search
02-10-2015
|
0
|
8
| |||
|
Hello, I have a search that tables certain values from my data fields, although i wish to create a new field on all e...
by
markthompson
Builder
in
Splunk Search
02-11-2015
|
4
|
3
| |||
|
I would like to convert a earliest and latest time and concatenate in a string value, so I could have that in my Dash...
by
celsohso
Path Finder
in
Splunk Search
02-10-2015
|
1
|
5
| |||
|
Hello, I am looking for a solution to manage my splunk objects (searches, event type, macros, lookups, etc). There ar...
by
rmurthy
Engager
in
Splunk Search
08-17-2012
|
4
|
2
| |||
|
I'm creating dashboards for the error status. We currently have 3 different statuses (200,404, and 0). The '200' stat...
by
skoelpin
SplunkTrust
in
Splunk Search
02-10-2015
|
0
|
4
| |||
|
I was wondering if it was possible to write a props.conf something similar to the following:
props:
[sourcetype...
by
ltrand
Contributor
in
Splunk Search
02-04-2015
|
0
|
2
|