| Thread Info | |||||
|---|---|---|---|---|---|
| 
        I am working on a search that will take a massive list of user groups and table the servers under such group.  An exa...
        
         
           by 
           
                
                    
                        herndona
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               02-12-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Let's say that I do an outputlookup after a timechart command. Now I have a csv file that should be formatted for the...
        
         
           by 
           
                
                    
                        landen99
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  17
	 | |||
| 
        Basically I have a field "Name" and I want to keep all events with duplicate "Name"s. So exactly the opposite of dedu...
        
         
           by 
           
                
                    
                        rlough
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-12-2015
             
           
         
        | 
		
		1
   | 
	  
	  4
	 | |||
| 
        I have problem with saving regex for extracting class name Here is my regex (?i)\[([0-9a-zA-Z\.\s\-]*(\[[0-9]*\])?[0-...
        
         
           by 
           
                
                    
                        broman
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               02-12-2015
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi guys 
  I have a CSV file with following structure: 
  +--------+-----------+------------+
| DEV_ID | attr_name | ...
        
         
           by 
           
                
                    
                        Muryoutaisuu
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               02-10-2015
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Is it possible to set field name and value with rex - or some other command - on the search bar?  
  I have a large X...
        
         
           by 
           
                
                    
                        Jason
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-06-2013
             
           
         
        | 
		
		1
   | 
	  
	  4
	 | |||
| 
        I have a bash script which list the Application name and its version as follows in a file which is indexed by Splunk ...
        
         
           by 
           
                
                    
                        VikasSinha
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Attached is some data that you should be able to use to reproduce what I am trying to achieve. 
  Events.csv – extrac...
        
         
           by 
           
                
                    
                        himynamesdave
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi , I have this query :  sourcetype= Filed=X [search sourcetype= Filed=X | iplocation IPAddress | stats dc(Country) ...
        
         
           by 
           
                
                    
                        shayfa
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		1
   | 
	  
	  4
	 | |||
| 
        {%searchmanager id="test" search='eventcount summarize=false index=$input_index$ | fields index | map search="|metada...
        
         
           by 
           
                
                    
                        freeofwind
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello, 
  I have two log sources (AD logs and approval logs) which I am performing a correlation on (via a join). Eac...
        
         
           by 
           
                
                    
                        pjb2160
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-05-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I am looking for a tool to perform text mining searches, adhoc and based on lookup criteria/table, and the ability to...
        
         
           by 
           
                
                    
                        OMohi
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am logging something like: Foo=123|456 When I query Splunk to get me Foo, it only prints 123 and it ignores |456. 
...
        
         
           by 
           
                
                    
                        servlette
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I'm sorry, I am not even sure how to ask this question or whether the subject line really explains what I am after. 
...
        
         
           by 
           
                
                    
                        ccsfdave
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        So my question is based on something I am trying to do, but my splunk-foo is not powerful enough to figure this out! ...
        
         
           by 
           
                
                    
                        jewettg
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               02-04-2015
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on Janu...
        
         
           by 
           
                
                    
                        sugitime
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I have two sets of data that I'm trying to join. Both data sets have a field for SystemMessageId value, but in the se...
        
         
           by 
           
                
                    
                        redc
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               02-09-2015
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        Hi Guys 
  I am trying to automatically create a lookup table based on results from searches, part of the search will...
        
         
           by 
           
                
                    
                        darrend
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-12-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I want to disable these searches that run automatically when a user is in the search view or launcher view.
        
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Splunk Search
           
           
              
               09-30-2014
             
           
         
        | 
		
		3
   | 
	  
	  2
	 | |||
| 
        Hello Everyone, 
  I have a file containing Account ="xxx/\xxx/\xxx/\xx" value and this needs to be concatenated with...
        
         
           by 
           
                
                    
                        snehal8
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-10-2015
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        Hello, I have a search that tables certain values from my data fields, although i wish to create a new field on all e...
        
         
           by 
           
                
                    
                        markthompson
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               02-11-2015
             
           
         
        | 
		
		4
   | 
	  
	  3
	 | |||
| 
        I would like to convert a earliest and latest time and concatenate in a string value, so I could have that in my Dash...
        
         
           by 
           
                
                    
                        celsohso
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-10-2015
             
           
         
        | 
		
		1
   | 
	  
	  5
	 | |||
| 
        Hello, I am looking for a solution to manage my splunk objects (searches, event type, macros, lookups, etc). There ar...
        
         
           by 
           
                
                    
                        rmurthy
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               08-17-2012
             
           
         
        | 
		
		4
   | 
	  
	  2
	 | |||
| 
        I'm creating dashboards for the error status. We currently have 3 different statuses (200,404, and 0). The '200' stat...
        
         
           by 
           
                
                    
                        skoelpin
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Splunk Search
           
           
              
               02-10-2015
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I was wondering if it was possible to write a props.conf something similar to the following: 
  props: 
  [sourcetype...
        
         
           by 
           
                
                    
                        ltrand
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               02-04-2015
             
           
         
        | 
		
		0
   | 
	  
	  2
	 |