Splunk Search

Splunk Search
Community Activity
Muryoutaisuu
Hi guys I have a CSV file with following structure: +--------+-----------+------------+ | DEV_ID | attr_name | att...
by Muryoutaisuu Communicator in Splunk Search 02-12-2015
0 3
0
3
Jason
Is it possible to set field name and value with rex - or some other command - on the search bar? I have a large XML...
by Jason Motivator in Splunk Search 02-12-2015
1 4
1
4
VikasSinha
I have a bash script which list the Application name and its version as follows in a file which is indexed by Splunk ...
by VikasSinha New Member in Splunk Search 02-12-2015
0 2
0
2
himynamesdave
Attached is some data that you should be able to use to reproduce what I am trying to achieve. Events.csv – extract ...
by himynamesdave Contributor in Splunk Search 02-12-2015
0 2
0
2
shayfa
Hi , I have this query : sourcetype= Filed=X [search sourcetype= Filed=X | iplocation IPAddress | stats dc(Cou...
by shayfa Path Finder in Splunk Search 02-12-2015
1 4
1
4
freeofwind
{%searchmanager id="test" search='eventcount summarize=false index=$input_index$ | fields index | map search="|m...
by freeofwind New Member in Splunk Search 02-11-2015
0 1
0
1
pjb2160
Hello, I have two log sources (AD logs and approval logs) which I am performing a correlation on (via a join). Each...
by pjb2160 Path Finder in Splunk Search 02-11-2015
0 5
0
5
OMohi
I am looking for a tool to perform text mining searches, adhoc and based on lookup criteria/table, and the ability t...
by OMohi Path Finder in Splunk Search 02-11-2015
0 2
0
2
servlette
I am logging something like: Foo=123|456 When I query Splunk to get me Foo, it only prints 123 and it ignores |456. ...
by servlette Engager in Splunk Search 02-11-2015
0 5
0
5
ccsfdave
I'm sorry, I am not even sure how to ask this question or whether the subject line really explains what I am after. ...
by ccsfdave Builder in Splunk Search 02-11-2015
0 2
0
2
jewettg
So my question is based on something I am trying to do, but my splunk-foo is not powerful enough to figure this out! ...
by jewettg Explorer in Splunk Search 02-11-2015
0 1
0
1
sugitime
I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on Janu...
by sugitime Explorer in Splunk Search 02-11-2015
1 1
1
1
redc
I have two sets of data that I'm trying to join. Both data sets have a field for SystemMessageId value, but in the s...
by redc Builder in Splunk Search 02-11-2015
0 7
0
7
darrend
Hi Guys I am trying to automatically create a lookup table based on results from searches, part of the search will b...
by darrend Path Finder in Splunk Search 02-11-2015
0 4
0
4
the_wolverine
I want to disable these searches that run automatically when a user is in the search view or launcher view.
by the_wolverine Champion in Splunk Search 02-11-2015
3 2
3
2
snehal8
Hello Everyone, I have a file containing Account ="xxx/\xxx/\xxx/\xx" value and this needs to be concatenated with a...
by snehal8 Path Finder in Splunk Search 02-11-2015
0 8
0
8
markthompson
Hello, I have a search that tables certain values from my data fields, although i wish to create a new field on all e...
by markthompson Builder in Splunk Search 02-11-2015
4 3
4
3
celsohso
I would like to convert a earliest and latest time and concatenate in a string value, so I could have that in my Dash...
by celsohso Path Finder in Splunk Search 02-10-2015
1 5
1
5
rmurthy
Hello, I am looking for a solution to manage my splunk objects (searches, event type, macros, lookups, etc). There ar...
by rmurthy Engager in Splunk Search 02-10-2015
4 2
4
2
skoelpin
I'm creating dashboards for the error status. We currently have 3 different statuses (200,404, and 0). The '200' stat...
by SplunkTrust SplunkTrust in Splunk Search 02-10-2015
0 4
0
4
ltrand
I was wondering if it was possible to write a props.conf something similar to the following: props: [sourcetype = m...
by ltrand Contributor in Splunk Search 02-10-2015
0 2
0
2
jwalzerpitt
Jesse, Wondering if I could throw another question at you... I have the following query: source="mysource" Immediat...
by jwalzerpitt Influencer in Splunk Search 02-10-2015
0 2
0
2
satya2p
I see a variety of letters being used like w,n,d,s etc. pls help me to understand what characters are available to us...
by satya2p Path Finder in Splunk Search 02-10-2015
0 5
0
5
rogerbinny
Hi I have field named as "extract_datetime" and it has the following values; 2015-02-08 02:15:24 2015-02-08 02:18:3...
by rogerbinny Explorer in Splunk Search 02-10-2015
0 10
0
10
lbogle
Hello Splunkers, Question: I have a lookup working properly on a .csv file but I appear to have correctly assumed tha...
by lbogle Contributor in Splunk Search 02-10-2015
0 5
0
5
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...
Top Solution Authors