| Hi guys I have a CSV file with following structure: +--------+-----------+------------+ | DEV_ID | attr_name | att... by Muryoutaisuu Communicator in Splunk Search 02-12-2015 0 3 | 0 | 3 | ||
| Is it possible to set field name and value with rex - or some other command - on the search bar? I have a large XML... by Jason Motivator in Splunk Search 02-12-2015 1 4 | 1 | 4 | ||
| I have a bash script which list the Application name and its version as follows in a file which is indexed by Splunk ... by VikasSinha New Member in Splunk Search 02-12-2015 0 2 | 0 | 2 | ||
| Attached is some data that you should be able to use to reproduce what I am trying to achieve. Events.csv – extract ... by himynamesdave Contributor in Splunk Search 02-12-2015 0 2 | 0 | 2 | ||
| Hi , I have this query : sourcetype= Filed=X [search sourcetype= Filed=X | iplocation IPAddress | stats dc(Cou... by shayfa Path Finder in Splunk Search 02-12-2015 1 4 | 1 | 4 | ||
| {%searchmanager id="test" search='eventcount summarize=false index=$input_index$ | fields index | map search="|m... by freeofwind New Member in Splunk Search 02-11-2015 0 1 | 0 | 1 | ||
| Hello, I have two log sources (AD logs and approval logs) which I am performing a correlation on (via a join). Each... by pjb2160 Path Finder in Splunk Search 02-11-2015 0 5 | 0 | 5 | ||
| I am looking for a tool to perform text mining searches, adhoc and based on lookup criteria/table, and the ability t... by OMohi Path Finder in Splunk Search 02-11-2015 0 2 | 0 | 2 | ||
| I am logging something like: Foo=123|456 When I query Splunk to get me Foo, it only prints 123 and it ignores |456. ... by servlette Engager in Splunk Search 02-11-2015 0 5 | 0 | 5 | ||
| I'm sorry, I am not even sure how to ask this question or whether the subject line really explains what I am after. ... by ccsfdave Builder in Splunk Search 02-11-2015 0 2 | 0 | 2 | ||
| So my question is based on something I am trying to do, but my splunk-foo is not powerful enough to figure this out! ... by jewettg Explorer in Splunk Search 02-11-2015 0 1 | 0 | 1 | ||
| I am doing a search in Splunk over a time period (from Jan 25th to present). I expect that no data be present on Janu... by sugitime Explorer in Splunk Search 02-11-2015 1 1 | 1 | 1 | ||
| I have two sets of data that I'm trying to join. Both data sets have a field for SystemMessageId value, but in the s... by redc Builder in Splunk Search 02-11-2015 0 7 | 0 | 7 | ||
| Hi Guys I am trying to automatically create a lookup table based on results from searches, part of the search will b... by darrend Path Finder in Splunk Search 02-11-2015 0 4 | 0 | 4 | ||
| I want to disable these searches that run automatically when a user is in the search view or launcher view. by the_wolverine Champion in Splunk Search 02-11-2015 3 2 | 3 | 2 | ||
| Hello Everyone, I have a file containing Account ="xxx/\xxx/\xxx/\xx" value and this needs to be concatenated with a... by snehal8 Path Finder in Splunk Search 02-11-2015 0 8 | 0 | 8 | ||
| Hello, I have a search that tables certain values from my data fields, although i wish to create a new field on all e... by markthompson Builder in Splunk Search 02-11-2015 4 3 | 4 | 3 | ||
| I would like to convert a earliest and latest time and concatenate in a string value, so I could have that in my Dash... by celsohso Path Finder in Splunk Search 02-10-2015 1 5 | 1 | 5 | ||
| Hello, I am looking for a solution to manage my splunk objects (searches, event type, macros, lookups, etc). There ar... by rmurthy Engager in Splunk Search 02-10-2015 4 2 | 4 | 2 | ||
| I'm creating dashboards for the error status. We currently have 3 different statuses (200,404, and 0). The '200' stat... by skoelpin SplunkTrust 0 4 | 0 | 4 | ||
| I was wondering if it was possible to write a props.conf something similar to the following: props: [sourcetype = m... by ltrand Contributor in Splunk Search 02-10-2015 0 2 | 0 | 2 | ||
| Jesse, Wondering if I could throw another question at you... I have the following query: source="mysource" Immediat... by jwalzerpitt Influencer in Splunk Search 02-10-2015 0 2 | 0 | 2 | ||
| I see a variety of letters being used like w,n,d,s etc. pls help me to understand what characters are available to us... by satya2p Path Finder in Splunk Search 02-10-2015 0 5 | 0 | 5 | ||
| Hi I have field named as "extract_datetime" and it has the following values; 2015-02-08 02:15:24 2015-02-08 02:18:3... by rogerbinny Explorer in Splunk Search 02-10-2015 0 10 | 0 | 10 | ||
| Hello Splunkers, Question: I have a lookup working properly on a .csv file but I appear to have correctly assumed tha... by lbogle Contributor in Splunk Search 02-10-2015 0 5 | 0 | 5 |