| I use a lookup file for matching a TCP or UDP port and an application. Is it possible to specify a port range instead... by erwan_raulet Explorer in Splunk Search 01-30-2015 0 4 | 0 | 4 | ||
| Hi all, We are looking for a way to identify when users share their passwords. For example, userA has elevated privi... by taylormimission New Member in Splunk Search 01-30-2015 0 1 | 0 | 1 | ||
| Sorry if this question lacks objectivity. Basically, in my current SPA webapp, I am making three queries to Splunk t... by mohitab Path Finder in Splunk Search 01-30-2015 0 1 | 0 | 1 | ||
| Hi Experts, I have an issue with stacked time chart. My search is like Sourcetype="ABC"| timechart count by dest_ip... by vikas_gopal Builder in Splunk Search 01-30-2015 0 4 | 0 | 4 | ||
| I have a home grown ticket system (relational database). It includes a "DateClosed" field that gets updated (obviousl... by gjohnson New Member in Splunk Search 01-30-2015 0 1 | 0 | 1 | ||
| Hi, I'm trying to convert a dashboard based on internal searches to one using data models. One thing I'm missing is ... by echalex Builder in Splunk Search 01-30-2015 0 1 | 0 | 1 | ||
| Hi all, I'm having an issue with timestamp extraction. Trying to extract the timestamp from formatted text, and I c... by kenvanderheyden Path Finder in Splunk Search 01-30-2015 0 7 | 0 | 7 | ||
| Hello, I have two data sources Active Directory (Source 1) and Change Approvals (Source 2). I need to identify any A... by pjb2160 Path Finder in Splunk Search 01-29-2015 0 2 | 0 | 2 | ||
| I am relatively new to all things splunk. I am trying to set up a timechart that will pass a value onto another input... by KindaWorking Path Finder in Splunk Search 01-29-2015 0 3 | 0 | 3 | ||
| I have a search head cluster (splunk 6.2) with two search head members (1 captain,1 search head,1 deployer) and one i... by liquid Engager in Splunk Search 01-29-2015 0 1 | 0 | 1 | ||
| Hi- I have the logs below in SPlunk. I wanted to create an alert when the UsePct is gretaer than 90%. Please help f... by Isaias_Garcia Path Finder in Splunk Search 01-29-2015 0 2 | 0 | 2 | ||
| I am using the below query to create a timechart. sourcetype=xxx AND source = "xxxx" | rex "Operation:(?[A-Z]*)" |... by sivagujju New Member in Splunk Search 01-29-2015 0 6 | 0 | 6 | ||
| Hello, I've been using the query provided at http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume to g... by hcheang Path Finder in Splunk Search 01-29-2015 0 5 | 0 | 5 | ||
| Hello. I have a search that looks for event id's that are the result of a regex: index=app_sec_prod sourcetype="... by datablick Engager in Splunk Search 01-29-2015 1 2 | 1 | 2 | ||
| I am using | dbquery to get the lookup details and outputlookup to generate the lookup file, but it always generates ... by vishal_bandavad Explorer in Splunk Search 01-29-2015 0 3 | 0 | 3 | ||
| So I finally got my query to work only to find out that subsearch has a limit to 10,000 results! Is there a way to ra... by rlough Path Finder in Splunk Search 01-29-2015 2 5 | 2 | 5 | ||
| I am trying to rex a URL string. Here is an example: ManageAccount.do?ACTION=VIEW&id=27271905&acctViewType=transact... by kknopp Path Finder in Splunk Search 01-29-2015 0 9 | 0 | 9 | ||
| Hi. I am creating a search and dashboard to display our last ten locked account events. This seems to work well as I ... by jhillenburg Path Finder in Splunk Search 01-29-2015 1 5 | 1 | 5 | ||
| I have a search as below : index="network_wireless" sourcetype="Wireless_Client_Count*" | rex "(?[^,]*),(?[^,]*),... by blieberman Engager in Splunk Search 01-29-2015 0 4 | 0 | 4 | ||
| I'll state my problem first, then some of the posts, apps, and documents I've looked at already.... In AD, we have a... by reswob4 Builder in Splunk Search 01-29-2015 0 6 | 0 | 6 | ||
| On patch night some of my splunk servers are not starting. I can see the ones that are starting with this search ho... by hartfoml Motivator in Splunk Search 01-29-2015 0 2 | 0 | 2 | ||
| This works wonderfully to give me the count and median per server farm, per URL: index=wtf earliest=10/13/2014:10:0... by jundai Explorer in Splunk Search 01-29-2015 1 5 | 1 | 5 | ||
| I have a field of the following form: mysplit=A.B Where A is a string of letters and B is a Number. I'm trying... by Splunkster45 Communicator in Splunk Search 01-29-2015 0 5 | 0 | 5 | ||
| Im trying to count how many events by category per email domain and do a total of events going to each domain. My que... by Dallastek Explorer in Splunk Search 01-29-2015 0 8 | 0 | 8 | ||
| In each log event, I have 3 fields that keep a record count of the number of rows inserted, updated and deleted. I am... by Splunkster45 Communicator in Splunk Search 01-29-2015 0 2 | 0 | 2 |