Splunk Search

Splunk Search
Community Activity
erwan_raulet
I use a lookup file for matching a TCP or UDP port and an application. Is it possible to specify a port range instead...
by erwan_raulet Explorer in Splunk Search 01-30-2015
0 4
0
4
taylormimission
Hi all, We are looking for a way to identify when users share their passwords. For example, userA has elevated privi...
by taylormimission New Member in Splunk Search 01-30-2015
0 1
0
1
mohitab
Sorry if this question lacks objectivity. Basically, in my current SPA webapp, I am making three queries to Splunk t...
by mohitab Path Finder in Splunk Search 01-30-2015
0 1
0
1
vikas_gopal
Hi Experts, I have an issue with stacked time chart. My search is like Sourcetype="ABC"| timechart count by dest_ip...
by vikas_gopal Builder in Splunk Search 01-30-2015
0 4
0
4
gjohnson
I have a home grown ticket system (relational database). It includes a "DateClosed" field that gets updated (obviousl...
by gjohnson New Member in Splunk Search 01-30-2015
0 1
0
1
echalex
Hi, I'm trying to convert a dashboard based on internal searches to one using data models. One thing I'm missing is ...
by echalex Builder in Splunk Search 01-30-2015
0 1
0
1
kenvanderheyden
Hi all, I'm having an issue with timestamp extraction. Trying to extract the timestamp from formatted text, and I c...
by kenvanderheyden Path Finder in Splunk Search 01-30-2015
0 7
0
7
pjb2160
Hello, I have two data sources Active Directory (Source 1) and Change Approvals (Source 2). I need to identify any A...
by pjb2160 Path Finder in Splunk Search 01-29-2015
0 2
0
2
KindaWorking
I am relatively new to all things splunk. I am trying to set up a timechart that will pass a value onto another input...
by KindaWorking Path Finder in Splunk Search 01-29-2015
0 3
0
3
liquid
I have a search head cluster (splunk 6.2) with two search head members (1 captain,1 search head,1 deployer) and one i...
by liquid Engager in Splunk Search 01-29-2015
0 1
0
1
Isaias_Garcia
Hi- I have the logs below in SPlunk. I wanted to create an alert when the UsePct is gretaer than 90%. Please help f...
by Isaias_Garcia Path Finder in Splunk Search 01-29-2015
0 2
0
2
sivagujju
I am using the below query to create a timechart. sourcetype=xxx AND source = "xxxx" | rex "Operation:(?[A-Z]*)" |...
by sivagujju New Member in Splunk Search 01-29-2015
0 6
0
6
hcheang
Hello, I've been using the query provided at http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume to g...
by hcheang Path Finder in Splunk Search 01-29-2015
0 5
0
5
datablick
Hello. I have a search that looks for event id's that are the result of a regex: index=app_sec_prod sourcetype="...
by datablick Engager in Splunk Search 01-29-2015
1 2
1
2
vishal_bandavad
I am using | dbquery to get the lookup details and outputlookup to generate the lookup file, but it always generates ...
by vishal_bandavad Explorer in Splunk Search 01-29-2015
0 3
0
3
rlough
So I finally got my query to work only to find out that subsearch has a limit to 10,000 results! Is there a way to ra...
by rlough Path Finder in Splunk Search 01-29-2015
2 5
2
5
kknopp
I am trying to rex a URL string. Here is an example: ManageAccount.do?ACTION=VIEW&id=27271905&acctViewType=transact...
by kknopp Path Finder in Splunk Search 01-29-2015
0 9
0
9
jhillenburg
Hi. I am creating a search and dashboard to display our last ten locked account events. This seems to work well as I ...
by jhillenburg Path Finder in Splunk Search 01-29-2015
1 5
1
5
blieberman
I have a search as below : index="network_wireless" sourcetype="Wireless_Client_Count*" | rex "(?[^,]*),(?[^,]*),...
by blieberman Engager in Splunk Search 01-29-2015
0 4
0
4
reswob4
I'll state my problem first, then some of the posts, apps, and documents I've looked at already.... In AD, we have a...
by reswob4 Builder in Splunk Search 01-29-2015
0 6
0
6
hartfoml
On patch night some of my splunk servers are not starting. I can see the ones that are starting with this search ho...
by hartfoml Motivator in Splunk Search 01-29-2015
0 2
0
2
jundai
This works wonderfully to give me the count and median per server farm, per URL: index=wtf earliest=10/13/2014:10:0...
by jundai Explorer in Splunk Search 01-29-2015
1 5
1
5
Splunkster45
I have a field of the following form: mysplit=A.B Where A is a string of letters and B is a Number. I'm trying...
by Splunkster45 Communicator in Splunk Search 01-29-2015
0 5
0
5
Dallastek
Im trying to count how many events by category per email domain and do a total of events going to each domain. My que...
by Dallastek Explorer in Splunk Search 01-29-2015
0 8
0
8
Splunkster45
In each log event, I have 3 fields that keep a record count of the number of rows inserted, updated and deleted. I am...
by Splunkster45 Communicator in Splunk Search 01-29-2015
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...