Splunk Search

Splunk Search
Community Activity
sivagujju
I am using the below query to create a timechart. sourcetype=xxx AND source = "xxxx" | rex "Operation:(?[A-Z]*)" |...
by sivagujju New Member in Splunk Search 01-29-2015
0 6
0
6
hcheang
Hello, I've been using the query provided at http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume to g...
by hcheang Path Finder in Splunk Search 01-29-2015
0 5
0
5
datablick
Hello. I have a search that looks for event id's that are the result of a regex: index=app_sec_prod sourcetype="...
by datablick Engager in Splunk Search 01-29-2015
1 2
1
2
vishal_bandavad
I am using | dbquery to get the lookup details and outputlookup to generate the lookup file, but it always generates ...
by vishal_bandavad Explorer in Splunk Search 01-29-2015
0 3
0
3
rlough
So I finally got my query to work only to find out that subsearch has a limit to 10,000 results! Is there a way to ra...
by rlough Path Finder in Splunk Search 01-29-2015
2 5
2
5
kknopp
I am trying to rex a URL string. Here is an example: ManageAccount.do?ACTION=VIEW&id=27271905&acctViewType=transact...
by kknopp Path Finder in Splunk Search 01-29-2015
0 9
0
9
jhillenburg
Hi. I am creating a search and dashboard to display our last ten locked account events. This seems to work well as I ...
by jhillenburg Path Finder in Splunk Search 01-29-2015
1 5
1
5
blieberman
I have a search as below : index="network_wireless" sourcetype="Wireless_Client_Count*" | rex "(?[^,]*),(?[^,]*),...
by blieberman Engager in Splunk Search 01-29-2015
0 4
0
4
reswob4
I'll state my problem first, then some of the posts, apps, and documents I've looked at already.... In AD, we have a...
by reswob4 Builder in Splunk Search 01-29-2015
0 6
0
6
hartfoml
On patch night some of my splunk servers are not starting. I can see the ones that are starting with this search ho...
by hartfoml Motivator in Splunk Search 01-29-2015
0 2
0
2
jundai
This works wonderfully to give me the count and median per server farm, per URL: index=wtf earliest=10/13/2014:10:0...
by jundai Explorer in Splunk Search 01-29-2015
1 5
1
5
Splunkster45
I have a field of the following form: mysplit=A.B Where A is a string of letters and B is a Number. I'm trying...
by Splunkster45 Communicator in Splunk Search 01-29-2015
0 5
0
5
Dallastek
Im trying to count how many events by category per email domain and do a total of events going to each domain. My que...
by Dallastek Explorer in Splunk Search 01-29-2015
0 8
0
8
Splunkster45
In each log event, I have 3 fields that keep a record count of the number of rows inserted, updated and deleted. I am...
by Splunkster45 Communicator in Splunk Search 01-29-2015
0 2
0
2
marees123
*swt* "changed state to" */*/* | rex "(?i) Interface (?P[^,]+)" | rex "(?i)changed state to (?P.+)" | table host, AnI...
by marees123 Path Finder in Splunk Search 01-28-2015
0 4
0
4
nfieglein
I run this command: index=dccmtdit sourcetype=DCCMT_Log4J_JSON | transaction DpsNum maxevents=-1 It returns: 4,999...
by nfieglein Path Finder in Splunk Search 01-28-2015
0 2
0
2
smolcj
Hi, My search is like given below and my column names are source file names. As the source file name consists of dir...
by smolcj Builder in Splunk Search 01-28-2015
0 3
0
3
neha10
Hi , I have a scripted input in my app which is polling data every 60 minutes. This data brings a particular field w...
by neha10 Engager in Splunk Search 01-28-2015
0 1
0
1
ccsfdave
What I am trying to do is find what group a client IP belongs to. I have some existing assets (lookup csv) which ide...
by ccsfdave Builder in Splunk Search 01-28-2015
0 10
0
10
rlough
Hello, I currently have two queries which both have the same field. Is there a way, using subsearch, to filter out a...
by rlough Path Finder in Splunk Search 01-28-2015
0 8
0
8
visa87
I have a log file containing information logged in the below format: Response Received from ABC service for Submit T...
by visa87 Explorer in Splunk Search 01-28-2015
0 2
0
2
tmarlette
I'm attempting to chart some raw windows perfmon values on a chart over time, and I can't seem to find a way. I've be...
by tmarlette Motivator in Splunk Search 01-28-2015
0 7
0
7
d044160
I'd like to have some opinions on the following search. We're not thrilled with it's performance, and I'm sure theres...
by d044160 Explorer in Splunk Search 01-28-2015
4 7
4
7
avilandau
I have a log, broken to fields, where the free text field is the last field and can be multiline. After defining the ...
by avilandau Path Finder in Splunk Search 01-28-2015
0 1
0
1
Splunkster45
I have a Field that contains values in the YYYY-MM-DD. What's the best way to convert it to the day of week? For exam...
by Splunkster45 Communicator in Splunk Search 01-28-2015
0 1
0
1
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...