Splunk Search

Splunk Search
Community Activity
steverimar
I'm trying to return the associated fields based on a stats command. My stats command determines the minimum field va...
by steverimar Explorer in Splunk Search 01-22-2015
0 1
0
1
puneetkharband1
Below is the string I need to extract ROM_RAMESH from and similarly there are multiple client info so I need a regula...
by puneetkharband1 Path Finder in Splunk Search 01-22-2015
0 1
0
1
Thuan
I have the following excerpt of exchange logs. There are more fields before and after this excerpt. ,awells@atcorp....
by Thuan Explorer in Splunk Search 01-22-2015
0 15
0
15
dr_juice
I've connected to an MS SQL database using DB Connect and have a query running that successfully extracts table data....
by dr_juice Explorer in Splunk Search 01-22-2015
0 3
0
3
pradeepkumarg
We have a situation where we need to restrict users to be able to search during a specific period of time. Removing s...
by pradeepkumarg Influencer in Splunk Search 01-22-2015
0 4
0
4
splunkn
I am having a source file with the two below mentioned format. However I need to extract a same field but whose posit...
by splunkn Communicator in Splunk Search 01-22-2015
0 1
0
1
spsdoit
The events look like this: DATE=2015-01-19;TIME=10:34:20;STATUS=INFO;ID=57689;JOB=;ACTION=updateCounter;REASON=NotD...
by spsdoit New Member in Splunk Search 01-22-2015
0 4
0
4
ashwinipatil198
Hi, I have defined an eventtype in Splunk for a particular search. I defined a lookup which had this eventtype as a ...
by ashwinipatil198 Explorer in Splunk Search 01-21-2015
0 2
0
2
angelacb
I'm graphing out network I/O over _time on a timechart (Area Chart). Is there any easy way to have an overlay to high...
by angelacb New Member in Splunk Search 01-21-2015
0 1
0
1
loeweps
I have the following data. Each one has a different date entry. DATE ACCOUNT_NUMBER SOLUTION NAME ADDRESS ...
by loeweps Explorer in Splunk Search 01-21-2015
0 2
0
2
vtsguerrero
Hello everybody! I could use some help with this project that I've been working with... I have some .txt files which...
by vtsguerrero Contributor in Splunk Search 01-21-2015
0 12
0
12
splunk_zen
Why is this monitor whitelist not working ? [monitor:///opt/logs/] whitelist = (connectors/connectors\-\d\-boot|app1...
by splunk_zen Builder in Splunk Search 01-21-2015
0 4
0
4
dustyblahblah
Is anyone utilizing deduplication on storage arrays for Splunk volumes, and how does it perform?
by dustyblahblah New Member in Splunk Search 01-21-2015
0 3
0
3
priyenshah6
I want to create a table as: Column A, Column B LoginFailure, YES LoginSuccess, NO Account Lockout, YES Basically Y...
by priyenshah6 Engager in Splunk Search 01-20-2015
0 3
0
3
jgbricker
Hello, I'm trying to do something more complicated than this search, but the more complicated scenario includes regu...
by jgbricker Contributor in Splunk Search 01-20-2015
0 10
0
10
KindaWorking
I am super new to using the powerful eval command but cannot quite get my head around the syntax. Can someone help me...
by KindaWorking Path Finder in Splunk Search 01-20-2015
0 6
0
6
rlough
Hello, I'm trying to remove a string from the _raw of my search with the replace command and was wondering if wildca...
by rlough Path Finder in Splunk Search 01-20-2015
1 1
1
1
lennys26
Hello. I have a search which first collects the top 3% of "S3_call_error2", then searches within that list to return...
by lennys26 Communicator in Splunk Search 01-20-2015
0 5
0
5
kallisrayar1986
I have a pie chart with multiple slices, clicking on each slice will take you to Custom URL, please see the simple xm...
by kallisrayar1986 Path Finder in Splunk Search 01-20-2015
1 3
1
3
raindrop18
I have these two simple searches and I would like to combine them on one graph to display both "passed" and "failed" ...
by raindrop18 Communicator in Splunk Search 01-20-2015
1 8
1
8
sunilsuresh
Dear Experties, I am working on onboarding the apache weblogs and mapping the data in to access combined sourcetype ...
by sunilsuresh New Member in Splunk Search 01-20-2015
0 1
0
1
ewanbrown
Hi I have a search query that I need to join to a lookup table. I have it joining to this lookup table TestDec14 an...
by ewanbrown Path Finder in Splunk Search 01-20-2015
1 2
1
2
milande
In the documentation of "eval" command is written: "The result of an eval statement is not allowed to be boolean." (...
by milande Path Finder in Splunk Search 01-20-2015
0 4
0
4
immortalraghava
Hi in our application we run searches in the following ways. And we suspect some discrepancy when using splunk.search...
by immortalraghava Path Finder in Splunk Search 01-20-2015
2 2
2
2
RNB
I am having an issue where I have created a search string that returns the correct results, but when used as an alert...
by RNB Path Finder in Splunk Search 01-20-2015
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...