Splunk Search

Splunk Search
Community Activity
himynamesdave
I have events that look like this. Example 1. Example 2. ....... I have indexed the data using a props.conf like t...
by himynamesdave Contributor in Splunk Search 01-07-2015
0 11
0
11
hcheang
Hello, I would like to know if there is any restriction in the rex command because for all the rex field-extractions...
by hcheang Path Finder in Splunk Search 01-07-2015
0 6
0
6
imarks001
I am trying to come up with a search that would parse Google search queries made though my Ironport web proxy. I woul...
by imarks001 Explorer in Splunk Search 01-07-2015
1 7
1
7
a212830
I want to map the host to data coming in and need help with the regex to put in transforms.conf. The data is: metri...
by a212830 Champion in Splunk Search 01-07-2015
0 1
0
1
markthompson
Hello, Well we have a job that runs and produces log files that runs and if it fails, it retries up to 3x. How woul...
by markthompson Builder in Splunk Search 01-07-2015
1 5
1
5
vikas_gopal
Hi Experts, I have syslog file and I want to generate a table from this log file .This file contains log like 2014-...
by vikas_gopal Builder in Splunk Search 01-07-2015
0 11
0
11
mohitab
I have a query like: search /my/huge/query/with/lot/of/evals/and/joins | stats avg(field3) group by field1 search /...
by mohitab Path Finder in Splunk Search 01-07-2015
0 5
0
5
arindam_sur
Hi, I have created a dashboard panel which lists out top actions taken by a Palo Alto firewall. The Action field ta...
by arindam_sur New Member in Splunk Search 01-07-2015
0 1
0
1
horst_poehlmann
I would like to write a search to give me all log lines relating to a particular bounced email message: Basically I ...
by horst_poehlmann Explorer in Splunk Search 01-06-2015
0 1
0
1
ferlin
I'm trying to retrieve this log event using the Splunk C# SDK v2.1.1.0 <Event timestamp="2015-01-06T17:44:54.284679+...
by ferlin Engager in Splunk Search 01-06-2015
0 1
0
1
DFresh4130
I have my apache servers' mod_status output (/server-status?auto) being pulled into Splunk with a scripted input. Th...
by DFresh4130 Path Finder in Splunk Search 01-06-2015
1 1
1
1
Splunkster45
Currently I can use a write an if statement in the following form: ... | eval adjusted_start=start_sum + 1 | eval c...
by Splunkster45 Communicator in Splunk Search 01-06-2015
1 1
1
1
Splunkster45
I want to be able to create a column on the statistic tab that has 1 if it is the start of the transaction or a 0 if...
by Splunkster45 Communicator in Splunk Search 01-06-2015
0 5
0
5
Wind
Such as when I using the following search: sourcetype="xyz" status=* |stats dc(ID) by ID status |sort by ID I will ge...
by Wind New Member in Splunk Search 01-06-2015
0 2
0
2
prabu_harsh12
string used in the search rex "(?i) Message= (?P[^.]+)" Event log form where im trying to extract "Message=The Win...
by prabu_harsh12 New Member in Splunk Search 01-06-2015
0 3
0
3
ssingh5
How we can monitor and genrate daily or weekly Splunk Health Reports? Can Splunk daemon status be monitored?
by ssingh5 Path Finder in Splunk Search 01-06-2015
0 2
0
2
ksolanki88
index="xyz_order_line"|join ORDER_NUMBER_KEY[|inputlookup sample_lookup1.csv|where serial_no>0 AND serial_no<50001]| ...
by ksolanki88 Explorer in Splunk Search 01-06-2015
0 2
0
2
akanno
Hi,Splunk community. I have a question about time-base-lookup. I set following attribute to transforms.conf [test]...
by akanno Communicator in Splunk Search 01-05-2015
0 4
0
4
DanielFordWA
Hi, I have around 50-60 searches/reports that are required to run each month after a lookup is manually updated and ...
by DanielFordWA Contributor in Splunk Search 01-05-2015
0 1
0
1
stefanlasiewski
I know that Splunk can show me results for the last 24 hours. I also know that Splunk can show me results in real tim...
by stefanlasiewski Contributor in Splunk Search 01-05-2015
0 4
0
4
bcdatacomm
I have a saved search that I alert on and there is certain events I don't want the alert to trigger for when it's com...
by bcdatacomm Explorer in Splunk Search 01-05-2015
2 2
2
2
sbeamro
Hi, when I run any search the date format is MM/DD/YEAR. how can I change the format to appear as DD/MM/YEAR ?
by sbeamro Explorer in Splunk Search 01-05-2015
1 7
1
7
epacke
Dear experts! Happy new year to you all.  Got a strange thing when I am creating a timechart in Splunk in the panel...
by epacke Path Finder in Splunk Search 01-05-2015
0 2
0
2
himynamesdave
Happy New Year everyone! Regex n00b here - I am struggling to break events for a particular source. Any help would b...
by himynamesdave Contributor in Splunk Search 01-04-2015
0 5
0
5
davidatpinger
My apologies if this is easy - I couldn't find a good example. I've got some log data that is mostly nicely formatte...
by davidatpinger Path Finder in Splunk Search 01-02-2015
0 7
0
7
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...