Splunk Search

Splunk Search
Community Activity
himynamesdave
I have events that look like this. Example 1. Example 2. ....... I have indexed the data using a props.conf like t...
by himynamesdave Contributor in Splunk Search 01-07-2015
0 11
0
11
hcheang
Hello, I would like to know if there is any restriction in the rex command because for all the rex field-extractions...
by hcheang Path Finder in Splunk Search 01-07-2015
0 6
0
6
imarks001
I am trying to come up with a search that would parse Google search queries made though my Ironport web proxy. I woul...
by imarks001 Explorer in Splunk Search 01-07-2015
1 7
1
7
a212830
I want to map the host to data coming in and need help with the regex to put in transforms.conf. The data is: metri...
by a212830 Champion in Splunk Search 01-07-2015
0 1
0
1
markthompson
Hello, Well we have a job that runs and produces log files that runs and if it fails, it retries up to 3x. How woul...
by markthompson Builder in Splunk Search 01-07-2015
1 5
1
5
vikas_gopal
Hi Experts, I have syslog file and I want to generate a table from this log file .This file contains log like 2014-...
by vikas_gopal Builder in Splunk Search 01-07-2015
0 11
0
11
mohitab
I have a query like: search /my/huge/query/with/lot/of/evals/and/joins | stats avg(field3) group by field1 search /...
by mohitab Path Finder in Splunk Search 01-07-2015
0 5
0
5
arindam_sur
Hi, I have created a dashboard panel which lists out top actions taken by a Palo Alto firewall. The Action field ta...
by arindam_sur New Member in Splunk Search 01-07-2015
0 1
0
1
horst_poehlmann
I would like to write a search to give me all log lines relating to a particular bounced email message: Basically I ...
by horst_poehlmann Explorer in Splunk Search 01-06-2015
0 1
0
1
ferlin
I'm trying to retrieve this log event using the Splunk C# SDK v2.1.1.0 <Event timestamp="2015-01-06T17:44:54.284679+...
by ferlin Engager in Splunk Search 01-06-2015
0 1
0
1
DFresh4130
I have my apache servers' mod_status output (/server-status?auto) being pulled into Splunk with a scripted input. Th...
by DFresh4130 Path Finder in Splunk Search 01-06-2015
1 1
1
1
Splunkster45
Currently I can use a write an if statement in the following form: ... | eval adjusted_start=start_sum + 1 | eval c...
by Splunkster45 Communicator in Splunk Search 01-06-2015
1 1
1
1
Splunkster45
I want to be able to create a column on the statistic tab that has 1 if it is the start of the transaction or a 0 if...
by Splunkster45 Communicator in Splunk Search 01-06-2015
0 5
0
5
Wind
Such as when I using the following search: sourcetype="xyz" status=* |stats dc(ID) by ID status |sort by ID I will ge...
by Wind New Member in Splunk Search 01-06-2015
0 2
0
2
prabu_harsh12
string used in the search rex "(?i) Message= (?P[^.]+)" Event log form where im trying to extract "Message=The Win...
by prabu_harsh12 New Member in Splunk Search 01-06-2015
0 3
0
3
ssingh5
How we can monitor and genrate daily or weekly Splunk Health Reports? Can Splunk daemon status be monitored?
by ssingh5 Path Finder in Splunk Search 01-06-2015
0 2
0
2
ksolanki88
index="xyz_order_line"|join ORDER_NUMBER_KEY[|inputlookup sample_lookup1.csv|where serial_no>0 AND serial_no<50001]| ...
by ksolanki88 Explorer in Splunk Search 01-06-2015
0 2
0
2
akanno
Hi,Splunk community. I have a question about time-base-lookup. I set following attribute to transforms.conf [test]...
by akanno Communicator in Splunk Search 01-05-2015
0 4
0
4
DanielFordWA
Hi, I have around 50-60 searches/reports that are required to run each month after a lookup is manually updated and ...
by DanielFordWA Contributor in Splunk Search 01-05-2015
0 1
0
1
stefanlasiewski
I know that Splunk can show me results for the last 24 hours. I also know that Splunk can show me results in real tim...
by stefanlasiewski Contributor in Splunk Search 01-05-2015
0 4
0
4
bcdatacomm
I have a saved search that I alert on and there is certain events I don't want the alert to trigger for when it's com...
by bcdatacomm Explorer in Splunk Search 01-05-2015
2 2
2
2
sbeamro
Hi, when I run any search the date format is MM/DD/YEAR. how can I change the format to appear as DD/MM/YEAR ?
by sbeamro Explorer in Splunk Search 01-05-2015
1 7
1
7
epacke
Dear experts! Happy new year to you all.  Got a strange thing when I am creating a timechart in Splunk in the panel...
by epacke Path Finder in Splunk Search 01-05-2015
0 2
0
2
himynamesdave
Happy New Year everyone! Regex n00b here - I am struggling to break events for a particular source. Any help would b...
by himynamesdave Contributor in Splunk Search 01-04-2015
0 5
0
5
davidatpinger
My apologies if this is easy - I couldn't find a good example. I've got some log data that is mostly nicely formatte...
by davidatpinger Path Finder in Splunk Search 01-02-2015
0 7
0
7
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...