Thread Info | |||||
---|---|---|---|---|---|
If I have fields such as:
_time = timestamphost = the host nameMessage = either "up" or "down"
How do I group b...
by
ardave
Explorer
in
Splunk Search
10-13-2014
|
1
|
2
| |||
I have two types of logs in my files that record when a user logs in and logs out. They are of the form:
Session <...
by
Splunkster45
Communicator
in
Splunk Search
10-14-2014
|
0
|
1
| |||
Hello Splunkers!
My eventdata places on folders:
/folder1/subfolder1/123/log1.log
/folder1/subfolder1/234/log2....
by
ryastrebov
Communicator
in
Splunk Search
10-14-2014
|
0
|
4
| |||
Hi community,
propably a simple question, but I still hanging. I need a search over two logfiles, which shows me a...
by
eichfuss
Path Finder
in
Splunk Search
10-14-2014
|
0
|
2
| |||
I want to get all events related to dnis=27159866 I can perform this by getting all the events with a sessionid or pa...
by
ludowillemans
Explorer
in
Splunk Search
10-14-2014
|
0
|
3
| |||
I'm building a drop-down menu for picking the timechart span in simple dashboard. By default I'd like to have automat...
by
giovere
Path Finder
in
Splunk Search
10-13-2014
|
0
|
1
| |||
Hi all
Hope someone can help me with this.
I am building a custom application, which extracts data from a db an...
by
polymorphic
Communicator
in
Splunk Search
10-07-2014
|
0
|
1
| |||
Hi
My search :
index="abc" (source="tac.log" DebugLevelSrc=xxx "*ccc*") OR (source="crt.log" DebugLevelSrc=xx...
by
prad18
Path Finder
in
Splunk Search
10-13-2014
|
1
|
4
| |||
Hello everybody,
I have a question that might have been responded before but I have a log file from a server that ...
by
juancarlos_pola
Explorer
in
Splunk Search
10-10-2014
|
0
|
3
| |||
I hope someone can point me in the right direction because I really need help. SPL transforms are anything but easy a...
by
jtelep
New Member
in
Splunk Search
10-13-2014
|
0
|
1
| |||
Hi.
We are trying to create a dashboard in which all the panels use the same information about the current (real t...
by
arturoduran
Engager
in
Splunk Search
10-03-2014
|
0
|
1
| |||
HI All,
Im have a search and its working great for calculating averages based on the domain, the problem is that I...
by
brywilk_umich
Path Finder
in
Splunk Search
10-13-2014
|
0
|
6
| |||
I know I can override the default bins=100 in any particular search. Is there any way to set something slightly highe...
by
Richfez
SplunkTrust
in
Splunk Search
10-13-2014
|
1
|
2
| |||
I'm looking to change the format of the useful duration tool from seconds to hours. I found out how to do this via so...
by
Splunkster45
Communicator
in
Splunk Search
10-13-2014
|
2
|
4
| |||
Hello guys,
I installed hunk and followed its tutorial. I have checked the HDFS location and it seems fine. Hadoop...
by
rameez
Engager
in
Splunk Search
10-13-2014
|
0
|
1
| |||
My actual search sourcetype="xyz" Operation=q | eval msg=if(Status == "fail",[search sourcetype="xyz" Operation="p" ...
by
tehale
New Member
in
Splunk Search
10-13-2014
|
0
|
1
| |||
I have some conditions for each search as follows:
Search A
index=users Channel=40
| eval Token = User."-".Cha...
by
vtsguerrero
Contributor
in
Splunk Search
10-09-2014
|
0
|
10
| |||
I have a set of URLs in a log like so:
url1:"POST /stuff/test/" url2: "GET /stuff/test-type?" url:3"POST /stuff/te...
by
atanasmitev
Path Finder
in
Splunk Search
10-12-2014
|
0
|
2
| |||
Hi All,
we had configured splunk to get the perfmon counter data from server (every 5mins). The counter value gets...
by
rsathish47
Contributor
in
Splunk Search
10-09-2014
|
0
|
2
| |||
I've got users using 2 apps that I'm pulling from, and I'm looking at login reports. Given that the users have unique...
by
Cox_JoshS
Explorer
in
Splunk Search
10-09-2014
|
1
|
4
| |||
I have 26 days of events (Monday 9/15 through Friday 10/10) piped to a timechart span=7d.
I'd like to have 3 bucke...
by
ruman
Splunk Employee
in
Splunk Search
10-10-2014
|
2
|
13
| |||
Comparing regex strings...
Log format: Thu 08/07/2014, 6:41:59.97,USERA,TERM1,XXXX-YYYAPP65-5 Thu 08/07/2014, 6:...
by
NK_1
Path Finder
in
Splunk Search
09-06-2014
|
1
|
7
| |||
In a lookup file, how can I configure more than one time-based fields (ex. start_date, update_date, expire_date)?
...
by
boris
Path Finder
in
Splunk Search
08-22-2012
|
6
|
1
| |||
I have an event with the field SRT and value as show below.
SRT="0|0|NA1|FB1|FE2|FE0|FR1|IR2|FE3|FR1|IR3|FD1|ID21|...
by
ben_leung
Builder
in
Splunk Search
10-10-2014
|
0
|
2
| |||
Does this work? When my lookup table is updated every hour via a separate search, is my real-time search using that n...
by
thisissplunk
Builder
in
Splunk Search
10-10-2014
|
0
|
4
|