| Hi My search : index="abc" (source="tac.log" DebugLevelSrc=xxx "*ccc*") OR (source="crt.log" DebugLevelSrc=xxx "*... by prad18 Path Finder in Splunk Search 10-13-2014 1 4 | 1 | 4 | ||
| Hello everybody, I have a question that might have been responded before but I have a log file from a server that lo... by juancarlos_pola Explorer in Splunk Search 10-13-2014 0 3 | 0 | 3 | ||
| I hope someone can point me in the right direction because I really need help. SPL transforms are anything but easy a... by jtelep New Member in Splunk Search 10-13-2014 0 1 | 0 | 1 | ||
| Hi. We are trying to create a dashboard in which all the panels use the same information about the current (real tim... by arturoduran Engager in Splunk Search 10-13-2014 0 1 | 0 | 1 | ||
| HI All, Im have a search and its working great for calculating averages based on the domain, the problem is that I w... by brywilk_umich Path Finder in Splunk Search 10-13-2014 0 6 | 0 | 6 | ||
| I know I can override the default bins=100 in any particular search. Is there any way to set something slightly high... by Richfez SplunkTrust 1 2 | 1 | 2 | ||
| I'm looking to change the format of the useful duration tool from seconds to hours. I found out how to do this via so... by Splunkster45 Communicator in Splunk Search 10-13-2014 2 4 | 2 | 4 | ||
| Hello guys, I installed hunk and followed its tutorial. I have checked the HDFS location and it seems fine. Hadoop v... by rameez Engager in Splunk Search 10-13-2014 0 1 | 0 | 1 | ||
| My actual search sourcetype="xyz" Operation=q | eval msg=if(Status == "fail",[search sourcetype="xyz" Operation="p" ... by tehale New Member in Splunk Search 10-13-2014 0 1 | 0 | 1 | ||
| I have some conditions for each search as follows: Search A index=users Channel=40 | eval Token = User."-".Channel... by vtsguerrero Contributor in Splunk Search 10-13-2014 0 10 | 0 | 10 | ||
| I have a set of URLs in a log like so: url1:"POST /stuff/test/" url2: "GET /stuff/test-type?" url:3"POST /stuff/tes... by atanasmitev Path Finder in Splunk Search 10-13-2014 0 2 | 0 | 2 | ||
| Hi All, we had configured splunk to get the perfmon counter data from server (every 5mins). The counter value gets r... by rsathish47 Contributor in Splunk Search 10-12-2014 0 2 | 0 | 2 | ||
| I've got users using 2 apps that I'm pulling from, and I'm looking at login reports. Given that the users have unique... by Cox_JoshS Explorer in Splunk Search 10-12-2014 1 4 | 1 | 4 | ||
| I have 26 days of events (Monday 9/15 through Friday 10/10) piped to a timechart span=7d. I'd like to have 3 buckets... by ruman Splunk Employee 2 13 | 2 | 13 | ||
| Comparing regex strings... Log format: Thu 08/07/2014, 6:41:59.97,USERA,TERM1,XXXX-YYYAPP65-5 Thu 08/07/2014, 6:42... by NK_1 Path Finder in Splunk Search 10-11-2014 1 7 | 1 | 7 | ||
| In a lookup file, how can I configure more than one time-based fields (ex. start_date, update_date, expire_date)? W... by boris Path Finder in Splunk Search 10-11-2014 6 1 | 6 | 1 | ||
| I have an event with the field SRT and value as show below. SRT="0|0|NA1|FB1|FE2|FE0|FR1|IR2|FE3|FR1|IR3|FD1|ID21|FE... by ben_leung Builder in Splunk Search 10-10-2014 0 2 | 0 | 2 | ||
| Does this work? When my lookup table is updated every hour via a separate search, is my real-time search using that n... by thisissplunk Builder in Splunk Search 10-10-2014 0 4 | 0 | 4 | ||
| Hi I´m trying to create a search that basically count the number of unique UserId generated over a certain time in t... by Norling80 Path Finder in Splunk Search 10-10-2014 0 2 | 0 | 2 | ||
| I have exactly 7 spaces randomly in each line of my data such as below and I would like to trim exactly these number... by ishugupta Path Finder in Splunk Search 10-10-2014 0 2 | 0 | 2 | ||
| We are using the Juniper SA app, however I am trying to create a dashboard that will show a chart of unique VPN users... by casey18cc Explorer in Splunk Search 10-10-2014 0 2 | 0 | 2 | ||
| When input length exceeds a certain threshold, it seems that some rex match will fail while others do not. Consider ... by yuanliu SplunkTrust 1 2 | 1 | 2 | ||
| source="dbmon-tail://idwarehouse/idw_account" application=TFAYD [|inputlookup execSSO.csv |rename sso as owner] |eval... by siraj198204 Explorer in Splunk Search 10-10-2014 0 32 | 0 | 32 | ||
| The query is as follows: index="inverntory" source="s1" UUID="C64" | join UUID [search index="inverntory" source="s1"... by kelvin56887 Explorer in Splunk Search 10-10-2014 0 3 | 0 | 3 | ||
| I can't return _raw data from subsearch as below , but i can find this raw data if i use it in separate main search .... by anilchauhanmanu Explorer in Splunk Search 10-10-2014 1 4 | 1 | 4 |