Splunk Search

Splunk Search
Community Activity
armonsal
Hello everyone, I have events with this format 10/23/2014 04:00:02 -0300, search_name=CDR_INSTITUCIONES_APP, search...
by armonsal Explorer in Splunk Search 10-23-2014
0 3
0
3
a212830
Hi, I have a very ugly data feed, and the customer thinks that they are getting duplicate events, because the event ...
by a212830 Champion in Splunk Search 10-23-2014
0 3
0
3
vtsguerrero
Hello guys! I know Splunk has a REGEX helper, but in this case, I have an amount of data wich is almost binary, take ...
by vtsguerrero Contributor in Splunk Search 10-23-2014
1 14
1
14
shangshin
Hi, Is it possible to suppress alert email from the saved searches due to splunk internal error. For example, I rece...
by shangshin Builder in Splunk Search 10-23-2014
0 15
0
15
bohrasaurabh
I have the below lines in of of the logs and I want to perform Search time field extraction on the sourcetype 14133...
by bohrasaurabh Communicator in Splunk Search 10-23-2014
0 6
0
6
kkossery
Experts, I have a Event Log output using the search string sourcetype="WinEventLog:Security" "eventcode=4767" OR "e...
by kkossery Communicator in Splunk Search 10-23-2014
0 7
0
7
DanielFordWA
I have created an app that contains some simple XML dashboards. I am trying to achieve the following. User logs ont...
by DanielFordWA Contributor in Splunk Search 10-23-2014
1 2
1
2
srinathd
get epoch time from string time example from 20090930 to epoch time?
by srinathd Contributor in Splunk Search 10-23-2014
0 1
0
1
shariinPH
Hi Splunkers! Anyone here who knows how to change the range of colors for D3 Chart? Hope someone can help us with t...
by shariinPH Contributor in Splunk Search 10-23-2014
1 1
1
1
mikaelbje
I'm working on a dashboard that shows VPN logins and Citrix XenApp applications with inputs to select a specific busi...
by mikaelbje Motivator in Splunk Search 10-23-2014
0 3
0
3
chandravadanj
I need suggestion to write a search query to calculate a difference between the timestamps for the same event. Follow...
by chandravadanj Explorer in Splunk Search 10-22-2014
1 6
1
6
subtrakt
Summary searches occur every 5 mins but for those who need more immediate results can a non-summary search be merged ...
by subtrakt Contributor in Splunk Search 10-22-2014
0 1
0
1
rdunn
I'm relatively new to Splunk, so I'm pretty sure I'm going about this the wrong way but I have to think it's possible...
by rdunn Engager in Splunk Search 10-22-2014
4 3
4
3
shikhanshu
My event has fields like this: _time = <timestamp> target_date1 = "1/1/2015" target_date2 = "2/3/2015" target_date3 ...
by shikhanshu Path Finder in Splunk Search 10-22-2014
0 7
0
7
gozulin
How do I do this? The index I'm renaming is brand new so there are no reports/searches or anything relying on it yet ...
by gozulin Communicator in Splunk Search 10-22-2014
4 2
4
2
bigrichie90
I have this query in which I join with another query. I want to take the earliest event of the first query, go back a...
by bigrichie90 Path Finder in Splunk Search 10-22-2014
0 5
0
5
kpavan
Hi All, Need to find Windows Edition through splunk query like Windows 2003, Vista, 2008 etc.. I checked query ind...
by kpavan Path Finder in Splunk Search 10-22-2014
0 1
0
1
atanasmitev
I have a _raw field with the following data in: .............. "Stuff\":\"CAPITALS_AND_UNDERSCORES\", .........
by atanasmitev Path Finder in Splunk Search 10-22-2014
1 2
1
2
smudge797
I need to extract the email address from the following logs, either in a search or via props.conf - transforms.conf ...
by smudge797 Path Finder in Splunk Search 10-22-2014
1 9
1
9
tpflicke
I've got a large number of logs which look similar to: INFO com.this.that.SomeLogger 2014-05-08 08:29:49,997 [CSP-1...
by tpflicke Path Finder in Splunk Search 10-22-2014
0 2
0
2
markthompson
Hi, I have a field called Submit Date and it's format is like this: 10/21/2014 11:26:05 AM I'm trying to separate th...
by markthompson Builder in Splunk Search 10-22-2014
1 3
1
3
myahes
using this articles advice (http://blogs.splunk.com/2012/02/19/compare-two-time-ranges-in-one-report/) i am trying ...
by myahes Explorer in Splunk Search 10-21-2014
0 2
0
2
mohankesireddy
I have two sets of data, both sets have a common field with common value, when i use join command i am able to find t...
by mohankesireddy Path Finder in Splunk Search 10-21-2014
1 2
1
2
menonmanish
Can the universal forwarder monitor event logs and filter out events using REGEX in whitelist for eg: [WinEventLog://...
by menonmanish Path Finder in Splunk Search 10-21-2014
0 1
0
1
abhayneilam
Hi, I want to replace all ":*" character means :: ::: :::: and so on with only singel ":" character. for Location fi...
by abhayneilam Contributor in Splunk Search 10-21-2014
2 6
2
6
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...