Splunk Search

Splunk Search
Community Activity
juancarlos_pola
Hello everybody, I have a question that might have been responded before but I have a log file from a server that lo...
by juancarlos_pola Explorer in Splunk Search 10-13-2014
0 3
0
3
jtelep
I hope someone can point me in the right direction because I really need help. SPL transforms are anything but easy a...
by jtelep New Member in Splunk Search 10-13-2014
0 1
0
1
arturoduran
Hi. We are trying to create a dashboard in which all the panels use the same information about the current (real tim...
by arturoduran Engager in Splunk Search 10-13-2014
0 1
0
1
brywilk_umich
HI All, Im have a search and its working great for calculating averages based on the domain, the problem is that I w...
by brywilk_umich Path Finder in Splunk Search 10-13-2014
0 6
0
6
Richfez
I know I can override the default bins=100 in any particular search. Is there any way to set something slightly high...
by SplunkTrust SplunkTrust in Splunk Search 10-13-2014
1 2
1
2
Splunkster45
I'm looking to change the format of the useful duration tool from seconds to hours. I found out how to do this via so...
by Splunkster45 Communicator in Splunk Search 10-13-2014
2 4
2
4
rameez
Hello guys, I installed hunk and followed its tutorial. I have checked the HDFS location and it seems fine. Hadoop v...
by rameez Engager in Splunk Search 10-13-2014
0 1
0
1
tehale
My actual search sourcetype="xyz" Operation=q | eval msg=if(Status == "fail",[search sourcetype="xyz" Operation="p" ...
by tehale New Member in Splunk Search 10-13-2014
0 1
0
1
vtsguerrero
I have some conditions for each search as follows: Search A index=users Channel=40 | eval Token = User."-".Channel...
by vtsguerrero Contributor in Splunk Search 10-13-2014
0 10
0
10
atanasmitev
I have a set of URLs in a log like so: url1:"POST /stuff/test/" url2: "GET /stuff/test-type?" url:3"POST /stuff/tes...
by atanasmitev Path Finder in Splunk Search 10-13-2014
0 2
0
2
rsathish47
Hi All, we had configured splunk to get the perfmon counter data from server (every 5mins). The counter value gets r...
by rsathish47 Contributor in Splunk Search 10-12-2014
0 2
0
2
Cox_JoshS
I've got users using 2 apps that I'm pulling from, and I'm looking at login reports. Given that the users have unique...
by Cox_JoshS Explorer in Splunk Search 10-12-2014
1 4
1
4
ruman
I have 26 days of events (Monday 9/15 through Friday 10/10) piped to a timechart span=7d. I'd like to have 3 buckets...
by ruman Splunk Employee Splunk Employee in Splunk Search 10-11-2014
2 13
2
13
NK_1
Comparing regex strings... Log format: Thu 08/07/2014, 6:41:59.97,USERA,TERM1,XXXX-YYYAPP65-5 Thu 08/07/2014, 6:42...
by NK_1 Path Finder in Splunk Search 10-11-2014
1 7
1
7
boris
In a lookup file, how can I configure more than one time-based fields (ex. start_date, update_date, expire_date)? W...
by boris Path Finder in Splunk Search 10-11-2014
6 1
6
1
ben_leung
I have an event with the field SRT and value as show below. SRT="0|0|NA1|FB1|FE2|FE0|FR1|IR2|FE3|FR1|IR3|FD1|ID21|FE...
by ben_leung Builder in Splunk Search 10-10-2014
0 2
0
2
thisissplunk
Does this work? When my lookup table is updated every hour via a separate search, is my real-time search using that n...
by thisissplunk Builder in Splunk Search 10-10-2014
0 4
0
4
Norling80
Hi I´m trying to create a search that basically count the number of unique UserId generated over a certain time in t...
by Norling80 Path Finder in Splunk Search 10-10-2014
0 2
0
2
ishugupta
I have exactly 7 spaces randomly in each line of my data such as below and I would like to trim exactly these number...
by ishugupta Path Finder in Splunk Search 10-10-2014
0 2
0
2
casey18cc
We are using the Juniper SA app, however I am trying to create a dashboard that will show a chart of unique VPN users...
by casey18cc Explorer in Splunk Search 10-10-2014
0 2
0
2
yuanliu
When input length exceeds a certain threshold, it seems that some rex match will fail while others do not. Consider ...
by SplunkTrust SplunkTrust in Splunk Search 10-10-2014
1 2
1
2
siraj198204
source="dbmon-tail://idwarehouse/idw_account" application=TFAYD [|inputlookup execSSO.csv |rename sso as owner] |eval...
by siraj198204 Explorer in Splunk Search 10-10-2014
0 32
0
32
kelvin56887
The query is as follows: index="inverntory" source="s1" UUID="C64" | join UUID [search index="inverntory" source="s1"...
by kelvin56887 Explorer in Splunk Search 10-10-2014
0 3
0
3
anilchauhanmanu
I can't return _raw data from subsearch as below , but i can find this raw data if i use it in separate main search ....
by anilchauhanmanu Explorer in Splunk Search 10-10-2014
1 4
1
4
devicenul1
6.1.1 known issues: Events format settings like list, table, max lines, wrapping do not apply to PDF reports and are ...
by devicenul1 Path Finder in Splunk Search 10-10-2014
0 7
0
7
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors