Splunk Search

Splunk Search
Community Activity
coleman07
In a previous question I asked last night. I found weird unexpected results on my search. This begs the question - is...
by coleman07 Path Finder in Splunk Search 10-17-2014
1 1
1
1
nekb1958
when i take my eventgen conf in sample-mode the timestamp is replaced with the actual time in the defined format. whe...
by nekb1958 Path Finder in Splunk Search 10-17-2014
0 3
0
3
nramya82
Hi , I need to make a graph for the delta_f where i am finding the difference of current value and next value . By u...
by nramya82 Explorer in Splunk Search 10-17-2014
2 3
2
3
kkossery
I want my search result from a source and another search result from a different source to appear on one single PDF r...
by kkossery Communicator in Splunk Search 10-17-2014
0 1
0
1
siraj198204
Hi , index =casm_prod source =/opt/siteminder/log/smtracedefault.log sourcetype=smtrace supportcentral | rex "(\[[...
by siraj198204 Explorer in Splunk Search 10-17-2014
0 3
0
3
hxa27
Hi, I am trying to use Splunk to monitor my process by using the db connect. My problem is I am using the followin...
by hxa27 Path Finder in Splunk Search 10-17-2014
0 6
0
6
asimagu
Hi I have an issue trying to create an input with db connect that throws this error 2013-06-12 11:29:23.417 dbx7796...
by asimagu Builder in Splunk Search 10-17-2014
0 8
0
8
kpattison
I have a multi-threaded application in Glassfish. A single event generates multiple lines of logging but multiple eve...
by kpattison New Member in Splunk Search 10-17-2014
0 2
0
2
markthompson
Hi, i have the following search query: index=project_omega host=PersistUBS | transaction startswith="Targeting file ...
by markthompson Builder in Splunk Search 10-17-2014
1 16
1
16
bigrichie90
I am trying to build a query so that anytime someone needs to find the host of a DHCP IP at a specific time (since th...
by bigrichie90 Path Finder in Splunk Search 10-16-2014
2 4
2
4
DEAD_BEEF
My existing query produces a table that has the following columns in this order: Source IPCountDestination IPDestina...
by DEAD_BEEF Builder in Splunk Search 10-16-2014
0 5
0
5
benstraw
I have several searches that search over all time and they don't seem to finish unless I send them to the background....
by benstraw Splunk Employee Splunk Employee in Splunk Search 10-16-2014
3 2
3
2
mbuschle
I have a search situation I haven't yet been able to crack. I have two sourcetypes that contain data for Web Confere...
by mbuschle Explorer in Splunk Search 10-16-2014
0 1
0
1
Splunkster45
I have two types of logs in my files that record when a user logs in and logs out. They are of the form: Session <nu...
by Splunkster45 Communicator in Splunk Search 10-16-2014
0 1
0
1
jaj
I have a log where labelData=123-345 or lableData=123 How I want to ignore the -345 and just keep the first ...
by jaj Path Finder in Splunk Search 10-16-2014
0 6
0
6
FutureSight
In order for me to create appropriate Splunk alerts for a certain process, I need to be able to dynamically generate ...
by FutureSight Engager in Splunk Search 10-16-2014
3 2
3
2
Bhuavana
Hi, I have a below log : INFO com.wu.channelservices.businesslogic.impl.ChannelServicesLogicImpl S:METHOD_NAME=Gwp...
by Bhuavana Explorer in Splunk Search 10-16-2014
0 2
0
2
a212830
Hi, I need to do a field extraction on a multi-line event. The values have quotes, and I'm having problems getting ...
by a212830 Champion in Splunk Search 10-15-2014
0 2
0
2
tayyujie
I am running pfSense in my environment. Currently, I am sending logs through UDP 50000, and my source type is pfsense...
by tayyujie Explorer in Splunk Search 10-15-2014
0 4
0
4
renems
I'm having a really hard time figuring this one out. How can I enrich my search results with an inputlookup? In this...
by renems Communicator in Splunk Search 10-15-2014
0 1
0
1
ludowillemans
How can I limit the available events in an app ? Search results in the app should only return events that also match...
by ludowillemans Explorer in Splunk Search 10-15-2014
0 2
0
2
sjanwity
How do I hide rows based on the number of rows returned in a transaction? (EDITED: removed all the contextual inform...
by sjanwity Communicator in Splunk Search 10-15-2014
1 3
1
3
yuanliu
In stats, values() can be used to enumerate values fitting the stats criteria. Is there a similar function to do thi...
by SplunkTrust SplunkTrust in Splunk Search 10-15-2014
0 1
0
1
OMohi
I would like to know how do I find the distribution of all Universal forwarders in Splunk by os type (Unix, Windows, ...
by OMohi Path Finder in Splunk Search 10-15-2014
0 4
0
4
kmasood
Hello, I have this query, which takes an ip address, returns FQDN and count columns: base search | `ip2fqdn(ip)` | ...
by kmasood Explorer in Splunk Search 10-15-2014
0 8
0
8
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...