Splunk Search

Splunk Search
Community Activity
vtsguerrero
I have some conditions for each search as follows: Search A index=users Channel=40 | eval Token = User."-".Channel...
by vtsguerrero Contributor in Splunk Search 10-13-2014
0 10
0
10
atanasmitev
I have a set of URLs in a log like so: url1:"POST /stuff/test/" url2: "GET /stuff/test-type?" url:3"POST /stuff/tes...
by atanasmitev Path Finder in Splunk Search 10-13-2014
0 2
0
2
rsathish47
Hi All, we had configured splunk to get the perfmon counter data from server (every 5mins). The counter value gets r...
by rsathish47 Contributor in Splunk Search 10-12-2014
0 2
0
2
Cox_JoshS
I've got users using 2 apps that I'm pulling from, and I'm looking at login reports. Given that the users have unique...
by Cox_JoshS Explorer in Splunk Search 10-12-2014
1 4
1
4
ruman
I have 26 days of events (Monday 9/15 through Friday 10/10) piped to a timechart span=7d. I'd like to have 3 buckets...
by ruman Splunk Employee Splunk Employee in Splunk Search 10-11-2014
2 13
2
13
NK_1
Comparing regex strings... Log format: Thu 08/07/2014, 6:41:59.97,USERA,TERM1,XXXX-YYYAPP65-5 Thu 08/07/2014, 6:42...
by NK_1 Path Finder in Splunk Search 10-11-2014
1 7
1
7
boris
In a lookup file, how can I configure more than one time-based fields (ex. start_date, update_date, expire_date)? W...
by boris Path Finder in Splunk Search 10-11-2014
6 1
6
1
ben_leung
I have an event with the field SRT and value as show below. SRT="0|0|NA1|FB1|FE2|FE0|FR1|IR2|FE3|FR1|IR3|FD1|ID21|FE...
by ben_leung Builder in Splunk Search 10-10-2014
0 2
0
2
thisissplunk
Does this work? When my lookup table is updated every hour via a separate search, is my real-time search using that n...
by thisissplunk Builder in Splunk Search 10-10-2014
0 4
0
4
Norling80
Hi I´m trying to create a search that basically count the number of unique UserId generated over a certain time in t...
by Norling80 Path Finder in Splunk Search 10-10-2014
0 2
0
2
ishugupta
I have exactly 7 spaces randomly in each line of my data such as below and I would like to trim exactly these number...
by ishugupta Path Finder in Splunk Search 10-10-2014
0 2
0
2
casey18cc
We are using the Juniper SA app, however I am trying to create a dashboard that will show a chart of unique VPN users...
by casey18cc Explorer in Splunk Search 10-10-2014
0 2
0
2
yuanliu
When input length exceeds a certain threshold, it seems that some rex match will fail while others do not. Consider ...
by SplunkTrust SplunkTrust in Splunk Search 10-10-2014
1 2
1
2
siraj198204
source="dbmon-tail://idwarehouse/idw_account" application=TFAYD [|inputlookup execSSO.csv |rename sso as owner] |eval...
by siraj198204 Explorer in Splunk Search 10-10-2014
0 32
0
32
kelvin56887
The query is as follows: index="inverntory" source="s1" UUID="C64" | join UUID [search index="inverntory" source="s1"...
by kelvin56887 Explorer in Splunk Search 10-10-2014
0 3
0
3
anilchauhanmanu
I can't return _raw data from subsearch as below , but i can find this raw data if i use it in separate main search ....
by anilchauhanmanu Explorer in Splunk Search 10-10-2014
1 4
1
4
devicenul1
6.1.1 known issues: Events format settings like list, table, max lines, wrapping do not apply to PDF reports and are ...
by devicenul1 Path Finder in Splunk Search 10-10-2014
0 7
0
7
herve1
This is an eval-based macro to be used before the first | macro definition: if($Id$=="", " ", " LOGIN_NAME=$Id$ ") I...
by herve1 Engager in Splunk Search 10-10-2014
0 1
0
1
thisissplunk
Hello All, I'm using a lookup table which includes of a bunch of IPs. I use this as a blacklist to search through my...
by thisissplunk Builder in Splunk Search 10-09-2014
2 5
2
5
dhavamanis
we have user registered data with zipcode, can you please tell us, how to build the map chart using the zipcode.
by dhavamanis Builder in Splunk Search 10-09-2014
0 3
0
3
dhavamanis
We are trying to build the MAP with the query below. I can see some results in the statistics view but nothing is sho...
by dhavamanis Builder in Splunk Search 10-09-2014
0 4
0
4
merethhe
I'm performing a very simple search: type="Workflow model" | top 20 org My problem is, the number of events does no...
by merethhe Engager in Splunk Search 10-09-2014
0 2
0
2
hortonew
I have logs that I'm trying to analyze and get the daily average latency per URL. I'll provide a sample log, and wha...
by hortonew Builder in Splunk Search 10-09-2014
0 2
0
2
ben_leung
Example data: From: To: 1. www.google.com www.google.com/123 2. www.yahoo.com www.yahoo...
by ben_leung Builder in Splunk Search 10-09-2014
1 1
1
1
vzzbrs
I'm trying to set hostnames extracting them from filenames I'm using host_regex with this regex: host_regex = (myse...
by vzzbrs Explorer in Splunk Search 10-09-2014
1 5
1
5
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...