Splunk Search

Splunk Search
Community Activity
sadkha
Hi All, In my scenario, I have a batch of events that are for a particular Event Code, sorted by time. The fields ...
by sadkha Path Finder in Splunk Search 08-28-2014
0 6
0
6
NaorPenso
Hi Everyone, I have a need to create a delta between the count of id today to the count of id yesterday search: searc...
by NaorPenso Explorer in Splunk Search 08-27-2014
1 3
1
3
jkat54
index="test" host="*P*" "Type=Error" |eval Code = if(EventCode="10034","Access Denied",if(EventCode="5749","Port Tim...
by SplunkTrust SplunkTrust in Splunk Search 08-27-2014
0 2
0
2
Ronvgraham
I would like to be able to create/run a report that would show me the hosts, sourcetypes for each host, and the sourc...
by Ronvgraham Engager in Splunk Search 08-27-2014
0 2
0
2
jdbtee
Hi, I want to create a new field, from a string, showing the domain user, where the only constant is "\" which I don...
by jdbtee Path Finder in Splunk Search 08-27-2014
0 5
0
5
dhavamanis
We have created new sourcetype (acquia_access_combined) by coping the existing sourcetype (access_combined) and added...
by dhavamanis Builder in Splunk Search 08-27-2014
1 4
1
4
fschiavo
I want to add cer device type to the following string to search for both. Boolean expression? index=cisco cdnt* part...
by fschiavo New Member in Splunk Search 08-27-2014
0 2
0
2
xbbj3nj
How do I lookup for a field which has Or condition. example Source Destination File name act bank indexes_...
by xbbj3nj Path Finder in Splunk Search 08-27-2014
0 1
0
1
pradeepkumarg
I have a field which has leading 0's before the actual value. How can I get rid of them. Possible Values 0000000040...
by pradeepkumarg Influencer in Splunk Search 08-27-2014
0 1
0
1
alexl1
hi, how do I search for asterisk C asterisk in splunk, in other words C when I put that as the search criteria it re...
by alexl1 Path Finder in Splunk Search 08-27-2014
0 6
0
6
ApurvaB
I am using Splunk forwarder to receive log files from multiple monitors. I need to filter events, based on a regex, f...
by ApurvaB Engager in Splunk Search 08-27-2014
0 3
0
3
mookiie2005
ERROR ProcessDispatchedSearch - PROCESS_SEARCH "XXX": The process cannot access the file because it is being used by ...
by mookiie2005 Communicator in Splunk Search 08-27-2014
2 2
2
2
HeinzWaescher
Hi, is it possible to use a column header for a lookup? Let's say that we have a csv like this: Date | A | B 01.0...
by HeinzWaescher Motivator in Splunk Search 08-27-2014
0 5
0
5
sadkha
Hi All, I am using a transaction command to group log data by Account Name. I'm particularly interested in any acco...
by sadkha Path Finder in Splunk Search 08-27-2014
0 9
0
9
jbouch03
I have created a dashboard that uses a drop down menu to populate the data for a search using Django bindings. I know...
by jbouch03 Path Finder in Splunk Search 08-27-2014
0 2
0
2
ThomasLeroy
Hello, I would like to extract bing and yahoo search from my proxySG logs. i have this for yahoo search search ya...
by ThomasLeroy Explorer in Splunk Search 08-27-2014
1 3
1
3
garypark
In my logs I have a lot of java errors that are about 100 lines long. I would like to filter the event at the univers...
by garypark New Member in Splunk Search 08-26-2014
0 1
0
1
juniormint
My goal is to get information on a list of processes. I think WMI is a decent way to do this, but keep getting a syn...
by juniormint Communicator in Splunk Search 08-26-2014
0 3
0
3
sanjay_shrestha
Hi, I created dblookup and used in a saved search as admin, which is working fine. However when I run same saved sea...
by sanjay_shrestha Contributor in Splunk Search 08-26-2014
0 9
0
9
pparkerntx99
I am attempting to get the LoginCount of REQUESTING_IP grouping the REQUESTING_IP's together over a 7 day period in...
by pparkerntx99 Explorer in Splunk Search 08-26-2014
0 3
0
3
pavan_bhumanapa
We have a scenario where we have many domains and we want to split it accordingly . Any advice would be great help . ...
by pavan_bhumanapa New Member in Splunk Search 08-26-2014
0 4
0
4
pollockm
I'm working to deploy Splunk in an HPC environment and am trying to set up some metrics queries that I didn't see in ...
by pollockm Engager in Splunk Search 08-26-2014
0 8
0
8
locguero
Hello. I am new to splunk and regex so please bear with me. I have the following log file format iNRPMPLANTCD: AR| ...
by locguero Engager in Splunk Search 08-26-2014
1 2
1
2
chriscje
I've been looking around the forums, but nothing seems to quite cover what I need. We are currently logging stats fo...
by chriscje New Member in Splunk Search 08-26-2014
0 3
0
3
xvxt006
Hi, I have 2 data points and i would like to show one as line and other one as column chart. is it possible? any sug...
by xvxt006 Contributor in Splunk Search 08-26-2014
0 2
0
2
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Solution Authors