Splunk Search

Splunk Search
Community Activity
digital_alchemy
I currently have a search that kinda works for what I need but it returns a lot of false positives. Example: Say I ...
by digital_alchemy Path Finder in Splunk Search 07-30-2014
1 3
1
3
iabreu
Hello Splunkers, I need a little help to exclude similar values at the same field in a search: ....| search Comput...
by iabreu New Member in Splunk Search 07-30-2014
0 6
0
6
david_rundle_fi
I would like to extract and store data in a new fields so that I don't have to define a conditional statement each ti...
by david_rundle_fi Explorer in Splunk Search 07-30-2014
0 10
0
10
edookati
I am currently using the below query... index=a field1="ABC" | join id [Search index=a AND (field2="B" OR field2="C" ...
by edookati Path Finder in Splunk Search 07-30-2014
0 1
0
1
jedatt01
I'm trying to extract a string in a field that spans multiple lines. See example below. 03/09/2014 07:10:38 AM - Pro...
by jedatt01 Builder in Splunk Search 07-30-2014
1 5
1
5
RagtimeWilly
I have a large amount of logs in the following format: 2014-07-30 14:23:51,802 - MyApp - 6 - INFO - Performance - pr...
by RagtimeWilly Explorer in Splunk Search 07-30-2014
1 6
1
6
jlacal
Howdy: I'm a new Splunker so this may be a dumb question. I have looked around splunk>Answers and couldn't find a sol...
by jlacal Explorer in Splunk Search 07-30-2014
0 1
0
1
mjmcloughlin
Hey, I'm looking for a little advice. I'm trying to produce a report showing how many events of a particular type (w...
by mjmcloughlin Engager in Splunk Search 07-30-2014
1 2
1
2
rolaso
Hi everyone, I am trying to find a way count the lines inside a lookup table and pass it to the return command. For...
by rolaso Explorer in Splunk Search 07-30-2014
1 2
1
2
zliu
Below is the transforms.conf at $SPLUNK_HOME/etc/local: [test_lookup] filename=test.csv And I uploaded test.csv (a...
by zliu Splunk Employee Splunk Employee in Splunk Search 07-29-2014
5 2
5
2
dreamwork801
I want my users to be able to chose a file extension from a drop down that is populated with a search. I was thinking...
by dreamwork801 Path Finder in Splunk Search 07-29-2014
1 5
1
5
sethuk555
Hi, I need to find the transaction time between these 2 statements which has same startswith Log strings(different e...
by sethuk555 Engager in Splunk Search 07-29-2014
0 1
0
1
lbogle
Hello Splunkers, I'm processing results of an asset database search. I have one database that is the 'reference' data...
by lbogle Contributor in Splunk Search 07-29-2014
0 5
0
5
jlkokko
What is the proper command/syntax to specify a day of the week for searching (converting date/timestamp)? example: i...
by jlkokko Path Finder in Splunk Search 07-29-2014
1 7
1
7
EricLloyd79
I am feeling more and more like the new Pivot UI functionality is way too limiting. Can anyone help me to do a query ...
by EricLloyd79 Builder in Splunk Search 07-29-2014
0 2
0
2
edookati
I am using the below query to join 2 searches, but the table is showing me duplicate rows with only common_fields and...
by edookati Path Finder in Splunk Search 07-28-2014
1 4
1
4
lbogle
Hello Splunkers, I feel like I have the most basic of questions here but I can't get it to work. I have a .csv log fi...
by lbogle Contributor in Splunk Search 07-28-2014
1 2
1
2
dabunn
I have sendmail logs which have an action field which can be DELIVER, DROP or QUARANTINE. What I am trying to do is ...
by dabunn Engager in Splunk Search 07-28-2014
1 3
1
3
dlespron
I know I must be missing something simple and have searched here trying multiple things but still can't get this to w...
by dlespron Path Finder in Splunk Search 07-28-2014
1 1
1
1
Thuan
I am trying to feed Arcsight with the results of a Splunk search using the real time output app. I get the following...
by Thuan Explorer in Splunk Search 07-28-2014
0 1
0
1
ezajac
How can I create a field extraction to modify a key in a key value pair? I have a new file that I am indexing. The ke...
by ezajac Path Finder in Splunk Search 07-28-2014
0 3
0
3
JoeSco27
I am working in a single node environment (indexer is also deployment-server)and I am having trouble determining why ...
by JoeSco27 Communicator in Splunk Search 07-28-2014
0 3
0
3
LordVoldemort
This issue continually bites me and there's something I'm just not understanding. If I search like so: sourcetype=...
by LordVoldemort Explorer in Splunk Search 07-28-2014
0 5
0
5
TBo123
Hello, I hope there is someone who can help me solve this problem. I'd like to know how to group events shown as fo...
by TBo123 Path Finder in Splunk Search 07-28-2014
1 2
1
2
shangshin
Hi, I get the user_id info from web log and would like to enrich data from the connected DB in Splunk. I tried the...
by shangshin Builder in Splunk Search 07-28-2014
1 5
1
5
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...