Thread Info | |||||
---|---|---|---|---|---|
Splunk Community,
I’d like to be able to count the number of events I have per SourceFile when my sourcetype is Lo...
by
MichaelCohen829
Explorer
in
Splunk Search
06-19-2014
|
0
|
4
| |||
There is a log file which has events in the following format 0|10|434d5532|xxxxxx34|2014/06/06 04:47:54|819670|3|2014...
by
Mubarish
Path Finder
in
Splunk Search
06-20-2014
|
0
|
1
| |||
Hi all,
I'm having difficulty trying to create a total_cpu field. If I map a single variable to it, this works fin...
by
alekksi
Communicator
in
Splunk Search
06-20-2014
|
0
|
2
| |||
I can write a search like this:
| dbquery "DB1" "SELECT A.* AOS.* FROM Assets A JOIN AssetOSs AOS ON A.AssetOSID =...
by
hartfoml
Motivator
in
Splunk Search
06-19-2014
|
0
|
5
| |||
Hi [index=main host=syslog status="deny"| top src_IP | table src_IP ]:::::this is my sub search. and it will produce ...
by
thambisetty
SplunkTrust
in
Splunk Search
06-19-2014
|
0
|
6
| |||
Hi, we're trying to find out windows XP users with some rules:
if mod=syn, get client ip (cli)if mod=syn+ack, get ...
by
stwong
Communicator
in
Splunk Search
06-17-2014
|
0
|
6
| |||
I am attempting to perform a search time field extraction via the rex command. I use the default field of _raw and gi...
by
dkichline
Engager
in
Splunk Search
06-19-2014
|
0
|
3
| |||
This is a recurring problem for me in SPL. I want to assign some stats command results to a variable name and pop tha...
by
proletariat99
Communicator
in
Splunk Search
06-19-2014
|
0
|
1
| |||
i have 50 indexes and i want to find out the last most recent event for each host in each index.
i can do this for...
by
robf
Path Finder
in
Splunk Search
06-16-2014
|
1
|
6
| |||
HI, I have data like below, Source_Address Event_Code Time User 10.10.10.010 4625 6/17/2014 00:12:26 Balaji 10.10.10....
by
thambisetty
SplunkTrust
in
Splunk Search
06-17-2014
|
0
|
14
| |||
Hi, I have a query that is meant to compare longitudinal count of an event of a given day (e.g. today) with historica...
by
kundeng
Path Finder
in
Splunk Search
06-13-2014
|
0
|
3
| |||
Dear All,
I have oracle error data i need to extract some fields from it here is the data
[EntID: ] 17-Jun-2014...
by
gajananh999
Contributor
in
Splunk Search
06-19-2014
|
0
|
6
| |||
In the below stanzas , both are having same source-type names, how the priority will be in assigning sourcetype?
H...
by
splunker12er
Motivator
in
Splunk Search
06-19-2014
|
0
|
1
| |||
Search query: list the last known user (userid) on each host.
sourcetype=syslog source=/var/log/secure "pam_unix(s...
by
ayenumula
Explorer
in
Splunk Search
06-17-2014
|
2
|
4
| |||
Hi,
I am in great troubles with a multilines events i'm trying to analyse, and associated required regex to extrac...
by
guilmxm
Influencer
in
Splunk Search
06-12-2014
|
0
|
8
| |||
Hey guys, is it possible to run an eval function in the search bar without piping a search to it?
In an attempt to...
by
pfernandez133
Explorer
in
Splunk Search
06-18-2014
|
0
|
4
| |||
I'm using splunk 6.0.3
When I search for: "has been closed after being in use" I have a series of hits like shown ...
by
fziegler
New Member
in
Splunk Search
06-18-2014
|
0
|
2
| |||
I will try my best to formulate my question as I couldn't find anything similar asked already.
I am trying to disp...
by
ateterine
Path Finder
in
Splunk Search
06-16-2014
|
0
|
9
| |||
All,
I want to create a search that will return the count of events over the last 5 minutes, 30 minutes, hour, 6 h...
by
bruceclarke
Contributor
in
Splunk Search
06-18-2014
|
1
|
4
| |||
Hi,
I have a request to trend new users on a web application by month over a two year period and produce this repo...
by
DanielFordWA
Contributor
in
Splunk Search
06-13-2014
|
0
|
2
| |||
Hi All Here are my sample logs
_time prod-server-1234 web_access 10.11.12.13 "GET /json/some_search?asasa HTTP/1.1...
by
splunk_worker
Path Finder
in
Splunk Search
06-17-2014
|
1
|
2
| |||
Hi, i'm using splunk 6.1.1
I made this si- search and scheduled it to run "every hour" at period -1h@m to "now"
...
by
ejpulsar
Path Finder
in
Splunk Search
06-16-2014
|
0
|
6
| |||
I'm trying to do
"[Simple text search]" | top limit=50 count
To so the 50 highest occurrences of my search for...
by
letharion
Engager
in
Splunk Search
06-18-2014
|
0
|
1
| |||
Hello
I am running the following search with the end aim of using the 'map' functionality to plot the results but ...
by
ahogbin
Communicator
in
Splunk Search
06-17-2014
|
0
|
1
| |||
How to rename the _time to TIME in the below query:
|inputlookup currentesdorders.csv | dedup ORDER_NUMBER | where...
by
webnair
Explorer
in
Splunk Search
06-17-2014
|
2
|
3
|