Splunk Search

Splunk Search
Community Activity
splunkbeginner2
Hello, I wanted to take a look at some data with splunk, as I was suddenly very surprised by its form. splunks show...
by splunkbeginner2 Path Finder in Splunk Search 07-07-2014
0 2
0
2
mvaradarajam
I want to put symbols against the values in a column. I have different ranges for different rows. eg. : 1st row : ran...
by mvaradarajam Path Finder in Splunk Search 07-07-2014
0 2
0
2
pritamkumar01
my data for buffer use for a particular time is: 00:00:04: port 1, buffer 12221, 00:00:04: port 2, buffer 22, 00:00:0...
by pritamkumar01 Engager in Splunk Search 07-07-2014
0 2
0
2
charles981
I have a webserver log with one entry per request. Every entry contains the used cipher. I want to generate a chart o...
by charles981 Engager in Splunk Search 07-07-2014
1 2
1
2
Mag2sub
Im using a metadata type=hosts query to output hosts that have not logged data using recenttime However i dont see th...
by Mag2sub Path Finder in Splunk Search 07-07-2014
1 13
1
13
Mag2sub
On 5.0.4 ...appreciate suggestions on performance conducive query to output hosts not logging to index with index nam...
by Mag2sub Path Finder in Splunk Search 07-07-2014
0 5
0
5
irfy
I have the following three different types of logs coming into a single source-type <189>Jul 06 15:38:54|100.888.94....
by irfy New Member in Splunk Search 07-06-2014
0 1
0
1
jagadish85
I want to extract the previous line if found a matching string in an event. for Eg in an event : 4XESTACKTRACE ...
by jagadish85 Path Finder in Splunk Search 07-04-2014
0 1
0
1
yuan_ka
I created a dashboard with inline searches. Why can't other users see any results, even users in the same Admin group...
by yuan_ka Explorer in Splunk Search 07-04-2014
1 4
1
4
takemusu
I have the following search query: source=*Src some_filtering | ... | timechart span=5m max(ActCnt) by source that...
by takemusu Explorer in Splunk Search 07-03-2014
0 3
0
3
uayub
The following events are filtered by Snare and sent to Splunk from Windows Servers: Server.egcorp.com MSWinEventLo...
by uayub Path Finder in Splunk Search 07-03-2014
0 16
0
16
cbs01
We are successfully ingesting Websense logs into Splunk but the user field is recorded in LDAP context and has spaces...
by cbs01 Engager in Splunk Search 07-03-2014
0 1
0
1
matthewhaswell
I have a query that provides windows startup, ending and duration - however I was looking for a way to graph this? T...
by matthewhaswell Path Finder in Splunk Search 07-03-2014
0 1
0
1
echojacques
So I have this basic search for a line graph visualization: (search goes here) | timechart count Let's say I've ha...
by echojacques Builder in Splunk Search 07-03-2014
0 9
0
9
jravida
Hi folks, I'm trying to merge events that share a common keyword value, with the mvcombine. The problem is it just l...
by jravida Communicator in Splunk Search 07-03-2014
0 1
0
1
dreamwork801
So I'm running this search string here: index = git | rename Data.payload.head_commit.modified{} as FilesModified | ...
by dreamwork801 Path Finder in Splunk Search 07-03-2014
0 2
0
2
caroline_fortun
Hello everyone, I´m trying to filter some Windows Security Event Logs that contains the machine name as the username...
by caroline_fortun Explorer in Splunk Search 07-03-2014
0 4
0
4
geoffmartin
I'm trying to produce a multivalue field out of another multivalue field in my data model, and that's proven to be qu...
by geoffmartin Engager in Splunk Search 07-03-2014
0 1
0
1
sergeyvinnik
Anybody can answer to simple question? How to remove from indexing host= d:\TEST.log just "<TD>" combination? What sh...
by sergeyvinnik Explorer in Splunk Search 07-03-2014
0 3
0
3
yuanliu
My Splunk is 5.0.5. I constructed a rex to extract user from free-hand logs. In some logs, user is null. This skew...
by SplunkTrust SplunkTrust in Splunk Search 07-03-2014
0 9
0
9
albyva
Is it possible to add a comment field in a Macro so that it is displayed in a search? For example, if a macro contain...
by albyva Communicator in Splunk Search 07-03-2014
0 1
0
1
splunker12er
How does the results of the correlation events go to "notable" index ? Is there any configuration file for this ? Al...
by splunker12er Motivator in Splunk Search 07-03-2014
0 1
0
1
jlhamlet
Hi, I have a proxy log that logs the time the query was executed and also give the duration in seconds. "11/Jan/201...
by jlhamlet Path Finder in Splunk Search 07-03-2014
0 3
0
3
Bliide
Hello, I am trying to extract a field and I have an error in my REGEX. The line looks like this: 6/26/2014 13:00:1...
by Bliide Path Finder in Splunk Search 07-03-2014
1 5
1
5
RicoSuave
As a splunk user, i want to find the most common events in my search results. How would I accomplish this? I am tryin...
by RicoSuave Builder in Splunk Search 07-02-2014
2 2
2
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...