Splunk Search

Splunk Search
Community Activity
ayenumula
Search query: list the last known user (userid) on each host. sourcetype=syslog source=/var/log/secure "pam_unix(ssh...
by ayenumula Explorer in Splunk Search 06-18-2014
2 4
2
4
guilmxm
Hi, I am in great troubles with a multilines events i'm trying to analyse, and associated required regex to extract ...
by guilmxm Influencer in Splunk Search 06-18-2014
0 8
0
8
pfernandez133
Hey guys, is it possible to run an eval function in the search bar without piping a search to it? In an attempt to t...
by pfernandez133 Explorer in Splunk Search 06-18-2014
0 4
0
4
fziegler
I'm using splunk 6.0.3 When I search for: "has been closed after being in use" I have a series of hits like shown i...
by fziegler New Member in Splunk Search 06-18-2014
0 2
0
2
ateterine
I will try my best to formulate my question as I couldn't find anything similar asked already. I am trying to displa...
by ateterine Path Finder in Splunk Search 06-18-2014
0 9
0
9
bruceclarke
All, I want to create a search that will return the count of events over the last 5 minutes, 30 minutes, hour, 6 hou...
by bruceclarke Contributor in Splunk Search 06-18-2014
1 4
1
4
DanielFordWA
Hi, I have a request to trend new users on a web application by month over a two year period and produce this report...
by DanielFordWA Contributor in Splunk Search 06-18-2014
0 2
0
2
splunk_worker
Hi All Here are my sample logs _time prod-server-1234 web_access 10.11.12.13 "GET /json/some_search?asasa HTTP/1.1" ...
by splunk_worker Path Finder in Splunk Search 06-18-2014
1 2
1
2
ejpulsar
Hi, i'm using splunk 6.1.1 I made this si- search and scheduled it to run "every hour" at period -1h@m to "now" .. ...
by ejpulsar Path Finder in Splunk Search 06-18-2014
0 6
0
6
letharion
I'm trying to do "[Simple text search]" | top limit=50 count To so the 50 highest occurrences of my search for whi...
by letharion Engager in Splunk Search 06-18-2014
0 1
0
1
ahogbin
Hello I am running the following search with the end aim of using the 'map' functionality to plot the results but wh...
by ahogbin Communicator in Splunk Search 06-17-2014
0 1
0
1
webnair
How to rename the _time to TIME in the below query: |inputlookup currentesdorders.csv | dedup ORDER_NUMBER | where O...
by webnair Explorer in Splunk Search 06-17-2014
2 3
2
3
millie
Hi! I would like to draw a chart with stacked bars , but I don't know how to add columns depend on result. for exampl...
by millie Engager in Splunk Search 06-17-2014
1 2
1
2
AppServices
Hi, We are trying to limit the maxKBps of a couple forwarders to 30 KBps. We are doing this because the app on those ...
by AppServices Explorer in Splunk Search 06-17-2014
1 7
1
7
xvxt006
Hi, I saw that there is dc so we can get the distinct count but what if I want to get the sum for unique field value...
by xvxt006 Contributor in Splunk Search 06-17-2014
1 2
1
2
chrmcq
How do I specify a minimum width for columns in a column chart? The documentation very usefully says columnStyle sty...
by chrmcq Explorer in Splunk Search 06-17-2014
2 9
2
9
soundchaos
I am trying to get a search result that shows a single IP associated with all of its user agents, but I would like th...
by soundchaos Path Finder in Splunk Search 06-17-2014
1 5
1
5
stwong
Hi all, can I return fields from subsearch but not used as filter in outer sesarch? Assuming the log1 contains fiel...
by stwong Communicator in Splunk Search 06-17-2014
0 1
0
1
guilmxm
Hi, I have data indexed with variable fields (csv data indexed as csv by Splunk) such as: timestamp device1 device2...
by guilmxm Influencer in Splunk Search 06-17-2014
1 10
1
10
suhprano
sendemail command limits to 10k events. This number makes my automates search emails imcomplete. Is there anywhere I ...
by suhprano Path Finder in Splunk Search 06-17-2014
4 7
4
7
sloshburch
I've discovered that if you have newlines in a stats command in a savedsearch like this: | stats values(blah), lis...
by sloshburch Ultra Champion in Splunk Search 06-17-2014
1 1
1
1
somu2014
we have two log files one is ids logs and another is waf we want to check for source address which are common in bot...
by somu2014 New Member in Splunk Search 06-17-2014
0 1
0
1
somu2014
hiii we are having waf and ids the ip passes from ids and waf so i need to correlate the ip address and name fields ...
by somu2014 New Member in Splunk Search 06-17-2014
0 3
0
3
uayub
The above warning message is displayed in th GUI with the following error message: [JobManager module] Splunkd daemo...
by uayub Path Finder in Splunk Search 06-17-2014
0 2
0
2
hyahmadi
hello, I want to search proxy logs for 2 different area of ip address ? (like from x.x.x.x to y.y.y.y and from x1.x...
by hyahmadi Explorer in Splunk Search 06-17-2014
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...