Splunk Search

Splunk Search
Community Activity
jravida
Hi folks, I'll do my best to explain this. I'll use cars as an analogy because it is easier to explain: In my data s...
by jravida Communicator in Splunk Search 06-20-2014
0 2
0
2
dgillam
I have mail processing log lines I need to combine and report on. One type of log line contains strings like "clon...
by dgillam Engager in Splunk Search 06-20-2014
0 12
0
12
bruceclarke
Hey all, I have a search that uses the map command. It looks like: <myBaseSearch> | map [search index=main sourcety...
by bruceclarke Contributor in Splunk Search 06-20-2014
0 3
0
3
ericrobinson
My field in the events is as follows UserFullName=Lastname, Firstname , I know that I can use a regex to extract th...
by ericrobinson Path Finder in Splunk Search 06-20-2014
0 3
0
3
MichaelCohen829
Splunk Community, I’d like to be able to count the number of events I have per SourceFile when my sourcetype is LogF...
by MichaelCohen829 Explorer in Splunk Search 06-20-2014
0 4
0
4
Mubarish
There is a log file which has events in the following format 0|10|434d5532|xxxxxx34|2014/06/06 04:47:54|819670|3|2014...
by Mubarish Path Finder in Splunk Search 06-20-2014
0 1
0
1
alekksi
Hi all, I'm having difficulty trying to create a total_cpu field. If I map a single variable to it, this works fine ...
by alekksi Communicator in Splunk Search 06-20-2014
0 2
0
2
hartfoml
I can write a search like this: | dbquery "DB1" "SELECT A.* AOS.* FROM Assets A JOIN AssetOSs AOS ON A.AssetOSID = A...
by hartfoml Motivator in Splunk Search 06-20-2014
0 5
0
5
thambisetty
Hi [index=main host=syslog status="deny"| top src_IP | table src_IP ]:::::this is my sub search. and it will produce ...
by SplunkTrust SplunkTrust in Splunk Search 06-19-2014
0 6
0
6
stwong
Hi, we're trying to find out windows XP users with some rules: if mod=syn, get client ip (cli)if mod=syn+ack, get se...
by stwong Communicator in Splunk Search 06-19-2014
0 6
0
6
dkichline
I am attempting to perform a search time field extraction via the rex command. I use the default field of _raw and g...
by dkichline Engager in Splunk Search 06-19-2014
0 3
0
3
proletariat99
This is a recurring problem for me in SPL. I want to assign some stats command results to a variable name and pop th...
by proletariat99 Communicator in Splunk Search 06-19-2014
0 1
0
1
robf
i have 50 indexes and i want to find out the last most recent event for each host in each index. i can do this for e...
by robf Path Finder in Splunk Search 06-19-2014
1 6
1
6
thambisetty
HI, I have data like below, Source_Address Event_Code Time User 10.10.10.010 4625 6/17/2014 0...
by SplunkTrust SplunkTrust in Splunk Search 06-19-2014
0 14
0
14
kundeng
Hi, I have a query that is meant to compare longitudinal count of an event of a given day (e.g. today) with historic...
by kundeng Path Finder in Splunk Search 06-19-2014
0 3
0
3
gajananh999
Dear All, I have oracle error data i need to extract some fields from it here is the data [EntID: ] 17-Jun-2014, 07...
by gajananh999 Contributor in Splunk Search 06-19-2014
0 6
0
6
splunker12er
In the below stanzas , both are having same source-type names, how the priority will be in assigning sourcetype? Has...
by splunker12er Motivator in Splunk Search 06-19-2014
0 1
0
1
ayenumula
Search query: list the last known user (userid) on each host. sourcetype=syslog source=/var/log/secure "pam_unix(ssh...
by ayenumula Explorer in Splunk Search 06-18-2014
2 4
2
4
guilmxm
Hi, I am in great troubles with a multilines events i'm trying to analyse, and associated required regex to extract ...
by guilmxm Influencer in Splunk Search 06-18-2014
0 8
0
8
pfernandez133
Hey guys, is it possible to run an eval function in the search bar without piping a search to it? In an attempt to t...
by pfernandez133 Explorer in Splunk Search 06-18-2014
0 4
0
4
fziegler
I'm using splunk 6.0.3 When I search for: "has been closed after being in use" I have a series of hits like shown i...
by fziegler New Member in Splunk Search 06-18-2014
0 2
0
2
ateterine
I will try my best to formulate my question as I couldn't find anything similar asked already. I am trying to displa...
by ateterine Path Finder in Splunk Search 06-18-2014
0 9
0
9
bruceclarke
All, I want to create a search that will return the count of events over the last 5 minutes, 30 minutes, hour, 6 hou...
by bruceclarke Contributor in Splunk Search 06-18-2014
1 4
1
4
DanielFordWA
Hi, I have a request to trend new users on a web application by month over a two year period and produce this report...
by DanielFordWA Contributor in Splunk Search 06-18-2014
0 2
0
2
splunk_worker
Hi All Here are my sample logs _time prod-server-1234 web_access 10.11.12.13 "GET /json/some_search?asasa HTTP/1.1" ...
by splunk_worker Path Finder in Splunk Search 06-18-2014
1 2
1
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...