Splunk Search

Splunk Search
Community Activity
jtrucks
Is there a way to set a max size on the entire tsidxstats or even a single set of tsidxstats? I have the Splunk for ...
by jtrucks Splunk Employee Splunk Employee in Splunk Search 06-06-2014
3 2
3
2
HeinzWaescher
Hi, I've got some fieldvalues like this: field=aaaaaaaabbbbccccddddeeeeeeeeeeee I would like to add a "-" after c...
by HeinzWaescher Motivator in Splunk Search 06-06-2014
0 2
0
2
redc
I've set up a database lookup, but it's not returning any results; it should be returning 5 events. Here are the sce...
by redc Builder in Splunk Search 06-05-2014
0 2
0
2
mfrost8
A user has asked me if they can take a chart they just generated in Splunk and then send it to other users who don't ...
by mfrost8 Builder in Splunk Search 06-05-2014
2 8
2
8
Dimitri_McKay
Wondering if it's possible to embed a macro into another macro.
by Dimitri_McKay Splunk Employee Splunk Employee in Splunk Search 06-05-2014
0 2
0
2
Bliide
New Splunk user. I am creating web dashboards and I want to calculate the percentage of successful status codes. Th...
by Bliide Path Finder in Splunk Search 06-05-2014
0 2
0
2
mmouse88
I have a created a table using timechart with the max #. It generates a row of maximum of sourcetype. How would I r...
by mmouse88 Path Finder in Splunk Search 06-04-2014
0 16
0
16
the_wolverine
Is there a search that I can run at the indexer that will tell me what versions my forwarders are on?
by the_wolverine Champion in Splunk Search 06-04-2014
4 4
4
4
jheney
I have a single numeric field that I want to timechart in ranges...i.e. rangemap the field into custom buckets, then ...
by jheney New Member in Splunk Search 06-04-2014
0 1
0
1
redc
I'm attempting to create my first database lookup. I followed this documentation, choosing to specify the fields dir...
by redc Builder in Splunk Search 06-04-2014
0 2
0
2
pitshot
Using Splunk v 5.04 I have a lookup table containing devicename,interfacename,speed . Each device name can have mul...
by pitshot Explorer in Splunk Search 06-04-2014
0 3
0
3
EricLloyd79
I have a query that works when I run it with a time range under 4 hours but anything at 4 hours or over, I get this e...
by EricLloyd79 Builder in Splunk Search 06-04-2014
0 6
0
6
brywilk_umich
Hello I have the below search and it seems to work fine for the most part. The problem is that if search 2 does no...
by brywilk_umich Path Finder in Splunk Search 06-04-2014
0 4
0
4
atewari
We would like to access Splunk Web from other hosts. We did a full splunk 5.0.1 (build: 143156) install on a Windows...
by atewari Path Finder in Splunk Search 06-04-2014
0 8
0
8
nlapier2
I have data that contains a field with dates and times formatted as such: "5/18/14 7:04:04.000 PM". The date part is ...
by nlapier2 Path Finder in Splunk Search 06-04-2014
0 1
0
1
thommck
I've been trying to use the field extractor to get some useful data from my Sophos Anti-virus scan log. Unfortunately...
by thommck New Member in Splunk Search 06-04-2014
0 5
0
5
HeinzWaescher
Hello, I'm running a dbquery and would like to save the results as a lookuptable.csv. | dbquery mysearch | outputlo...
by HeinzWaescher Motivator in Splunk Search 06-04-2014
0 5
0
5
desertpilotjc
I have a situation where I want to report on events from 2 sets of servers where i can compare the aggregate counts. ...
by desertpilotjc Explorer in Splunk Search 06-03-2014
0 1
0
1
boris
iplocation bug? "UNKNOWN COUNTRY" is returned for ip addresses that actually have a known country? USA 208.65.40.98...
by boris Path Finder in Splunk Search 06-03-2014
0 4
0
4
xvxt006
Hi, I have below variations of uri patterns for a particular functionality. i want to list out query string paramete...
by xvxt006 Contributor in Splunk Search 06-03-2014
0 4
0
4
_gkollias
I have a search that monitor's failed PO's. Essentially the idea is to monitor the overall state of the txn, and whe...
by _gkollias Builder in Splunk Search 06-03-2014
0 2
0
2
naveenurs
Hello, I am trying to parse a field like the one below into an array of Key/Value pairs and access each array value ...
by naveenurs Explorer in Splunk Search 06-03-2014
0 2
0
2
kmattern
I have two Splunk instances, a development and a test platform. Can I have them both pointing to the same indexer wit...
by kmattern Builder in Splunk Search 06-03-2014
0 7
0
7
Sqig
Hi. For some events in a particular index, users (including Admins) are getting an error of "Show Source not availab...
by Sqig Path Finder in Splunk Search 06-03-2014
0 3
0
3
aferone
In my local limits.conf file, on my Search Head, I have the following: [searchresults] maxresultrows = 100000 [s...
by aferone Builder in Splunk Search 06-03-2014
1 5
1
5
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors