Splunk Search

Splunk Search
Community Activity
HeinzWaescher
Hello, I'm running a dbquery and would like to save the results as a lookuptable.csv. | dbquery mysearch | outputlo...
by HeinzWaescher Motivator in Splunk Search 06-04-2014
0 5
0
5
desertpilotjc
I have a situation where I want to report on events from 2 sets of servers where i can compare the aggregate counts. ...
by desertpilotjc Explorer in Splunk Search 06-03-2014
0 1
0
1
boris
iplocation bug? "UNKNOWN COUNTRY" is returned for ip addresses that actually have a known country? USA 208.65.40.98...
by boris Path Finder in Splunk Search 06-03-2014
0 4
0
4
xvxt006
Hi, I have below variations of uri patterns for a particular functionality. i want to list out query string paramete...
by xvxt006 Contributor in Splunk Search 06-03-2014
0 4
0
4
_gkollias
I have a search that monitor's failed PO's. Essentially the idea is to monitor the overall state of the txn, and whe...
by _gkollias Builder in Splunk Search 06-03-2014
0 2
0
2
naveenurs
Hello, I am trying to parse a field like the one below into an array of Key/Value pairs and access each array value ...
by naveenurs Explorer in Splunk Search 06-03-2014
0 2
0
2
kmattern
I have two Splunk instances, a development and a test platform. Can I have them both pointing to the same indexer wit...
by kmattern Builder in Splunk Search 06-03-2014
0 7
0
7
Sqig
Hi. For some events in a particular index, users (including Admins) are getting an error of "Show Source not availab...
by Sqig Path Finder in Splunk Search 06-03-2014
0 3
0
3
aferone
In my local limits.conf file, on my Search Head, I have the following: [searchresults] maxresultrows = 100000 [s...
by aferone Builder in Splunk Search 06-03-2014
1 5
1
5
mvaradarajam
Hi All, whenever i am trying to search the query,i am getting following error. Splunkd daemon is not responding: ('...
by mvaradarajam Path Finder in Splunk Search 06-03-2014
0 1
0
1
Pierceyuk
Hey All, So i have some web logs, lets call them source type 'webbylogs'. If I search 'sourcetype=webbylogs | extrac...
by Pierceyuk Path Finder in Splunk Search 06-03-2014
0 4
0
4
isaacyeo
Hello, This is my input.conf on the iis server: [monitor://D:\IISLogs\W3SVC2] index=iis_db sourcetype=iis However,...
by isaacyeo Engager in Splunk Search 06-02-2014
0 8
0
8
johnoxley_liqui
I am have the following stanza in my inputs.conf. [dbmon-tail://DB/TABLE] interval = 1m query = SELECT SL_UID,SL_TIM...
by johnoxley_liqui Engager in Splunk Search 06-02-2014
1 1
1
1
adityapavan18
In my dashboard, it loads data into a table with 4 columns Now what i require is to drill down to Dashboard1 if any ...
by adityapavan18 Contributor in Splunk Search 06-02-2014
1 2
1
2
harshal_chakran
Hi, Following is the advance xml code, where I have defined a search command in a postprocess module and want to pas...
by harshal_chakran Builder in Splunk Search 06-02-2014
0 3
0
3
bbegyperkspot
When I search in the search application, my search terms are starting to appear in subsequent searches. So search fo...
by bbegyperkspot Explorer in Splunk Search 06-02-2014
1 5
1
5
mgubser
So I have three sources that i need to join together to view as one event. The three sources are NewWFL, MoneyNEW, an...
by mgubser Explorer in Splunk Search 06-02-2014
0 5
0
5
essklau
Hi, I have a search which returns 37 results for one date (May 30), but 0 results for May 30-Jun2. I am failing to...
by essklau Path Finder in Splunk Search 06-02-2014
0 3
0
3
hagjos43
Hello, I have the following query: . . . | iplocation ClientIP | eval GeoLocation=case(Country="United States", "...
by hagjos43 Contributor in Splunk Search 06-02-2014
0 1
0
1
nikekeen
Our deployed application services have a static deployment name of this format: {service name}-{environment}-{the r...
by nikekeen New Member in Splunk Search 06-02-2014
0 2
0
2
TechnicalRS
I have VPN access connect/disconnect events from a Meraki security appliance being fed into Splunk. They show up in S...
by TechnicalRS Engager in Splunk Search 06-02-2014
0 3
0
3
ch_goh
This rex statement works in search command: rex field=source "3......(?P.+?)rly" I would like to convert it into REGE...
by ch_goh Explorer in Splunk Search 06-02-2014
0 3
0
3
xvxt006
Hi, i want to extract account field and i have events in 2 patterns. One where account has boundaries of @account= ...
by xvxt006 Contributor in Splunk Search 06-02-2014
0 4
0
4
baranova
Hello guys , I kinda need your help , i spend some time on this query and i don't really see how to do that ( tried...
by baranova New Member in Splunk Search 06-02-2014
0 2
0
2
jodros
I have two scheduled searches that each output a single numerical value to populate panels on a dashboard. I want to...
by jodros Builder in Splunk Search 06-02-2014
2 3
2
3
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors