Splunk Search

Splunk Search
Community Activity
atewari
We would like to access Splunk Web from other hosts. We did a full splunk 5.0.1 (build: 143156) install on a Windows...
by atewari Path Finder in Splunk Search 06-04-2014
0 8
0
8
nlapier2
I have data that contains a field with dates and times formatted as such: "5/18/14 7:04:04.000 PM". The date part is ...
by nlapier2 Path Finder in Splunk Search 06-04-2014
0 1
0
1
thommck
I've been trying to use the field extractor to get some useful data from my Sophos Anti-virus scan log. Unfortunately...
by thommck New Member in Splunk Search 06-04-2014
0 5
0
5
HeinzWaescher
Hello, I'm running a dbquery and would like to save the results as a lookuptable.csv. | dbquery mysearch | outputlo...
by HeinzWaescher Motivator in Splunk Search 06-04-2014
0 5
0
5
desertpilotjc
I have a situation where I want to report on events from 2 sets of servers where i can compare the aggregate counts. ...
by desertpilotjc Explorer in Splunk Search 06-03-2014
0 1
0
1
boris
iplocation bug? "UNKNOWN COUNTRY" is returned for ip addresses that actually have a known country? USA 208.65.40.98...
by boris Path Finder in Splunk Search 06-03-2014
0 4
0
4
xvxt006
Hi, I have below variations of uri patterns for a particular functionality. i want to list out query string paramete...
by xvxt006 Contributor in Splunk Search 06-03-2014
0 4
0
4
_gkollias
I have a search that monitor's failed PO's. Essentially the idea is to monitor the overall state of the txn, and whe...
by _gkollias Builder in Splunk Search 06-03-2014
0 2
0
2
naveenurs
Hello, I am trying to parse a field like the one below into an array of Key/Value pairs and access each array value ...
by naveenurs Explorer in Splunk Search 06-03-2014
0 2
0
2
kmattern
I have two Splunk instances, a development and a test platform. Can I have them both pointing to the same indexer wit...
by kmattern Builder in Splunk Search 06-03-2014
0 7
0
7
Sqig
Hi. For some events in a particular index, users (including Admins) are getting an error of "Show Source not availab...
by Sqig Path Finder in Splunk Search 06-03-2014
0 3
0
3
aferone
In my local limits.conf file, on my Search Head, I have the following: [searchresults] maxresultrows = 100000 [s...
by aferone Builder in Splunk Search 06-03-2014
1 5
1
5
mvaradarajam
Hi All, whenever i am trying to search the query,i am getting following error. Splunkd daemon is not responding: ('...
by mvaradarajam Path Finder in Splunk Search 06-03-2014
0 1
0
1
Pierceyuk
Hey All, So i have some web logs, lets call them source type 'webbylogs'. If I search 'sourcetype=webbylogs | extrac...
by Pierceyuk Path Finder in Splunk Search 06-03-2014
0 4
0
4
isaacyeo
Hello, This is my input.conf on the iis server: [monitor://D:\IISLogs\W3SVC2] index=iis_db sourcetype=iis However,...
by isaacyeo Engager in Splunk Search 06-02-2014
0 8
0
8
johnoxley_liqui
I am have the following stanza in my inputs.conf. [dbmon-tail://DB/TABLE] interval = 1m query = SELECT SL_UID,SL_TIM...
by johnoxley_liqui Engager in Splunk Search 06-02-2014
1 1
1
1
adityapavan18
In my dashboard, it loads data into a table with 4 columns Now what i require is to drill down to Dashboard1 if any ...
by adityapavan18 Contributor in Splunk Search 06-02-2014
1 2
1
2
harshal_chakran
Hi, Following is the advance xml code, where I have defined a search command in a postprocess module and want to pas...
by harshal_chakran Builder in Splunk Search 06-02-2014
0 3
0
3
bbegyperkspot
When I search in the search application, my search terms are starting to appear in subsequent searches. So search fo...
by bbegyperkspot Explorer in Splunk Search 06-02-2014
1 5
1
5
mgubser
So I have three sources that i need to join together to view as one event. The three sources are NewWFL, MoneyNEW, an...
by mgubser Explorer in Splunk Search 06-02-2014
0 5
0
5
essklau
Hi, I have a search which returns 37 results for one date (May 30), but 0 results for May 30-Jun2. I am failing to...
by essklau Path Finder in Splunk Search 06-02-2014
0 3
0
3
hagjos43
Hello, I have the following query: . . . | iplocation ClientIP | eval GeoLocation=case(Country="United States", "...
by hagjos43 Contributor in Splunk Search 06-02-2014
0 1
0
1
nikekeen
Our deployed application services have a static deployment name of this format: {service name}-{environment}-{the r...
by nikekeen New Member in Splunk Search 06-02-2014
0 2
0
2
TechnicalRS
I have VPN access connect/disconnect events from a Meraki security appliance being fed into Splunk. They show up in S...
by TechnicalRS Engager in Splunk Search 06-02-2014
0 3
0
3
ch_goh
This rex statement works in search command: rex field=source "3......(?P.+?)rly" I would like to convert it into REGE...
by ch_goh Explorer in Splunk Search 06-02-2014
0 3
0
3
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...