Splunk Search

Splunk Search
Community Activity
sushma7
Hi, Please find the below XML file: 20140401-05:39:58 <![CDATA[Connection established]]> FTP 26875...
by sushma7 Path Finder in Splunk Search 04-09-2014
0 13
0
13
abhi144
I have a csv file in which two field are ShopNo and ShopId. From search i'm getting ShopNo and ShopIdinDevice so i wa...
by abhi144 New Member in Splunk Search 04-09-2014
0 1
0
1
frank_zhang
Hi, I have the following two sources: Source1: | Time | IP | MAC | | 08:01 | 10.0.1.1 | MAC1 | | 08:02...
by frank_zhang Path Finder in Splunk Search 04-09-2014
0 17
0
17
hadinh
Is web interface automatically installed with Splunk enterprise? Will it appear after installing and starting splunk ...
by hadinh Explorer in Splunk Search 04-08-2014
0 4
0
4
mamulani11
I have User_Id field in my log. In the user_Id field I have value like john,sonia,ces\ts1,...... Now when i am search...
by mamulani11 New Member in Splunk Search 04-08-2014
0 4
0
4
shri_27
Hi All, I have a field whose values look like value1>value2>value3!! Now i want to extract only value3 using rex! ...
by shri_27 Path Finder in Splunk Search 04-08-2014
0 12
0
12
snoobzilla
How do I get the last KER out of my lookup and get it into search below as LASTKER? I have a lookup table of error s...
by snoobzilla Builder in Splunk Search 04-08-2014
0 8
0
8
bkondakindi
Folks , we have case like as normal user from DBA not able to add his DB to external database on splunk side. as ...
by bkondakindi Path Finder in Splunk Search 04-08-2014
0 1
0
1
Jananee_iNautix
Hi , There are two fields named "start_time" and "end_time" extracted from logs and displayed in the format "03/...
by Jananee_iNautix Path Finder in Splunk Search 04-08-2014
0 2
0
2
ycalpu
I want to exclude the INFO log level in one of my searches. How would i do a "not" condition in the following: sour...
by ycalpu New Member in Splunk Search 04-08-2014
0 1
0
1
Ant1D
Hi, I have a field named hello_world and a value of the field is * I am writing a search where the results will not...
by Ant1D Motivator in Splunk Search 04-08-2014
0 7
0
7
duenguyen
Can I have indexer smart enough to go to dedicate index base on data value Here is my data "2013-12-02 20:30:30","a@...
by duenguyen Explorer in Splunk Search 04-08-2014
0 5
0
5
mrjester
I am consuming logs from my Vyatta firewall and I am having trouble getting the field extractor to reliably pull the ...
by mrjester Explorer in Splunk Search 04-07-2014
0 3
0
3
kaoriaraki
先週と今週の結果を比較するサーチを実行したいと考えています。 下記の例では曜日をキーにjoinして比較していますが、週の半ば(例えば水曜日)にサーチを実行すると水曜日までのグラフしか表示されません。 先週分は、日曜日から土曜日までの1...
by kaoriaraki Explorer in Splunk Search 04-07-2014
1 1
1
1
nikhilmehra79
As a quick check can some one suggest me if we have a 2 indexer envirornment with 2 search heads - does it make sense...
by nikhilmehra79 Path Finder in Splunk Search 04-07-2014
0 12
0
12
hbpatel142
Below Query Provides the Result. counter="% Processor Time" | chart avg(Value) over host by counter | search "% Proce...
by hbpatel142 Engager in Splunk Search 04-07-2014
1 1
1
1
j1nagar
Hello, I know i am doing something wrong but been going nowhere on this. Basically, have a maven project in eclipse ...
by j1nagar New Member in Splunk Search 04-07-2014
0 4
0
4
melonman
Hi I am looking for a search that iterates all my fieldname start with f* and get the statistics value of each f an...
by melonman Motivator in Splunk Search 04-07-2014
0 3
0
3
rsathish47
Hi , mvzip function takes two multivalue fields, I want to combine three multiple value.. Please let me if we have ...
by rsathish47 Contributor in Splunk Search 04-07-2014
3 2
3
2
jsmith39
I have a list of servers that do data backups to disk on a week night basis and I've built a query to display the res...
by jsmith39 Path Finder in Splunk Search 04-07-2014
0 3
0
3
SplunkUser5888
Hey guys, I'm trying to use regular expressions but can't get my head around it. I'm receiving lines such as: u'C:...
by SplunkUser5888 Path Finder in Splunk Search 04-07-2014
0 3
0
3
asmithe
I have a large mixed search, part of the resulting data is being pulled from search and part from an inputlookup csv...
by asmithe Path Finder in Splunk Search 04-07-2014
0 1
0
1
iTechEvent
The use case am working on: I have one sourcetype, one index. In the event log there are several apis with responset...
by iTechEvent Explorer in Splunk Search 04-06-2014
0 4
0
4
troywollenslege
As far as efficiency, we were told that realtime searches take "a fraction" of a CPU core per search. Does it matter ...
by troywollenslege Path Finder in Splunk Search 04-06-2014
0 3
0
3
linu1988
Hello Guyz, I have to extract around 30/40 fields from logs and monitor them. They are well formatted and can be extr...
by linu1988 Champion in Splunk Search 04-06-2014
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...