Splunk Search

Splunk Search
Community Activity
rmcdougal
Basically, I want to create a search that will alert me in a forwarder is indexing the same data multiple times. We ...
by rmcdougal Path Finder in Splunk Search 04-02-2014
0 2
0
2
dengjin
在Database Query中,搜索语句如果包含汉字,则会报错:Error in 'script': Getinfo probe failed for external search command 'dbquery' 搜索语句如下...
by dengjin New Member in Splunk Search 04-01-2014
0 3
0
3
rpascua
My Regex: | rex "\sof (?<Name>[A-Za-z0-9_]+)" | rex "\sdeposit \((?<Deposit>\d+)" | rex "\s*withdrawal \((?<Withdraw...
by rpascua Explorer in Splunk Search 04-01-2014
0 5
0
5
rpascua
My REGEX: | rex "\sof (?<Name>[A-Za-z0-9_]+)" | rex "\sdeposit \((?<Deposit>\d+)" | rex "\s*withdrawal \((?<Withdraw...
by rpascua Explorer in Splunk Search 04-01-2014
0 1
0
1
tmarlette
I am attempting to find the duration of each downtime instance that has occurred in the last 24 hours, and I am attem...
by tmarlette Motivator in Splunk Search 04-01-2014
0 5
0
5
shawnce
I believe the following two queries are essentially the same but when I run them the former returns results with 10s ...
by shawnce Engager in Splunk Search 04-01-2014
0 3
0
3
gnovak
NO this is no April Fools Joke. But it feels that way to me... I'm trying to use transforms.conf and props.conf to ...
by gnovak Builder in Splunk Search 04-01-2014
0 7
0
7
davewood
Hi, At search time, is there any way of splitting a tabular event into multiple events by column rather than row as ...
by davewood Explorer in Splunk Search 04-01-2014
0 5
0
5
ahsishsharmaait
Hi, We have events like this Time1 8000 UserId1 Event-Launch ProcessId-10000 ... Time2 10000 UserId1 Event-Login _ ...
by ahsishsharmaait New Member in Splunk Search 04-01-2014
0 3
0
3
pgadhari
Hello Experts, We are a Corporate Data center in our Internal IT department of the company. We host intranet service...
by pgadhari Builder in Splunk Search 03-31-2014
0 2
0
2
nikhilmehra79
Hi, I have build a dashboard using adv XML but since we have so much data to visualize it people have to scroll down...
by nikhilmehra79 Path Finder in Splunk Search 03-31-2014
0 3
0
3
cramasta
I have a search that is exported to a csv file which is also set up to be a lookup table. I can call the lookup tab...
by cramasta Builder in Splunk Search 03-31-2014
1 6
1
6
neiljpeterson
I have a chart with various counts of errors and corresponding Sparklines. In this instance the null values are just...
by neiljpeterson Communicator in Splunk Search 03-31-2014
0 6
0
6
theouhuios
Hello I need some help in fixing the regex for the below events. it works on few and it doesn't on few. The first ...
by theouhuios Motivator in Splunk Search 03-31-2014
0 3
0
3
antlefebvre
When piping fields into a table, the table eliminates extra spaces inside the field. For example: person_name="Smit...
by antlefebvre Communicator in Splunk Search 03-31-2014
0 3
0
3
ConSeannery
Hi, I'm trying to test splunks handling of structured data using an RFC 5494 compliant message. When I netcat the fo...
by ConSeannery Engager in Splunk Search 03-31-2014
1 4
1
4
nikhilmehra79
so i have hidden search in my advance XML file in v5. works perfect until i need to modify my search to extend some r...
by nikhilmehra79 Path Finder in Splunk Search 03-31-2014
0 3
0
3
subtrakt
HI! What's the easiest way to create a time-chart and stats table with same query so I can create a dashboard, have...
by subtrakt Contributor in Splunk Search 03-31-2014
0 2
0
2
jason_mannering
I am trying to find out how to create a custom field that will be available as an index field that I can set as a sta...
by jason_mannering Engager in Splunk Search 03-31-2014
0 4
0
4
subtrakt
Hi, I have a dashboard with time-charts... I'm trying to take the "App#" fields values that the time-chart is sourced...
by subtrakt Contributor in Splunk Search 03-30-2014
0 3
0
3
lpolo
Using the Splunk query language how would be a splunk query that returns the Top 1 from a set of Top N? Data set sam...
by lpolo Motivator in Splunk Search 03-29-2014
0 6
0
6
koshyk
I'm not sure if this is the correct way to put a suggestion. But it would be great to have Splunk DBConnect with SQli...
by koshyk Super Champion in Splunk Search 03-29-2014
0 2
0
2
splunkranger
The 'Search' page, which lists the number of events, the oldest and latest event is not accurate. Can anyone tell m...
by splunkranger Path Finder in Splunk Search 03-29-2014
0 7
0
7
isworks
I have configured the ASA to syslog directly to my splunk server(low volume) and I have set up to receive syslog on U...
by isworks New Member in Splunk Search 03-28-2014
0 1
0
1
JWBailey
I have two indexers that are being load balanced. I am interested to see the distribution of events from each host o...
by JWBailey Communicator in Splunk Search 03-28-2014
0 3
0
3
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...