Splunk Search

Splunk Search
Community Activity
swong
I want to search for the installed apps and their versions for OSX platform. Want to display results in table form sh...
by swong New Member in Splunk Search 04-02-2014
0 1
0
1
sp00l
I'm running a search that looks like this: index=myindex domain=*mydomain* domain!=*.mydomain.com* domain !=mydomain...
by sp00l New Member in Splunk Search 04-02-2014
0 11
0
11
splunkranger
my search returns 3 numbers acount, bcount, ccount 1 0 1 2 4 3 I would like to be able us...
by splunkranger Path Finder in Splunk Search 04-02-2014
0 3
0
3
jpvh12345
I have single-line log entries that come into splunk looking like this: Apr 1 12:34:09 10.1.9.254 %ASA-4-722051: Grou...
by jpvh12345 New Member in Splunk Search 04-02-2014
0 6
0
6
kestasm
Hi there, I need to develop a search query which looks for the specific file download after one file was downloaded ...
by kestasm Path Finder in Splunk Search 04-02-2014
1 5
1
5
rmcdougal
Basically, I want to create a search that will alert me in a forwarder is indexing the same data multiple times. We ...
by rmcdougal Path Finder in Splunk Search 04-02-2014
0 2
0
2
dengjin
在Database Query中,搜索语句如果包含汉字,则会报错:Error in 'script': Getinfo probe failed for external search command 'dbquery' 搜索语句如下...
by dengjin New Member in Splunk Search 04-01-2014
0 3
0
3
rpascua
My Regex: | rex "\sof (?<Name>[A-Za-z0-9_]+)" | rex "\sdeposit \((?<Deposit>\d+)" | rex "\s*withdrawal \((?<Withdraw...
by rpascua Explorer in Splunk Search 04-01-2014
0 5
0
5
rpascua
My REGEX: | rex "\sof (?<Name>[A-Za-z0-9_]+)" | rex "\sdeposit \((?<Deposit>\d+)" | rex "\s*withdrawal \((?<Withdraw...
by rpascua Explorer in Splunk Search 04-01-2014
0 1
0
1
tmarlette
I am attempting to find the duration of each downtime instance that has occurred in the last 24 hours, and I am attem...
by tmarlette Motivator in Splunk Search 04-01-2014
0 5
0
5
shawnce
I believe the following two queries are essentially the same but when I run them the former returns results with 10s ...
by shawnce Engager in Splunk Search 04-01-2014
0 3
0
3
gnovak
NO this is no April Fools Joke. But it feels that way to me... I'm trying to use transforms.conf and props.conf to ...
by gnovak Builder in Splunk Search 04-01-2014
0 7
0
7
davewood
Hi, At search time, is there any way of splitting a tabular event into multiple events by column rather than row as ...
by davewood Explorer in Splunk Search 04-01-2014
0 5
0
5
ahsishsharmaait
Hi, We have events like this Time1 8000 UserId1 Event-Launch ProcessId-10000 ... Time2 10000 UserId1 Event-Login _ ...
by ahsishsharmaait New Member in Splunk Search 04-01-2014
0 3
0
3
pgadhari
Hello Experts, We are a Corporate Data center in our Internal IT department of the company. We host intranet service...
by pgadhari Builder in Splunk Search 03-31-2014
0 2
0
2
nikhilmehra79
Hi, I have build a dashboard using adv XML but since we have so much data to visualize it people have to scroll down...
by nikhilmehra79 Path Finder in Splunk Search 03-31-2014
0 3
0
3
cramasta
I have a search that is exported to a csv file which is also set up to be a lookup table. I can call the lookup tab...
by cramasta Builder in Splunk Search 03-31-2014
1 6
1
6
neiljpeterson
I have a chart with various counts of errors and corresponding Sparklines. In this instance the null values are just...
by neiljpeterson Communicator in Splunk Search 03-31-2014
0 6
0
6
theouhuios
Hello I need some help in fixing the regex for the below events. it works on few and it doesn't on few. The first ...
by theouhuios Motivator in Splunk Search 03-31-2014
0 3
0
3
antlefebvre
When piping fields into a table, the table eliminates extra spaces inside the field. For example: person_name="Smit...
by antlefebvre Communicator in Splunk Search 03-31-2014
0 3
0
3
ConSeannery
Hi, I'm trying to test splunks handling of structured data using an RFC 5494 compliant message. When I netcat the fo...
by ConSeannery Engager in Splunk Search 03-31-2014
1 4
1
4
nikhilmehra79
so i have hidden search in my advance XML file in v5. works perfect until i need to modify my search to extend some r...
by nikhilmehra79 Path Finder in Splunk Search 03-31-2014
0 3
0
3
subtrakt
HI! What's the easiest way to create a time-chart and stats table with same query so I can create a dashboard, have...
by subtrakt Contributor in Splunk Search 03-31-2014
0 2
0
2
jason_mannering
I am trying to find out how to create a custom field that will be available as an index field that I can set as a sta...
by jason_mannering Engager in Splunk Search 03-31-2014
0 4
0
4
subtrakt
Hi, I have a dashboard with time-charts... I'm trying to take the "App#" fields values that the time-chart is sourced...
by subtrakt Contributor in Splunk Search 03-30-2014
0 3
0
3
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...