| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        Hi  
  I have a date field called Time_Line(01-Jan-13) in my source file. 
  My search query is: source=foo | eval st...
        
       
         
           by 
           
                
                    
                        ncbshiva
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-18-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Searches of DNS logs, sourcetype=dns, reveal records with information of the form *.in-addr.arpa While I can reverse ...
        
       
         
           by 
           
                
                    
                        landen99
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi all, 
  How do we check field2 contains field1? Please help. 
  Field1 Value= CA6 
  Field2 Value= IA6,CA6,CA8,CA9...
        
       
         
           by 
           
                
                    
                        rsathish47
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi, 
  I have a Postprocess search command in a Dashboard , which wait for couple of seconds to display the output. I...
        
       
         
           by 
           
                
                    
                        harshal_chakran
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               03-13-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have a need to monitor files that look like this: 
  host one =  
  /path/to/base/app/App1/App1.{pidnumber}.log /pa...
        
       
         
           by 
           
                
                    
                        GeorgeStarkey
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi, 
  I have written a search query in Advanced XML dashboard, which displays the table as follows, 
   
   paramete...
        
       
         
           by 
           
                
                    
                        harshal_chakran
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               03-11-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Quick question, is Splunk supposed to be able to understand a time stamp string like this; 
  2014 Mar 14 20:51:10:98...
        
       
         
           by 
           
                
                    
                        OldManEd
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I am attempting to incrase the number of RealTime searches a search head can spin up at one time. I am getting this m...
        
       
         
           by 
           
                
                    
                        tmarlette
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi 
  I need to display table along with percentage 
  This is my search query : source=foo | fields DS_CLIENTE,DS_ST...
        
       
         
           by 
           
                
                    
                        ncbshiva
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi, 
  I have data that gives these fields: user and error code. 
  I am trying to count the amount of certain errors...
        
       
         
           by 
           
                
                    
                        bcusick
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-12-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Hi I have a search like this host=A |stats last("Status") by TaskId  
  I like to group the result of above query by ...
        
       
         
           by 
           
                
                    
                        SplunkBaby
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I'm trying to connect to the database of another server for me to build dashboards but i can't connect. anyone here k...
        
       
         
           by 
           
                
                    
                        aquillius
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I have a weird situation.  
  1) I have a sourcetype "transactions" in which it has a field called "account_number". ...
        
       
         
           by 
           
                
                    
                        thirumalreddyb
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-17-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Below query gives the results like : 
  index=* | stats values(SERVICENAME) as SERVICE by HOST
HOST  SERVICE
----- -...
        
       
         
           by 
           
                
                    
                        splunker12er
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-13-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  8
	 
 | |||
| 
      
        Hello, Need some help on regex here, am sure i maybe making mistake here but.. I don't undesrtand the problem in splu...
        
       
         
           by 
           
                
                    
                        armonsal
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi,  
  I'm trying to collect the number of emails with the same subject line into a summary index. Problem is, whils...
        
       
         
           by 
           
                
                    
                        DerekKing
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Hai i have a field which has dates 
  example : 1-Oct-13 4-Dec-13 28-Oct-13 
  I have to convert to below format 
  0...
        
       
         
           by 
           
                
                    
                        ncbshiva
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I am comparing the results of two search queries using "| set diff [search1][search2]". This works correctly in that ...
        
       
         
           by 
           
                
                    
                        LordShacks
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I wanted to create a new field name like 'Country' from the incoming logs based on some characters in the hostname. 
...
        
       
         
           by 
           
                
                    
                        splunker12er
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hello 
  I am trying to change the data of the host field which has already been indexed. The host field has values i...
        
       
         
           by 
           
                
                    
                        theouhuios
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-13-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hello, 
  i want to have a search which shows me in 10 minute span how often something did happen. i only want to dis...
        
       
         
           by 
           
                
                    
                        Matthias_BY
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have saved searches in my app. In human words my requirement is: 1. Save the search 2. save the next search 3. save...
        
       
         
           by 
           
                
                    
                        disha
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               10-31-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello 
  I have a syslog server which is being used to collect various network oriented data. For example if its a Ar...
        
       
         
           by 
           
                
                    
                        theouhuios
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               02-28-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  24
	 
 | |||
| 
      
        We have build a query spanning multiple source types. We try to create a simple transaction with one field. The resul...
        
       
         
           by 
           
                
                    
                        cmeerbeek
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-14-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have a search that brings up specific order types by order numbers that begin with a 7: 
  index=contract_gateway s...
        
       
         
           by 
           
                
                    
                        _gkollias
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               03-13-2014
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 |