Splunk Search

Splunk Search
Community Activity
rileyken
we make the index names very short since they will be used in searches, but we have a lot of indexes, so we would lik...
by rileyken Explorer in Splunk Search 03-04-2014
0 1
0
1
mrjlam
Is there a way to create an alias to an existing index so we can search by its name and it's alias: eg. index=origi...
by mrjlam Engager in Splunk Search 03-03-2014
1 4
1
4
mdavis43
I have two source types, one (A) has Active Directory information, user id, full name, department. The other (B) con...
by mdavis43 Path Finder in Splunk Search 03-03-2014
0 1
0
1
mrflibbleuk
Hi, I have a single large dataset that is related as follows. Each User has a UserID, when they login a SessionID i...
by mrflibbleuk New Member in Splunk Search 03-03-2014
0 1
0
1
jasklee
I want to count the number for the multivalue field count(eval x=commands("search passed | search sub_areaA")) AS su...
by jasklee Engager in Splunk Search 03-03-2014
0 3
0
3
asmithe
this search: index=flowspaces sourcetype=auditlog produces search results that are not displayed in the ui. if field...
by asmithe Path Finder in Splunk Search 03-03-2014
0 2
0
2
harshal_chakran
Hi, I have a python file, whose output I am trying to show on splunk web interface. I have written some print stateme...
by harshal_chakran Builder in Splunk Search 03-03-2014
0 1
0
1
OldManEd
Why is Splunk On Splunk showing CPU usage at between 200% and 1100%? This makes me wonder if all the other monitorin...
by OldManEd Builder in Splunk Search 03-03-2014
0 3
0
3
ross_warren
Hi, I am grabbing interface errors from Cisco routers (via snmpget) that form a distinct path through the network. I...
by ross_warren New Member in Splunk Search 03-03-2014
0 4
0
4
vtrujillo
Hi everyone! I'm trying to add a new series to my line chart from my dashboard's xml file. (Which means I want to di...
by vtrujillo Explorer in Splunk Search 03-03-2014
0 3
0
3
Simon
Hi Is there a list of all known objects on which I can set ACLs which Splunk's metadata files (default.meta/local.me...
by Simon Contributor in Splunk Search 03-03-2014
2 1
2
1
gnoellbn
I'm trying to subtract the list of host contains in my csv file in field "clients_supprimes" to results of host not r...
by gnoellbn Explorer in Splunk Search 03-03-2014
0 5
0
5
clanglais
Hi, I'm trying to get less logs from CheckPoint Firewall (75.4) into a Splunk server (v 6). I just want to have all...
by clanglais Explorer in Splunk Search 03-03-2014
1 3
1
3
tt1
Hi, I am successfully reading and joining a couple of sources, but am having a trouble adding a 3rd. index=access_l...
by tt1 Explorer in Splunk Search 03-02-2014
0 1
0
1
Thuan
We have a need to identify the country of origin of IPs that are hitting our firewalls, notably from "unfriendly" cou...
by Thuan Explorer in Splunk Search 03-02-2014
1 8
1
8
pisc
カラム名の変換方法について教えてください。 正規表現を使用せずにSplunk側で処理が出来て読み込めたデータがありますが、カラム名を変更したいと思います。 Splunk側で読み込んだデータに対してカラム名を変更することは可能ですか?
by pisc Explorer in Splunk Search 03-02-2014
0 3
0
3
ho000dor
What's the easiest way to create a key for a list of octets that need to be renamed? Example: I have a rex query tha...
by ho000dor Explorer in Splunk Search 03-01-2014
0 3
0
3
vinraisf
I am trying to get average per second while using this query Source= (logRecordType="V" OR logRecordType="U") earl...
by vinraisf New Member in Splunk Search 03-01-2014
0 3
0
3
chris
Hi I thought that the bucket command would split events into two bins that cover half the search span if i use 2 bi...
by chris Motivator in Splunk Search 02-28-2014
0 2
0
2
foreright360
Could someone help me with a rex to extract the domain out of a http or https URL? For example, I need 'www.test.com...
by foreright360 Engager in Splunk Search 02-28-2014
1 3
1
3
toby53
How can I do a group by on a log column. For example: for fore: 28.02.2014 18:08:30.841 ERROR [pool-6-thread-14-com/...
by toby53 New Member in Splunk Search 02-28-2014
0 3
0
3
ahmetcepoglu
I have multiple searches, and I need their results in a particular order. I am trying to make a splunk view that show...
by ahmetcepoglu Engager in Splunk Search 02-28-2014
0 3
0
3
willial
Here's my rex: rex max_match=0 "(MSM-\w+\s+(?<slotMSM>\w+)\s+|MM-\w+\s+(?<slotMM>\w+)\s+|Slot-\d+\s+(?<slotNum>\d+)\...
by willial Communicator in Splunk Search 02-28-2014
0 3
0
3
dpoon
I can't seem to convert epoch time when using timechart. I'm trying to get each users first logon of the day over a p...
by dpoon Explorer in Splunk Search 02-28-2014
0 5
0
5
_gkollias
Hi All, I'm trying to create a table that shows the duration of a transaction by the hour. I'm trying to use someth...
by _gkollias Builder in Splunk Search 02-28-2014
0 12
0
12
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...