Splunk Search

Splunk Search
Community Activity
jimjohn
Hi HostA contains employer_code like (A,B,C,D,E,F,G) HostB contains ER Code like (A,A,B,D,D) I am trying ...
by jimjohn Path Finder in Splunk Search 03-05-2014
0 5
0
5
ma_anand1984
blacklist = ((\.(tar|gz|bz2|tar.gz|tgz|tbz|tbz2|zip|z)$)|(*logger_console*|*logger_soap*|*logger_batch-documents*)) ...
by ma_anand1984 Contributor in Splunk Search 03-05-2014
0 2
0
2
Hildoceras
Hi I am looking at access log data with the fields src_ip and method (get, post, head) I have been running the sear...
by Hildoceras New Member in Splunk Search 03-05-2014
0 3
0
3
0range
Hi all. When I type "useother=f" in timechart some values are lost: fro example, I've got 5-types events: A - 10 even...
by 0range Communicator in Splunk Search 03-05-2014
0 1
0
1
basanthp
Hi, I am trying to perform field extractions in the searchtime using hiddensearch module.the following search works f...
by basanthp Path Finder in Splunk Search 03-05-2014
0 1
0
1
ncbshiva
Hi i have a Date in the below form 201304 201306 201307 I want to convert to these to below form APR-13 JUN-13 JUL...
by ncbshiva Communicator in Splunk Search 03-05-2014
0 3
0
3
_gkollias
Hi All, I'd like to create a props.conf for log files in this format: DEBUG[ScriptingSession] 2013-11-30 15:52:4...
by _gkollias Builder in Splunk Search 03-04-2014
0 4
0
4
jasklee
I need to create a table which will display workweek as rows and subarea as column, meanwhile the data inside will ...
by jasklee Engager in Splunk Search 03-04-2014
0 1
0
1
jasklee
I need to create a table which will display workweek as rows and subarea as column, meanwhile the data inside will ...
by jasklee Engager in Splunk Search 03-04-2014
0 2
0
2
dmalcor
In the GUI I get results plus the fields: host, source, and sourcetype Same search in the CLI I just get results, no ...
by dmalcor Engager in Splunk Search 03-04-2014
0 5
0
5
twkan
Hello everybody, I'm trying to do a timechart using a 3 day timeframe, for example from Jul 17 2011 00:00:00 to Jul ...
by twkan Splunk Employee Splunk Employee in Splunk Search 03-04-2014
1 7
1
7
Thuan
I have set up a lookup table that consists of a number of offenses that need to be identified for every daily search....
by Thuan Explorer in Splunk Search 03-04-2014
0 3
0
3
vikas_gopal
Hi Everyone, Is it possible to concatenate current date and time with dashboard label e.g. my dashboard label is "Mon...
by vikas_gopal Builder in Splunk Search 03-04-2014
0 9
0
9
mcrawford44
Hi all, CSV export of multi-key values is a bit basic at the moment. It exports each value with a space delimiter. ...
by mcrawford44 Communicator in Splunk Search 03-04-2014
0 1
0
1
ryanmims
Trying to write a search that will show top 10 "repeat" offenders over last 7 days. I'm guessing an eval(if) statemen...
by ryanmims Explorer in Splunk Search 03-04-2014
0 7
0
7
rileyken
we make the index names very short since they will be used in searches, but we have a lot of indexes, so we would lik...
by rileyken Explorer in Splunk Search 03-04-2014
0 1
0
1
mrjlam
Is there a way to create an alias to an existing index so we can search by its name and it's alias: eg. index=origi...
by mrjlam Engager in Splunk Search 03-03-2014
1 4
1
4
mdavis43
I have two source types, one (A) has Active Directory information, user id, full name, department. The other (B) con...
by mdavis43 Path Finder in Splunk Search 03-03-2014
0 1
0
1
mrflibbleuk
Hi, I have a single large dataset that is related as follows. Each User has a UserID, when they login a SessionID i...
by mrflibbleuk New Member in Splunk Search 03-03-2014
0 1
0
1
jasklee
I want to count the number for the multivalue field count(eval x=commands("search passed | search sub_areaA")) AS su...
by jasklee Engager in Splunk Search 03-03-2014
0 3
0
3
asmithe
this search: index=flowspaces sourcetype=auditlog produces search results that are not displayed in the ui. if field...
by asmithe Path Finder in Splunk Search 03-03-2014
0 2
0
2
harshal_chakran
Hi, I have a python file, whose output I am trying to show on splunk web interface. I have written some print stateme...
by harshal_chakran Builder in Splunk Search 03-03-2014
0 1
0
1
OldManEd
Why is Splunk On Splunk showing CPU usage at between 200% and 1100%? This makes me wonder if all the other monitorin...
by OldManEd Builder in Splunk Search 03-03-2014
0 3
0
3
ross_warren
Hi, I am grabbing interface errors from Cisco routers (via snmpget) that form a distinct path through the network. I...
by ross_warren New Member in Splunk Search 03-03-2014
0 4
0
4
vtrujillo
Hi everyone! I'm trying to add a new series to my line chart from my dashboard's xml file. (Which means I want to di...
by vtrujillo Explorer in Splunk Search 03-03-2014
0 3
0
3
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors