Splunk Search

Splunk Search
Community Activity
FloFa
As first, sry for my bad english. At the moment i making a praktical training My ask is to analyze exim4 Logs. My Pr...
by FloFa New Member in Splunk Search 02-28-2014
0 2
0
2
appleman
lookupで指定されたcsvファイルを編集したい場合、splunk web上(GUI)で編集することは可能でしょうか。 若しくはコマンド上で編集するか、新しく編集したcsvをinputlookupで入れなおすしかないのでしょうか。 ...
by appleman Contributor in Splunk Search 02-27-2014
0 3
0
3
lain179
Hello, I have log lines that look like this [ some silly example but the idea is there  ] mm/dd/yyyy hh:mm:ss - fr...
by lain179 Communicator in Splunk Search 02-27-2014
1 1
1
1
fredclown
I'm trying to write an efficient search to find out the distinct days of events that I have in an index. Basically, I...
by fredclown Builder in Splunk Search 02-27-2014
0 3
0
3
fere
I have the following query: ..... | transaction CUSTOMER_KEY mvlist=t | makemv delim="," moves Problem is when it ...
by fere Path Finder in Splunk Search 02-27-2014
0 1
0
1
sideview
This is in regards to using the streamstats command with a "by" clause, and at the same time specifying window=N to ...
by SplunkTrust SplunkTrust in Splunk Search 02-27-2014
2 4
2
4
pdash
I have a log format that uses space as delim and "" as delim when we have space in between. How should i write the re...
by pdash Path Finder in Splunk Search 02-27-2014
0 6
0
6
gudavasr
Hi, I have a query like | dbquery TEST_DB "select a.time_stamp, a.num_busy_engines, a.num_total_engines, a.num_tasks...
by gudavasr Path Finder in Splunk Search 02-27-2014
0 9
0
9
fere
I have this as part of my query: eval this_move=tostring(seq)."-."screen Only I need to make sure seq is treated as...
by fere Path Finder in Splunk Search 02-27-2014
0 2
0
2
kpers
Looking to see if there is a way to search for only specific windows event logs that accrue after 4 pm up to 11:59 pm...
by kpers Path Finder in Splunk Search 02-27-2014
0 5
0
5
vikas_gopal
Hello Everyone, Please suggest me how to place an images to extreme left in the single value box.This is what I have...
by vikas_gopal Builder in Splunk Search 02-27-2014
0 3
0
3
Ant1D
Hi, I have a chart that is produced by executing a search with a | timechart command. As the search is executing, y...
by Ant1D Motivator in Splunk Search 02-27-2014
0 2
0
2
_gkollias
I have a search where I'd like to show the duration of the order. My search below almost gives me that, but the star...
by _gkollias Builder in Splunk Search 02-27-2014
0 1
0
1
appleman
下記サーチをダッシュボードに載せると結果が変わってしまうのですが、原因はなんでしょうか。 サーチ結果では前週比がでるはずが、ダッシュボードに載せるとその数が足された結果になってしまいます。 source=test id...
by appleman Contributor in Splunk Search 02-27-2014
0 1
0
1
appleman
Hello, I want to change X axis on timechart, so I created a dashboard, and added the following option. My search: ...
by appleman Contributor in Splunk Search 02-27-2014
0 3
0
3
rotate
Hi, Exporting search results to a file is a bit too cumbersome for our current workflow. Is there any way to export ...
by rotate Engager in Splunk Search 02-27-2014
3 1
3
1
L064979
I have a feed going into Splunk currently that follows a trend that looks like it starts at a very small number, then...
by L064979 Engager in Splunk Search 02-27-2014
0 1
0
1
abhayneilam
Hi, I have a JSON file which has a key value pair. I want to discard the events which contains "Name":"John" ( I mean...
by abhayneilam Contributor in Splunk Search 02-27-2014
0 2
0
2
sloshburch
While using the CASE() feature of the search command (as per http://docs.splunk.com/Documentation/Splunk/6.0.2/Search...
by sloshburch Ultra Champion in Splunk Search 02-26-2014
0 8
0
8
yong_ly
I'm having a bit of a problem with using JS scripts in my dashboard panels. I've been using the Simple XML examples a...
by yong_ly Path Finder in Splunk Search 02-26-2014
0 1
0
1
lehrfeld
I am trying to calculate an overall total value for use later in my pipeline in a percentage calculation. My data l...
by lehrfeld Path Finder in Splunk Search 02-26-2014
0 1
0
1
aferone
Here is an example of a VPN log with an error. I want to create a field for "Reason", which includes everything found...
by aferone Builder in Splunk Search 02-26-2014
0 2
0
2
delink
I am attempting to use the INDEXED_EXTRACTION = W3C configuration to pull logs from a Microsoft TMG server. I started...
by delink Communicator in Splunk Search 02-26-2014
1 5
1
5
jimjohn
My search string is host=ABC| append [search host=DEF]|stats sum(V) by "ER Code" Can I have a count function also wi...
by jimjohn Path Finder in Splunk Search 02-26-2014
0 1
0
1
dfigurello
Hello Splunkers, I Would like to create a new field with the last numbers in another field called logid For examp...
by dfigurello Communicator in Splunk Search 02-26-2014
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...