Splunk Search

Splunk Search
Community Activity
gmorreale_splun
Hi, I'm following below tutorial (section Lookups) http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/**Usef...
by gmorreale_splun Splunk Employee Splunk Employee in Splunk Search 02-18-2014
1 1
1
1
ramanjain1983
Hi there, I am trying working out a scenario with Splunk and having a hard time on it. I have got a XML which has t...
by ramanjain1983 Path Finder in Splunk Search 02-18-2014
0 1
0
1
tmarlette
I am attempting to get the latest status of a port scan for 5 different ports per host into a table. I am trying to...
by tmarlette Motivator in Splunk Search 02-18-2014
0 1
0
1
jaj
Given the following query, how can I append the second query so that the results show up as two rows so I can graph t...
by jaj Path Finder in Splunk Search 02-18-2014
1 4
1
4
mataharry
I have to do some maintenances in splunk and want to warn the users that splunk will be down. How to get the list of...
by mataharry Communicator in Splunk Search 02-18-2014
2 4
2
4
agentelinux
My query in dbconnect DatabaseInput is: SELECT b.modifielddate AS [Modfielddate], a.name, b.amount FROM sales b inne...
by agentelinux Explorer in Splunk Search 02-18-2014
0 8
0
8
dbecker_AU
We are using Splunk 6.0.1, and I found a search that generates license usage by host: index=_internal source=*licens...
by dbecker_AU Engager in Splunk Search 02-18-2014
0 3
0
3
di2esysadmin
I'm banging my head against the wall. Here's my search: host="atlassian-stash*" sourcetype=atlassian source="/opt/a...
by di2esysadmin Path Finder in Splunk Search 02-18-2014
0 9
0
9
jaj
I have the two separate queries that I could like to combine into on query without using event types. How can I do t...
by jaj Path Finder in Splunk Search 02-18-2014
1 10
1
10
crt89
Hi, We have a set of indexed logs from a server currently there's no new data that has been indexed. The data comput...
by crt89 Communicator in Splunk Search 02-18-2014
0 3
0
3
sdorich
I have events in xml format. Some of the events include this header: xml version="1.0" encoding="UTF-8" standalone="...
by sdorich Communicator in Splunk Search 02-18-2014
1 4
1
4
dctopper
Hi, I've run into a problem: Splunk ingests Window's security events in such a way that field names may occur more t...
by dctopper Explorer in Splunk Search 02-18-2014
0 2
0
2
johnsmithbitter
I'm trying to create a search that provides me with the average duration between VALIDATED and ARCHIVED only if it co...
by johnsmithbitter Explorer in Splunk Search 02-17-2014
0 7
0
7
jaj
I have a filed in my logs "labeDatal" and I also have another field that I trace out called "labelDataSpec" i.e. log...
by jaj Path Finder in Splunk Search 02-17-2014
0 1
0
1
changwoo
start_time = > 2014-02-13T22:57:15+0900 end_ time = > 2014-02-13T23:59:54+0900 how can i get the time difference ??...
by changwoo Communicator in Splunk Search 02-17-2014
0 3
0
3
the_wolverine
Previously we have encountered issues with using CAPS in index name configuration. What other issues should we be aw...
by the_wolverine Champion in Splunk Search 02-17-2014
0 4
0
4
surfjose
Hi I have a log-file with diffrent time formats. Is it possible to extract this diffrent timestamps with TIME_PREFIX ...
by surfjose New Member in Splunk Search 02-17-2014
0 2
0
2
kdb8916
I am trying to extract info from the _raw result of my Splunk query. Currently my _raw result is: _raw="2014-02-13 1...
by kdb8916 Explorer in Splunk Search 02-17-2014
1 5
1
5
harshal_chakran
Hi, I have used a code in advance xml for 3 buttons <module name="HTML" layoutPanel="panel_row3_col1"> <param n...
by harshal_chakran Builder in Splunk Search 02-17-2014
0 1
0
1
jimjohn
How can I join and group data from 2 different hosts. Say I have HostA , HostB and ID as common field in 2 hosts. I w...
by jimjohn Path Finder in Splunk Search 02-17-2014
0 1
0
1
SplunkBaby
Hi I have 2 data source say DS1 and DS2. There is a common field called EMPID for this two data source. I want to gen...
by SplunkBaby Explorer in Splunk Search 02-17-2014
0 2
0
2
ndkhoiits
I have a log file which contains a log like following: 2014-02-14 01:49:22,938 Updated this customer: email: test@te...
by ndkhoiits Explorer in Splunk Search 02-16-2014
0 3
0
3
the_wolverine
dbinspect has to be run on the indexer. It can't be run from the search head. How do I get the result from my searc...
by the_wolverine Champion in Splunk Search 02-16-2014
0 2
0
2
bckq
This is my search: index=cloud (cloud_severity="High" OR cloud_severity="Disaster") | dedup cloud_info,cloud_hostnam...
by bckq Path Finder in Splunk Search 02-16-2014
1 4
1
4
thesteve
I ran a search and noticed something unexpected in my results. Of course the error I saw was not an informative one,...
by thesteve Path Finder in Splunk Search 02-14-2014
0 4
0
4
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Solution Authors