Splunk Search

Splunk Search
Community Activity
changwoo
i am trying to search by year i have a field like movie_year ( ex: 1991, 1999, 2000) and i want make a dashboard wh...
by changwoo Communicator in Splunk Search 01-15-2014
0 3
0
3
Jananee_iNautix
I have to do something like according to the extension of the filename that i extract from logs i want to flag them. ...
by Jananee_iNautix Path Finder in Splunk Search 01-15-2014
0 4
0
4
dlespron
For instance, I have a search where I want to query for a value that would set that value to orderid such as: source...
by dlespron Path Finder in Splunk Search 01-15-2014
0 2
0
2
appleman
Hello there, I just wonder if I can divide an index into two indexes. e.g, Divide the data in index=main to index=pr...
by appleman Contributor in Splunk Search 01-15-2014
2 6
2
6
RMartinezDTV
Hi, I have a search where I'm attempting to use a lookup table and the top command in the same search. The search is...
by RMartinezDTV Path Finder in Splunk Search 01-15-2014
0 2
0
2
gmhp
Is there a search that will warn me of a logfile that is 0 bytes and is not updating? TIA.
by gmhp New Member in Splunk Search 01-15-2014
0 1
0
1
dfigurello
Hey Splunkers, Could you help me about identify a field. I don't have experience with regex. In my case I have fire...
by dfigurello Communicator in Splunk Search 01-15-2014
0 4
0
4
yuwtennis
Hi! I would like to have some help with summary indexing. My situations is like following: I have events that come...
by yuwtennis Communicator in Splunk Search 01-15-2014
0 2
0
2
yuwtennis
Hi! Is it possible to overwrite the summary index with same timestamp? Lets say you already have a summary index as...
by yuwtennis Communicator in Splunk Search 01-15-2014
0 2
0
2
Mag2sub
We have a search that is scheduled to run across several different,diverse index...this serach also trigger only when...
by Mag2sub Path Finder in Splunk Search 01-14-2014
0 3
0
3
changwoo
i tried this tutorial http://docs.splunk.com/Documentation/Splunk/6.0.1/SearchTutorial/Usefieldlookups Upload a loo...
by changwoo Communicator in Splunk Search 01-14-2014
0 2
0
2
singhbc
10.10.10.10 - - ProfileID=CRTClientAdmin 1,ProductCode=CRT,ou=products,o=cyH,ou=clients,o=a.com^ProfileID=SDGUser 1,P...
by singhbc Path Finder in Splunk Search 01-14-2014
1 5
1
5
xvxt006
Hi, I am getting number of orders per hour and last week same hour orders and delta percentage. i run this every hou...
by xvxt006 Contributor in Splunk Search 01-14-2014
0 5
0
5
SplunkMonster
I'm looking to create a report that lists out the occurrences of a given event, but also includes information about t...
by SplunkMonster Engager in Splunk Search 01-14-2014
0 2
0
2
rlautman
I am working on a a proof of concept for a monitoring system to work with several databases within my companys estate...
by rlautman Path Finder in Splunk Search 01-14-2014
0 1
0
1
sbsbb
Is it possible to use a defined lookup, within a custom python command ? If not, is it possible to access directly t...
by sbsbb Builder in Splunk Search 01-14-2014
2 2
2
2
sc0tt
We recently upgraded to Splunk 6 and on multiple occasions a real-time search seems to magically appear and causes al...
by sc0tt Builder in Splunk Search 01-14-2014
0 4
0
4
fuzzy_rocks
I am looking to get a list of unique users who share files. The logs have an entry when a file is accessed with the F...
by fuzzy_rocks Explorer in Splunk Search 01-13-2014
0 2
0
2
johnmca
Need some help adding a 0 count at search time. I have a log that contains the execution duration of a code function...
by johnmca Explorer in Splunk Search 01-13-2014
2 3
2
3
proletariat99
If I search for a generic term -- say, "John Doe" and I get thousands of results from dozens of sourcetypes, how can ...
by proletariat99 Communicator in Splunk Search 01-13-2014
0 3
0
3
cpenkert
The results of my searches don't wrap, so I'm left with one very very long line of an event. I saw in this post, tha...
by cpenkert Path Finder in Splunk Search 01-13-2014
3 8
3
8
changwoo
i am searching like this sourcetype=user |fields user_id, user_gender, user_age,user_occup,user_zipcode |rename use...
by changwoo Communicator in Splunk Search 01-13-2014
0 6
0
6
changwoo
i am trying to import a .csv but it is in txt format and it is seperated with :: not , do i have to change :: to ...
by changwoo Communicator in Splunk Search 01-13-2014
0 2
0
2
wardallen
I am analysing a logfile where there'll be a message that describes an outbound message going to an external system, ...
by wardallen Path Finder in Splunk Search 01-13-2014
0 3
0
3
andrewkenth
I am attempting to change the default color scheme via $SPLUNK_HOME/share/splunk/search_mrsparkle/exposed/css/skins/d...
by andrewkenth Communicator in Splunk Search 01-13-2014
1 4
1
4
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors