Splunk Search

Splunk Search
Community Activity
klee310
Hello & merry xmas to all, I would like to create a macro-expansion using searchmatch (eval-command) such that the a...
by klee310 Communicator in Splunk Search 12-27-2013
0 2
0
2
rahulgopal
I executed this search on my data, over two different time ranges: "malware" | timechart count The time ranges wer...
by rahulgopal Explorer in Splunk Search 12-27-2013
0 4
0
4
phoenixdigital
Someone just asked me if it was possible to have something like a slider on the app setup page for entry of data. So...
by phoenixdigital Builder in Splunk Search 12-26-2013
0 1
0
1
rmorlen
We have a user lookup table that contains information such as username, email, and managername. I can do a lookup to...
by rmorlen Splunk Employee Splunk Employee in Splunk Search 12-26-2013
0 2
0
2
appleman
Hello, My search: index=test sourcetype=traffic | stats sum(A) as A sum(B) as B sum(C) as C sum(D) as D | transpose ...
by appleman Contributor in Splunk Search 12-25-2013
0 2
0
2
rossikwan
sourcetype=xxx earliest=-1d@d latest=-0d@d | stats count by host | append [search earliest=-2d@d latest=-1d@d | stats...
by rossikwan Path Finder in Splunk Search 12-25-2013
0 4
0
4
sunrise
Hi Splunkers, I want to know the index time lag in subsecond order by following command. index=main | eval index_la...
by sunrise Contributor in Splunk Search 12-25-2013
0 2
0
2
yuwtennis
Hi! I would like to know what pulldown_type option (props.conf) affects in splunk. Are there any description in the ...
by yuwtennis Communicator in Splunk Search 12-25-2013
1 1
1
1
grijhwani
Demonstrated below: Black text on dark grey background - totally useless from an accessibility perspective. What ha...
by grijhwani Motivator in Splunk Search 12-24-2013
0 4
0
4
andrewkenth
I'm almost certian I used the wrong lingo but I'd like to essentially create a field based on search or regex, but I ...
by andrewkenth Communicator in Splunk Search 12-23-2013
0 1
0
1
kennethp
I have a index that contains both destination and source countries in each entry. I would like to get a list over top...
by kennethp Engager in Splunk Search 12-23-2013
1 1
1
1
moohkhol
Hi Guys, My log message looks like below, Time message 10:00 AM “log message 1” 10:10 AM “log message...
by moohkhol New Member in Splunk Search 12-23-2013
0 1
0
1
yuwtennis
Hi! I would like to do something similar to sprintf of perl. Which would be like, sprintf("%02d) put a 0 in front...
by yuwtennis Communicator in Splunk Search 12-23-2013
0 2
0
2
teedilo
Is there a way to inhibit alerts from saved searches that had errors? Saved searches will sometimes fail with errors...
by teedilo Path Finder in Splunk Search 12-23-2013
3 10
3
10
Snazter57
Hi all, I am having trouble displaying search results when I specify that the returned results must be greater than ...
by Snazter57 New Member in Splunk Search 12-23-2013
0 5
0
5
mkelderm
I like the predict clause, but how can I show only the prediction of the 'future'. For example: index=prd_stats earl...
by mkelderm Path Finder in Splunk Search 12-23-2013
0 2
0
2
harshal_chakran
Hi, I have a sourcetype = ALLXMLDATA, where I have added multiple XML files as data inputs such XMLfile1, XMLfile2 a...
by harshal_chakran Builder in Splunk Search 12-22-2013
0 3
0
3
harshal_chakran
Hi, I have 2 data logs "datasource1" and "datasource2", under same sourcetype name="DATALOGS", for e.g. datasource1...
by harshal_chakran Builder in Splunk Search 12-22-2013
0 3
0
3
harshal_chakran
Hi, I have written a search query which shows a specific value from the datalog. what i want is to show the reult in...
by harshal_chakran Builder in Splunk Search 12-22-2013
0 1
0
1
mileven
Currently trying to limit logs out of the application, security, and system logs. I want to send only application an...
by mileven Explorer in Splunk Search 12-20-2013
0 2
0
2
david_rundle_fi
I'm trying to search for multiple rule event hits in my historical data: Date 1, Rule A, NumAlerts 15 Date 1, Rule B...
by david_rundle_fi Explorer in Splunk Search 12-20-2013
0 2
0
2
BBakkenes
Hello Splunky's, I'am working on a project and want to correlate a couple of id's on different logs and got the time...
by BBakkenes Explorer in Splunk Search 12-20-2013
0 1
0
1
tbo
I have two fields, say foo and bar. They both have the same format. An example of the fields could be foo="{a=3, b=4...
by tbo Explorer in Splunk Search 12-19-2013
0 4
0
4
julirodr
Hi, I want put an alert witch detect non authorized connection. In order to do that I have integrate some workstatio...
by julirodr New Member in Splunk Search 12-19-2013
0 3
0
3
JoeSco27
"2013-12-19 11:13:23", "[INFO]", "30927", "MainProcess", "SSMITH" My data is coming into Splunk in this format, and ...
by JoeSco27 Communicator in Splunk Search 12-19-2013
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...