Splunk Search

Splunk Search
Community Activity
gsawyer1
I've got input from a syslog source, that looks like this: 2012-10-10 04:04:52[connection-5] AUTH: User xxx authenti...
by gsawyer1 Engager in Splunk Search 01-02-2014
0 5
0
5
echojacques
Hi, This is one of the canned correlation searches included in Splunk Enterprise Security. How can I exclude events...
by echojacques Builder in Splunk Search 01-02-2014
0 4
0
4
kunadkat
I want to tabulate peak period and low periods for my web transactions. The following search works but not very effic...
by kunadkat Explorer in Splunk Search 01-02-2014
1 5
1
5
harshal_chakran
Hi, I have a CLI query which works perfectly on Splunk Web terminal and the same thing I want to replicate it using ...
by harshal_chakran Builder in Splunk Search 01-02-2014
0 1
0
1
jowilliams
We currently have our web filtering logs forwarded to Splunk. I have been asked to provide a report that doesn't just...
by jowilliams New Member in Splunk Search 01-02-2014
0 5
0
5
dangerdx
I want to combine two regular expressions.Please help me. \b(2013)[- /.](0[1-9]|1[012])[- /.](0[1-9]|[12][0-9]|3[01]...
by dangerdx New Member in Splunk Search 01-02-2014
0 7
0
7
Avarion
Hi, I'm struggling with doing a regex search. I want to search the whole log files for credit card information. Sin...
by Avarion New Member in Splunk Search 01-02-2014
0 4
0
4
nikhilmehra79
Any disadvantages if we are running real time searches and alerting using those, currently we are testing few functio...
by nikhilmehra79 Path Finder in Splunk Search 12-31-2013
0 2
0
2
bojanz
I'm using fieldformat (Splunk 5.0.5, search head in a cluster, if that matters) in order to change how the time is di...
by bojanz Communicator in Splunk Search 12-31-2013
0 4
0
4
jonthanze
Hi I have a list of words in a lookup table and i would like to return the events of a search that match any of the ...
by jonthanze Explorer in Splunk Search 12-31-2013
0 2
0
2
ashleyherbert
We've just upgraded to V6, and one of the first things I've noticed is that you can't use the Alt-Click to add the NO...
by ashleyherbert Communicator in Splunk Search 12-30-2013
5 1
5
1
c_sahil
I am having a field deliveryExpiry (String type) in my log and I want to compare whether the expiry is before the cur...
by c_sahil New Member in Splunk Search 12-30-2013
0 4
0
4
dshpritz
Hey everyone, So this feels like something I should be able to do with the standard search language, but I am failin...
by SplunkTrust SplunkTrust in Splunk Search 12-27-2013
3 4
3
4
klee310
Hello & merry xmas to all, I would like to create a macro-expansion using searchmatch (eval-command) such that the a...
by klee310 Communicator in Splunk Search 12-27-2013
0 2
0
2
rahulgopal
I executed this search on my data, over two different time ranges: "malware" | timechart count The time ranges wer...
by rahulgopal Explorer in Splunk Search 12-27-2013
0 4
0
4
phoenixdigital
Someone just asked me if it was possible to have something like a slider on the app setup page for entry of data. So...
by phoenixdigital Builder in Splunk Search 12-26-2013
0 1
0
1
rmorlen
We have a user lookup table that contains information such as username, email, and managername. I can do a lookup to...
by rmorlen Splunk Employee Splunk Employee in Splunk Search 12-26-2013
0 2
0
2
appleman
Hello, My search: index=test sourcetype=traffic | stats sum(A) as A sum(B) as B sum(C) as C sum(D) as D | transpose ...
by appleman Contributor in Splunk Search 12-25-2013
0 2
0
2
rossikwan
sourcetype=xxx earliest=-1d@d latest=-0d@d | stats count by host | append [search earliest=-2d@d latest=-1d@d | stats...
by rossikwan Path Finder in Splunk Search 12-25-2013
0 4
0
4
sunrise
Hi Splunkers, I want to know the index time lag in subsecond order by following command. index=main | eval index_la...
by sunrise Contributor in Splunk Search 12-25-2013
0 2
0
2
yuwtennis
Hi! I would like to know what pulldown_type option (props.conf) affects in splunk. Are there any description in the ...
by yuwtennis Communicator in Splunk Search 12-25-2013
1 1
1
1
grijhwani
Demonstrated below: Black text on dark grey background - totally useless from an accessibility perspective. What ha...
by grijhwani Motivator in Splunk Search 12-24-2013
0 4
0
4
andrewkenth
I'm almost certian I used the wrong lingo but I'd like to essentially create a field based on search or regex, but I ...
by andrewkenth Communicator in Splunk Search 12-23-2013
0 1
0
1
kennethp
I have a index that contains both destination and source countries in each entry. I would like to get a list over top...
by kennethp Engager in Splunk Search 12-23-2013
1 1
1
1
moohkhol
Hi Guys, My log message looks like below, Time message 10:00 AM “log message 1” 10:10 AM “log message...
by moohkhol New Member in Splunk Search 12-23-2013
0 1
0
1
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...