Splunk Search

Splunk Search
Community Activity
gwu
Here's my search string: host=abc* source="/log...*" | rex "^[\d|-]+ [\d|:|,]+ (?P<Identifier>[\w\w|_]+)\s" | transa...
by gwu New Member in Splunk Search 12-14-2013
0 2
0
2
mklunder
Given the following log entry how would a find the number of host entries and assign it to a field? Thanks! FINEST|...
by mklunder Explorer in Splunk Search 12-14-2013
0 2
0
2
rizzo75
Hi - I am trying to wrap my head around the following search - looking at join, appendcols and map commands to get th...
by rizzo75 Path Finder in Splunk Search 12-14-2013
0 1
0
1
OldManEd
I have a simple search query that is collecting data from XML. The search query is below; sourcetype=someSourceType...
by OldManEd Builder in Splunk Search 12-13-2013
0 4
0
4
jbouch03
Having trouble getting a lookup table to replace my results. I have a lookup file that contains the following info: ...
by jbouch03 Path Finder in Splunk Search 12-13-2013
1 2
1
2
albyva
I'm trying to just chart the NTP offsets from the Loopstats file. Here is a sample of the data source: Day Seconds...
by albyva Communicator in Splunk Search 12-13-2013
0 2
0
2
ctripod
Hi all! Does transaction calculate duration per "transaction" or from the first event in the transaction to the last...
by ctripod Explorer in Splunk Search 12-13-2013
0 2
0
2
sriva6
Hi, I have the below query to compare the date I am extracting from logs with the current date: (sourcetype="XYZ") ...
by sriva6 New Member in Splunk Search 12-13-2013
0 3
0
3
ccsfdave
Greetings, I am trying to write a regex but am not successful as of yet. I am trying to match the: Bot: Mariposa Co...
by ccsfdave Builder in Splunk Search 12-13-2013
0 4
0
4
jerwood
This may be simple, but I am pretty new to splunk in general and my attempts have not proved fruitful yet. So I have...
by jerwood New Member in Splunk Search 12-13-2013
0 2
0
2
stimpfl
Can anybody tellme how should my asa be configured in order to receive data into splunk ? what I mean is... my splunk...
by stimpfl New Member in Splunk Search 12-13-2013
0 1
0
1
sriva6
Hi, I have two different sourcetypes and I am extrating two fields from the first sourcetype sourcetype1 and I need ...
by sriva6 New Member in Splunk Search 12-13-2013
0 7
0
7
dishasaxena
Is there any way to accelerate searches which are being used in forms. Since,we cannot save form searches as they con...
by dishasaxena Path Finder in Splunk Search 12-13-2013
0 2
0
2
lsmkelvin
Just for my interest. Hope some one can answer my question and with thanks. ^^ Can i remove or add the warm database...
by lsmkelvin New Member in Splunk Search 12-12-2013
0 2
0
2
w531t4
Hi all, I found an answer here on the Splunk forums that shows a good search to list the current size of indexes as ...
by w531t4 Path Finder in Splunk Search 12-12-2013
0 8
0
8
tonytang
Hi,all, I made a real-time search with my own index,it looks like it can only scan event once, after one scan,splun...
by tonytang Explorer in Splunk Search 12-12-2013
2 1
2
1
lehrfeld
Hi All - I'm working on creating a summary report and I am having difficulty discerning the various addtotals or addc...
by lehrfeld Path Finder in Splunk Search 12-12-2013
0 2
0
2
sanjay_shrestha
Following query has been used to calculate duration for individual source (input files) for last 5 days: index="my_i...
by sanjay_shrestha Contributor in Splunk Search 12-12-2013
0 5
0
5
aaronkorn
Hello, We have a primary alerting server that only us admins manage to setup alerts which sends out snmp traps of tr...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 12-12-2013
0 2
0
2
yuwtennis
Hi! I am considering to implement two separate indexes containing non-anonymized data and anonyimized on the other. ...
by yuwtennis Communicator in Splunk Search 12-12-2013
0 5
0
5
andrewkenth
I can't beleive I'm coming to Answers to ask this as I've done it many times before but I must be missing something t...
by andrewkenth Communicator in Splunk Search 12-12-2013
0 10
0
10
rmorlen
We keep getting the message: "WARN DispatchReaper - Too many search jobs found in the dispatch directory (found=3575...
by rmorlen Splunk Employee Splunk Employee in Splunk Search 12-12-2013
0 3
0
3
vinorama
I have two logs: Log 1: 12/5/13 3:29:14.000 peter is a dog 12/5/13 3:30:14.000 paul is a cat Log 2: 12/5/13 3:30:14...
by vinorama Explorer in Splunk Search 12-12-2013
0 6
0
6
lgmnemesis
We are logging the following application network statistics. I want to be able to index the data into splunk so we ca...
by lgmnemesis Explorer in Splunk Search 12-11-2013
0 5
0
5
104K
Hello Splunkers, I have two different sourcetypes that can be grouped by a unique id where one sourcetype has some n...
by 104K Engager in Splunk Search 12-11-2013
0 2
0
2
Get Updates on the Splunk Community!

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors