Splunk Search

Splunk Search
Community Activity
anjafischer
Hello, I am trying to figure out how to combine the following search and subsearch into one search such that I can u...
by anjafischer Path Finder in Splunk Search 11-15-2013
0 3
0
3
woodcock
I had a perfectly coherent question but when I clicked the "Ask Your Question" button, I saw that the most important ...
by Esteemed Legend in Splunk Search 11-14-2013
3 3
3
3
CharterBT
Hope someone is up for a challenge. Here's the query I'm using. index=[app] [keyword] earliest=10/01/2013:0:0:0 lat...
by CharterBT Explorer in Splunk Search 11-14-2013
0 1
0
1
ser72
I have Splunk set up on Windows 7. Set to receive on port 9997. I have Splunk Universal Forwarder on Ubuntu set to f...
by ser72 New Member in Splunk Search 11-14-2013
0 2
0
2
carljohan
I have a log file namned: wrapper.log This log file has two different type of events defined with the prefix INFO or ...
by carljohan Path Finder in Splunk Search 11-14-2013
0 10
0
10
dmlee
Hi the table module support horizontal scrolling ? I do not see the scroll bar , when there are too many columns i...
by dmlee Communicator in Splunk Search 11-14-2013
0 4
0
4
pil321
not sure how this happened, but I have the same host listed twice; once in all lower case (host1) and once in all CAP...
by pil321 Communicator in Splunk Search 11-14-2013
0 1
0
1
fredclown
We currently have a scripted input into Splunk that is a CSV and we are doing field extractions via regex. This is no...
by fredclown Builder in Splunk Search 11-14-2013
0 2
0
2
dhammad
Hello All - I have the following search query with following search results below. What I like to do is to limit the ...
by dhammad New Member in Splunk Search 11-14-2013
0 2
0
2
capilarity
I'm monitoring DHCP logs and I'm trying to separate out known device types with the aim of looking for unknown device...
by capilarity Path Finder in Splunk Search 11-14-2013
0 2
0
2
pil321
I'm trying to do a search for servers that have reported to verify their status (server up or server down). I have so...
by pil321 Communicator in Splunk Search 11-14-2013
0 2
0
2
andrewkenth
Is it possible to hide certain fields from users based on roles or some other granularity? I'm interested in giving...
by andrewkenth Communicator in Splunk Search 11-13-2013
2 2
2
2
thiliphk
Team, Please guide me to configure my wireless router to send the data over to Splunk ( My laptop) How to validate ...
by thiliphk New Member in Splunk Search 11-13-2013
0 4
0
4
nl_cape
I have two sourcetypes, one containing alerts from users that we have a problem, and another one with server logs. In...
by nl_cape Explorer in Splunk Search 11-13-2013
0 6
0
6
mcbradford
I have a field called "user". I am looking for matches that contain 6 or 7 characters, and always end with "a" but do...
by mcbradford Contributor in Splunk Search 11-13-2013
0 7
0
7
aelliott
I have a Splunk DB Connect input setup that simply runs a sql query to grab events from sql. I have a template as my...
by aelliott Motivator in Splunk Search 11-13-2013
1 20
1
20
DerekB
I upgraded to 6.0 and now my field extractions don't work at all. In fact I don't get any fields extracted when I run...
by DerekB Splunk Employee Splunk Employee in Splunk Search 11-13-2013
1 1
1
1
royimad
How do i write a query on SPL to have a flag when next value on events is greater then the precedence value? Here...
by royimad Builder in Splunk Search 11-13-2013
0 1
0
1
itgmidrange
I have been trying to complete a search whicj includes several ealiest and latest statements. I need to search betwe...
by itgmidrange New Member in Splunk Search 11-13-2013
0 2
0
2
sarumjanuch
Hi is there any way to return same value if not found in lookup table? i.e. I have file users.csv code,name 100,jh...
by sarumjanuch Path Finder in Splunk Search 11-13-2013
1 2
1
2
iKate
Hi! I have a lookup table with time srings like this: 2013.11 and I want splunk to understand it is a time and make ...
by iKate Builder in Splunk Search 11-13-2013
0 8
0
8
harshal_chakran
Hi, I need to find the value of PLANDATA_TYPE from the given string in my logs i.e. PLANDATA_TYPE: ASBFGH, PLANWORK...
by harshal_chakran Builder in Splunk Search 11-13-2013
0 5
0
5
jodros
I have two fields, src_ip and dest_ip. These two fields show up in the same log. I am trying to merge all values of...
by jodros Builder in Splunk Search 11-13-2013
1 19
1
19
toolsops
I am using a timechart query to display data for each task(TASK_ID) and time taken for completing a task. It is plott...
by toolsops New Member in Splunk Search 11-13-2013
0 3
0
3
ESIMatNeforce
I have a problem concerming multivalued fields. i wanted to create a dashboard which shows failed logins per user wi...
by ESIMatNeforce Path Finder in Splunk Search 11-13-2013
0 3
0
3
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

[Puzzles] Solve, Learn, Repeat: Family Trees

This puzzle (first published here is based on finding grandparents and grandchildren (inspired by a question ...