Splunk Search

Splunk Search
Community Activity
paragcisco
Hi, Is there splunk tool chain that simply sends splunk commands to the daemon (does not include daemon and web inte...
by paragcisco Explorer in Splunk Search 10-25-2013
1 6
1
6
lehrfeld
I have two sourcetypes - submitters, and recipient_group. I am looking to find the percentage of submitters that are...
by lehrfeld Path Finder in Splunk Search 10-25-2013
0 3
0
3
cdupuis123
2013-10-25 10:49:33,Major,REMOVED,Allowed, - Caller MD5=61b1dfb9703d0d678e108e0156fcbb69,Create Process,Begin: 2013-1...
by cdupuis123 Path Finder in Splunk Search 10-25-2013
0 3
0
3
sowings
I'm building a dashboard using the techniques described here on Splunkbase, so that I have two Y axes. What I'm seein...
by sowings Splunk Employee Splunk Employee in Splunk Search 10-25-2013
1 4
1
4
MikeSilady
I'm following the tutorial at your page 46. The popup menu that I see has a "Destination app" field with search above...
by MikeSilady Explorer in Splunk Search 10-25-2013
0 3
0
3
srajanbabu
I have the below search index=main sourcetype=summa | rex "::\s(?<timestamp>\S+)\s" | rex "^\S+\s(?<userid>\S+)\."...
by srajanbabu Explorer in Splunk Search 10-25-2013
0 6
0
6
multiverse
It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk cr...
by multiverse Engager in Splunk Search 10-25-2013
0 2
0
2
brywilk_umich
Hello, I have the a search that is working and I get the desired output. Now I am trying to make the output "prett...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
1 2
1
2
richnavis
Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick.. www-ber 10/18/2...
by richnavis Contributor in Splunk Search 10-24-2013
0 3
0
3
cdupuis123
I have this event and I'm trying to send it to the nullQueue if it contains SYSTEM. 2013-10-24 15:02:34,Major,REMOVE...
by cdupuis123 Path Finder in Splunk Search 10-24-2013
0 1
0
1
ytl
i have events with two fields: origin and duration i would like to present a table with the count of each origin, al...
by ytl Path Finder in Splunk Search 10-24-2013
0 1
0
1
brywilk_umich
Hello, I am new to Splunk and trying to come up with a way that would grab the usernames in certain lines (21_ubl) o...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
0 4
0
4
hartfoml
Here is my DNS raw data: Oct 17 19:47:09 ns1 named[15517]: 17-Oct-2013 19:47:09.314 queries: client xxx.xxx.xxx.xxx#...
by hartfoml Motivator in Splunk Search 10-24-2013
1 4
1
4
lohit
Hi , I have some forwarders installed in my environment and want to calculate the peak time in which log sources for...
by lohit Path Finder in Splunk Search 10-24-2013
1 5
1
5
Nisha18789
I have a site and errors on that site are being recorded in splunk. I basically need to filter out those error which ...
by Nisha18789 Builder in Splunk Search 10-24-2013
0 6
0
6
nekb1958
Hi the following search eval test=7200 | convert timeformat="%H:%M:%S" ctime(test) | table test gives me 03:00:00 ...
by nekb1958 Path Finder in Splunk Search 10-24-2013
0 4
0
4
lohit
Hello everyone, I have around 20 forwarders (Universal) in my env and configued to forward data to Splunk Indexer. I...
by lohit Path Finder in Splunk Search 10-24-2013
0 1
0
1
tim9gray
Hi All, I am monitoring files that land in the same directory that I wish to be considered as different source types...
by tim9gray Explorer in Splunk Search 10-23-2013
0 13
0
13
the_wolverine
I'd like to run the following search on my indexer to calculate compression. It works in UI, but not in CLI. I have...
by the_wolverine Champion in Splunk Search 10-23-2013
0 2
0
2
tscanlon
Setting up Splunk I'm getting rsyslog messages showing up fine but when I point a little test log4j app at it I start...
by tscanlon Engager in Splunk Search 10-23-2013
0 2
0
2
tnconners
Background: We have an existing indexer, that we have added a lot of data to. We would like to cut down on the amount...
by tnconners Explorer in Splunk Search 10-23-2013
0 3
0
3
tfitzgerald15
This has been giving me headaches for a long time now, and it's pretty simple. So, for reference, this search works a...
by tfitzgerald15 Explorer in Splunk Search 10-23-2013
0 3
0
3
splunknovice201
I have a duration field in seconds. I wanted the format to be D+hh:mm:ss, so I used this: eval dur_hhmmss=tostring(D...
by splunknovice201 New Member in Splunk Search 10-23-2013
0 2
0
2
ejdavis
The props.conf and transforms.conf files that should be modified are under /etc/system/local, correct? We have been ...
by ejdavis Path Finder in Splunk Search 10-23-2013
0 13
0
13
echojacques
I've been playing around with eval, transaction, and stats and I still can't figure this one out... so I'm asking for...
by echojacques Builder in Splunk Search 10-23-2013
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...