Splunk Search

Splunk Search
Community Activity
behymejt2012
Hi Everyone, Need a little help with regexing out a portion of a directory path. The examples below are the current ...
by behymejt2012 Path Finder in Splunk Search 11-04-2013
0 8
0
8
the_wolverine
Got this question today from someone who needs to reverse the order of the search results for their troubleshooting p...
by the_wolverine Champion in Splunk Search 11-04-2013
3 5
3
5
mzorzi
Is it possible to configure splunk searches to be multithreaded in a single box, that is - make single splunk-search ...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 11-03-2013
10 7
10
7
xvxt006
Hi, I am trying to get conversion and average order value and i am using eval function to calculate these. But i wan...
by xvxt006 Contributor in Splunk Search 11-03-2013
0 3
0
3
flaviadonno
Hi all, is there a quick way to find the earliest event (given the logtype and the index) matching a query ?
by flaviadonno Explorer in Splunk Search 11-03-2013
2 3
2
3
usethedata
I have a summary index where I record an event for each VPN session for users, tracking things like the client IP add...
by usethedata Path Finder in Splunk Search 11-03-2013
0 3
0
3
tristanmatthews
I'm running a scheduled search that uses the script command to call a python script, which generates a file. I'd real...
by tristanmatthews Path Finder in Splunk Search 11-01-2013
0 1
0
1
RMartinezDTV
Hi, I feel like this is a deceptively simple question, but I'm fairly new to Splunk. I want to find the avg transact...
by RMartinezDTV Path Finder in Splunk Search 11-01-2013
0 4
0
4
arpoador
I have two fields: EventCode (66 distinct values) and date_mday (28 distinct values) But when I run: ' * | continge...
by arpoador New Member in Splunk Search 11-01-2013
0 3
0
3
hartfoml
Here is what my DNS logs look line `Oct 31 23:59:59 ns2 named[19971]: 31-Oct-2013 23:59:59.999 queries: client xxx.x...
by hartfoml Motivator in Splunk Search 11-01-2013
0 2
0
2
adriangrassi
I have this field which display the total number of transactions since the server has been started. I need to find ou...
by adriangrassi Explorer in Splunk Search 11-01-2013
0 2
0
2
jpass
I have a scripted input with events that I want to send to different indexes based on a string within the event. I do...
by jpass Contributor in Splunk Search 11-01-2013
1 1
1
1
splunknovice201
I have this search index="jobs" host="abcp11" source="/work/grid_jobdir*.nodeFile" | rex field=source "(?i)/grid_jobd...
by splunknovice201 New Member in Splunk Search 11-01-2013
0 3
0
3
aholzer
I have created a few very straight-forward eventtype (ET) definitions. Example: ET1 index=myindex sourcetype=myst1 ...
by aholzer Motivator in Splunk Search 11-01-2013
1 5
1
5
royimad
How to extract date YYYYMMDD from _time?
by royimad Builder in Splunk Search 11-01-2013
2 3
2
3
jdomar
I would like to set a search timeframe of 1 week and for each day report the subtotals of Items 1, 2 and 3 (the items...
by jdomar Engager in Splunk Search 11-01-2013
0 2
0
2
jmheaton
So i want to create a table where i define the first column and then a search fills in results in the second column. ...
by jmheaton Path Finder in Splunk Search 11-01-2013
0 4
0
4
rdownie
I am trying to merge 3 lookup files having them join on one field but keep all additional fields and records(that don...
by rdownie Communicator in Splunk Search 11-01-2013
0 6
0
6
tmarlette
I am attempting to count the number of times a user has made a web server 'hit', and also display the average latency...
by tmarlette Motivator in Splunk Search 11-01-2013
0 3
0
3
darksky21
Hi i have a timechart | timechart count by serial_number is there a way to change the use of _time to another date ...
by darksky21 Path Finder in Splunk Search 11-01-2013
1 2
1
2
Glenn
I have summary search creating summarised data (number of accesses in an access log) once per minute (we are specifyi...
by Glenn Builder in Splunk Search 10-31-2013
1 5
1
5
giovere
I'm having log file which looks like this: name___________;ip_____________;soemeid_ Bob ;127.0.0.1 ...
by giovere Path Finder in Splunk Search 10-31-2013
0 3
0
3
helge
Some of my events have an unknown number of field names with a common naming scheme. In my searches I use a wildcard ...
by helge Builder in Splunk Search 10-31-2013
1 6
1
6
preben12
I have some sample data generated from curl -k -u admin:password https://localhost:8089/services/search/jobs/export ...
by preben12 Communicator in Splunk Search 10-31-2013
0 1
0
1
peter_gianusso
Simple one that I cannot find an answer to. I would like to know the number of events indexed yesterday for the inde...
by peter_gianusso Communicator in Splunk Search 10-31-2013
0 1
0
1
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...