Splunk Search

Splunk Search
Community Activity
MikeSilady
I'm following the tutorial at your page 46. The popup menu that I see has a "Destination app" field with search above...
by MikeSilady Explorer in Splunk Search 10-25-2013
0 3
0
3
srajanbabu
I have the below search index=main sourcetype=summa | rex "::\s(?<timestamp>\S+)\s" | rex "^\S+\s(?<userid>\S+)\."...
by srajanbabu Explorer in Splunk Search 10-25-2013
0 6
0
6
multiverse
It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk cr...
by multiverse Engager in Splunk Search 10-25-2013
0 2
0
2
brywilk_umich
Hello, I have the a search that is working and I get the desired output. Now I am trying to make the output "prett...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
1 2
1
2
richnavis
Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick.. www-ber 10/18/2...
by richnavis Contributor in Splunk Search 10-24-2013
0 3
0
3
cdupuis123
I have this event and I'm trying to send it to the nullQueue if it contains SYSTEM. 2013-10-24 15:02:34,Major,REMOVE...
by cdupuis123 Path Finder in Splunk Search 10-24-2013
0 1
0
1
ytl
i have events with two fields: origin and duration i would like to present a table with the count of each origin, al...
by ytl Path Finder in Splunk Search 10-24-2013
0 1
0
1
brywilk_umich
Hello, I am new to Splunk and trying to come up with a way that would grab the usernames in certain lines (21_ubl) o...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
0 4
0
4
hartfoml
Here is my DNS raw data: Oct 17 19:47:09 ns1 named[15517]: 17-Oct-2013 19:47:09.314 queries: client xxx.xxx.xxx.xxx#...
by hartfoml Motivator in Splunk Search 10-24-2013
1 4
1
4
lohit
Hi , I have some forwarders installed in my environment and want to calculate the peak time in which log sources for...
by lohit Path Finder in Splunk Search 10-24-2013
1 5
1
5
Nisha18789
I have a site and errors on that site are being recorded in splunk. I basically need to filter out those error which ...
by Nisha18789 Builder in Splunk Search 10-24-2013
0 6
0
6
nekb1958
Hi the following search eval test=7200 | convert timeformat="%H:%M:%S" ctime(test) | table test gives me 03:00:00 ...
by nekb1958 Path Finder in Splunk Search 10-24-2013
0 4
0
4
lohit
Hello everyone, I have around 20 forwarders (Universal) in my env and configued to forward data to Splunk Indexer. I...
by lohit Path Finder in Splunk Search 10-24-2013
0 1
0
1
tim9gray
Hi All, I am monitoring files that land in the same directory that I wish to be considered as different source types...
by tim9gray Explorer in Splunk Search 10-23-2013
0 13
0
13
the_wolverine
I'd like to run the following search on my indexer to calculate compression. It works in UI, but not in CLI. I have...
by the_wolverine Champion in Splunk Search 10-23-2013
0 2
0
2
tscanlon
Setting up Splunk I'm getting rsyslog messages showing up fine but when I point a little test log4j app at it I start...
by tscanlon Engager in Splunk Search 10-23-2013
0 2
0
2
tnconners
Background: We have an existing indexer, that we have added a lot of data to. We would like to cut down on the amount...
by tnconners Explorer in Splunk Search 10-23-2013
0 3
0
3
tfitzgerald15
This has been giving me headaches for a long time now, and it's pretty simple. So, for reference, this search works a...
by tfitzgerald15 Explorer in Splunk Search 10-23-2013
0 3
0
3
splunknovice201
I have a duration field in seconds. I wanted the format to be D+hh:mm:ss, so I used this: eval dur_hhmmss=tostring(D...
by splunknovice201 New Member in Splunk Search 10-23-2013
0 2
0
2
ejdavis
The props.conf and transforms.conf files that should be modified are under /etc/system/local, correct? We have been ...
by ejdavis Path Finder in Splunk Search 10-23-2013
0 13
0
13
echojacques
I've been playing around with eval, transaction, and stats and I still can't figure this one out... so I'm asking for...
by echojacques Builder in Splunk Search 10-23-2013
0 5
0
5
jeffreygaraygay
I get the error "Error in 'join' command: Usage: join <options> (<join-fields>)? [subsearch]" when running the follow...
by jeffreygaraygay Explorer in Splunk Search 10-23-2013
0 1
0
1
bowesmana
I've spent a long time reading, but am not sure the best way to do this. I have events, which contain username-xxx,...
by SplunkTrust SplunkTrust in Splunk Search 10-23-2013
0 4
0
4
jdastmalchi_spl
The flags such as exclude as explained in http://docs.splunk.com/Documentation/Splunk/6.0/Troubleshooting/ContactSplu...
by jdastmalchi_spl Splunk Employee Splunk Employee in Splunk Search 10-23-2013
1 1
1
1
kaddupa1
Hello, we are using SSO with LDAP based users for authentication on our search heads. On our search head; how do we ...
by kaddupa1 Explorer in Splunk Search 10-23-2013
1 2
1
2
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors