Splunk Search

Splunk Search
Community Activity
xvxt006
Hi, we have 2 uri patterns as shown below /search?searchQuery=4gmw4 (the end part is always single word which is al...
by xvxt006 Contributor in Splunk Search 10-27-2013
0 4
0
4
skippylou
Trying to figure out if this is possible. Many times I do a search similar to: host=somehosts* earliest=-1d | clust...
by skippylou Communicator in Splunk Search 10-27-2013
2 4
2
4
tristanmatthews
Hi, I have a weird data structure I'm trying to figure out a better way to handle. The data I'm getting uses categor...
by tristanmatthews Path Finder in Splunk Search 10-27-2013
0 2
0
2
sourabhguha
Hi, Following is my input. It is a set of tab delimited files. Here is a sample. I made updates to props.conf and tr...
by sourabhguha Explorer in Splunk Search 10-27-2013
0 4
0
4
HeinzWaescher
Hi everbody, I have got a field "Action" with different Values (A,B,C,D,E). I would like to calculate the percentage...
by HeinzWaescher Motivator in Splunk Search 10-27-2013
0 2
0
2
yuwtennis
Hi! I want to ask question if something like below can be implemented. I have created 4 searches. search A : creat...
by yuwtennis Communicator in Splunk Search 10-27-2013
0 2
0
2
yuwtennis
Hi ! I would like to get an advice with search command. I want to do something like , Reference the next row (line...
by yuwtennis Communicator in Splunk Search 10-27-2013
0 2
0
2
sourabhguha
Hi, I am indexing a set of csv files. the files do not have the header fields in it. While I am creating the source...
by sourabhguha Explorer in Splunk Search 10-27-2013
0 1
0
1
kaddupa1
I just noticed that the alert... menu item under Create in the search App is not available anymore for users with rol...
by kaddupa1 Explorer in Splunk Search 10-26-2013
1 1
1
1
gsawyer1
Another awesome Regex question, related to windows. I have a windows EventCode=4663. The event contains a Process_N...
by gsawyer1 Engager in Splunk Search 10-25-2013
0 4
0
4
albyva
Using this set of data: Time Host Type Packets 12:00 mothra A 5 12:05 mothra A 6 12:10 ...
by albyva Communicator in Splunk Search 10-25-2013
0 2
0
2
jeremiahc4
I indexed some csv data which has a field called Open Time which winds up being selected as the _time and looks fine ...
by jeremiahc4 Builder in Splunk Search 10-25-2013
1 2
1
2
rdownie
Using the dbconnect app without using advance(query), is there a way to make your lookup case insensitive by adding c...
by rdownie Communicator in Splunk Search 10-25-2013
0 1
0
1
paragcisco
Hi, Is there splunk tool chain that simply sends splunk commands to the daemon (does not include daemon and web inte...
by paragcisco Explorer in Splunk Search 10-25-2013
1 6
1
6
lehrfeld
I have two sourcetypes - submitters, and recipient_group. I am looking to find the percentage of submitters that are...
by lehrfeld Path Finder in Splunk Search 10-25-2013
0 3
0
3
cdupuis123
2013-10-25 10:49:33,Major,REMOVED,Allowed, - Caller MD5=61b1dfb9703d0d678e108e0156fcbb69,Create Process,Begin: 2013-1...
by cdupuis123 Path Finder in Splunk Search 10-25-2013
0 3
0
3
sowings
I'm building a dashboard using the techniques described here on Splunkbase, so that I have two Y axes. What I'm seein...
by sowings Splunk Employee Splunk Employee in Splunk Search 10-25-2013
1 4
1
4
MikeSilady
I'm following the tutorial at your page 46. The popup menu that I see has a "Destination app" field with search above...
by MikeSilady Explorer in Splunk Search 10-25-2013
0 3
0
3
srajanbabu
I have the below search index=main sourcetype=summa | rex "::\s(?<timestamp>\S+)\s" | rex "^\S+\s(?<userid>\S+)\."...
by srajanbabu Explorer in Splunk Search 10-25-2013
0 6
0
6
multiverse
It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk cr...
by multiverse Engager in Splunk Search 10-25-2013
0 2
0
2
brywilk_umich
Hello, I have the a search that is working and I get the desired output. Now I am trying to make the output "prett...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
1 2
1
2
richnavis
Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick.. www-ber 10/18/2...
by richnavis Contributor in Splunk Search 10-24-2013
0 3
0
3
cdupuis123
I have this event and I'm trying to send it to the nullQueue if it contains SYSTEM. 2013-10-24 15:02:34,Major,REMOVE...
by cdupuis123 Path Finder in Splunk Search 10-24-2013
0 1
0
1
ytl
i have events with two fields: origin and duration i would like to present a table with the count of each origin, al...
by ytl Path Finder in Splunk Search 10-24-2013
0 1
0
1
brywilk_umich
Hello, I am new to Splunk and trying to come up with a way that would grab the usernames in certain lines (21_ubl) o...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
0 4
0
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...