Splunk Search

Splunk Search
Community Activity
jeremiahc4
I indexed some csv data which has a field called Open Time which winds up being selected as the _time and looks fine ...
by jeremiahc4 Builder in Splunk Search 10-25-2013
1 2
1
2
rdownie
Using the dbconnect app without using advance(query), is there a way to make your lookup case insensitive by adding c...
by rdownie Communicator in Splunk Search 10-25-2013
0 1
0
1
paragcisco
Hi, Is there splunk tool chain that simply sends splunk commands to the daemon (does not include daemon and web inte...
by paragcisco Explorer in Splunk Search 10-25-2013
1 6
1
6
lehrfeld
I have two sourcetypes - submitters, and recipient_group. I am looking to find the percentage of submitters that are...
by lehrfeld Path Finder in Splunk Search 10-25-2013
0 3
0
3
cdupuis123
2013-10-25 10:49:33,Major,REMOVED,Allowed, - Caller MD5=61b1dfb9703d0d678e108e0156fcbb69,Create Process,Begin: 2013-1...
by cdupuis123 Path Finder in Splunk Search 10-25-2013
0 3
0
3
sowings
I'm building a dashboard using the techniques described here on Splunkbase, so that I have two Y axes. What I'm seein...
by sowings Splunk Employee Splunk Employee in Splunk Search 10-25-2013
1 4
1
4
MikeSilady
I'm following the tutorial at your page 46. The popup menu that I see has a "Destination app" field with search above...
by MikeSilady Explorer in Splunk Search 10-25-2013
0 3
0
3
srajanbabu
I have the below search index=main sourcetype=summa | rex "::\s(?<timestamp>\S+)\s" | rex "^\S+\s(?<userid>\S+)\."...
by srajanbabu Explorer in Splunk Search 10-25-2013
0 6
0
6
multiverse
It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk cr...
by multiverse Engager in Splunk Search 10-25-2013
0 2
0
2
brywilk_umich
Hello, I have the a search that is working and I get the desired output. Now I am trying to make the output "prett...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
1 2
1
2
richnavis
Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick.. www-ber 10/18/2...
by richnavis Contributor in Splunk Search 10-24-2013
0 3
0
3
cdupuis123
I have this event and I'm trying to send it to the nullQueue if it contains SYSTEM. 2013-10-24 15:02:34,Major,REMOVE...
by cdupuis123 Path Finder in Splunk Search 10-24-2013
0 1
0
1
ytl
i have events with two fields: origin and duration i would like to present a table with the count of each origin, al...
by ytl Path Finder in Splunk Search 10-24-2013
0 1
0
1
brywilk_umich
Hello, I am new to Splunk and trying to come up with a way that would grab the usernames in certain lines (21_ubl) o...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
0 4
0
4
hartfoml
Here is my DNS raw data: Oct 17 19:47:09 ns1 named[15517]: 17-Oct-2013 19:47:09.314 queries: client xxx.xxx.xxx.xxx#...
by hartfoml Motivator in Splunk Search 10-24-2013
1 4
1
4
lohit
Hi , I have some forwarders installed in my environment and want to calculate the peak time in which log sources for...
by lohit Path Finder in Splunk Search 10-24-2013
1 5
1
5
Nisha18789
I have a site and errors on that site are being recorded in splunk. I basically need to filter out those error which ...
by Nisha18789 Builder in Splunk Search 10-24-2013
0 6
0
6
nekb1958
Hi the following search eval test=7200 | convert timeformat="%H:%M:%S" ctime(test) | table test gives me 03:00:00 ...
by nekb1958 Path Finder in Splunk Search 10-24-2013
0 4
0
4
lohit
Hello everyone, I have around 20 forwarders (Universal) in my env and configued to forward data to Splunk Indexer. I...
by lohit Path Finder in Splunk Search 10-24-2013
0 1
0
1
tim9gray
Hi All, I am monitoring files that land in the same directory that I wish to be considered as different source types...
by tim9gray Explorer in Splunk Search 10-23-2013
0 13
0
13
the_wolverine
I'd like to run the following search on my indexer to calculate compression. It works in UI, but not in CLI. I have...
by the_wolverine Champion in Splunk Search 10-23-2013
0 2
0
2
tscanlon
Setting up Splunk I'm getting rsyslog messages showing up fine but when I point a little test log4j app at it I start...
by tscanlon Engager in Splunk Search 10-23-2013
0 2
0
2
tnconners
Background: We have an existing indexer, that we have added a lot of data to. We would like to cut down on the amount...
by tnconners Explorer in Splunk Search 10-23-2013
0 3
0
3
tfitzgerald15
This has been giving me headaches for a long time now, and it's pretty simple. So, for reference, this search works a...
by tfitzgerald15 Explorer in Splunk Search 10-23-2013
0 3
0
3
splunknovice201
I have a duration field in seconds. I wanted the format to be D+hh:mm:ss, so I used this: eval dur_hhmmss=tostring(D...
by splunknovice201 New Member in Splunk Search 10-23-2013
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...