| Hi, we have 2 uri patterns as shown below /search?searchQuery=4gmw4 (the end part is always single word which is al... by xvxt006 Contributor in Splunk Search 10-27-2013 0 4 | 0 | 4 | ||
| Trying to figure out if this is possible. Many times I do a search similar to: host=somehosts* earliest=-1d | clust... by skippylou Communicator in Splunk Search 10-27-2013 2 4 | 2 | 4 | ||
| Hi, I have a weird data structure I'm trying to figure out a better way to handle. The data I'm getting uses categor... by tristanmatthews Path Finder in Splunk Search 10-27-2013 0 2 | 0 | 2 | ||
| Hi, Following is my input. It is a set of tab delimited files. Here is a sample. I made updates to props.conf and tr... by sourabhguha Explorer in Splunk Search 10-27-2013 0 4 | 0 | 4 | ||
| Hi everbody, I have got a field "Action" with different Values (A,B,C,D,E). I would like to calculate the percentage... by HeinzWaescher Motivator in Splunk Search 10-27-2013 0 2 | 0 | 2 | ||
| Hi! I want to ask question if something like below can be implemented. I have created 4 searches. search A : creat... by yuwtennis Communicator in Splunk Search 10-27-2013 0 2 | 0 | 2 | ||
| Hi ! I would like to get an advice with search command. I want to do something like , Reference the next row (line... by yuwtennis Communicator in Splunk Search 10-27-2013 0 2 | 0 | 2 | ||
| Hi, I am indexing a set of csv files. the files do not have the header fields in it. While I am creating the source... by sourabhguha Explorer in Splunk Search 10-27-2013 0 1 | 0 | 1 | ||
| I just noticed that the alert... menu item under Create in the search App is not available anymore for users with rol... by kaddupa1 Explorer in Splunk Search 10-26-2013 1 1 | 1 | 1 | ||
| Another awesome Regex question, related to windows. I have a windows EventCode=4663. The event contains a Process_N... by gsawyer1 Engager in Splunk Search 10-25-2013 0 4 | 0 | 4 | ||
| Using this set of data: Time Host Type Packets 12:00 mothra A 5 12:05 mothra A 6 12:10 ... by albyva Communicator in Splunk Search 10-25-2013 0 2 | 0 | 2 | ||
| I indexed some csv data which has a field called Open Time which winds up being selected as the _time and looks fine ... by jeremiahc4 Builder in Splunk Search 10-25-2013 1 2 | 1 | 2 | ||
| Using the dbconnect app without using advance(query), is there a way to make your lookup case insensitive by adding c... by rdownie Communicator in Splunk Search 10-25-2013 0 1 | 0 | 1 | ||
| Hi, Is there splunk tool chain that simply sends splunk commands to the daemon (does not include daemon and web inte... by paragcisco Explorer in Splunk Search 10-25-2013 1 6 | 1 | 6 | ||
| I have two sourcetypes - submitters, and recipient_group. I am looking to find the percentage of submitters that are... by lehrfeld Path Finder in Splunk Search 10-25-2013 0 3 | 0 | 3 | ||
| 2013-10-25 10:49:33,Major,REMOVED,Allowed, - Caller MD5=61b1dfb9703d0d678e108e0156fcbb69,Create Process,Begin: 2013-1... by cdupuis123 Path Finder in Splunk Search 10-25-2013 0 3 | 0 | 3 | ||
| I'm building a dashboard using the techniques described here on Splunkbase, so that I have two Y axes. What I'm seein... by sowings Splunk Employee 1 4 | 1 | 4 | ||
| I'm following the tutorial at your page 46. The popup menu that I see has a "Destination app" field with search above... by MikeSilady Explorer in Splunk Search 10-25-2013 0 3 | 0 | 3 | ||
| I have the below search index=main sourcetype=summa | rex "::\s(?<timestamp>\S+)\s" | rex "^\S+\s(?<userid>\S+)\."... by srajanbabu Explorer in Splunk Search 10-25-2013 0 6 | 0 | 6 | ||
| It’s worth noting that this issue is being tested under the Splunk application for OS X. The goal is to get Splunk cr... by multiverse Engager in Splunk Search 10-25-2013 0 2 | 0 | 2 | ||
| Hello, I have the a search that is working and I get the desired output. Now I am trying to make the output "prett... by brywilk_umich Path Finder in Splunk Search 10-24-2013 1 2 | 1 | 2 | ||
| Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick.. www-ber 10/18/2... by richnavis Contributor in Splunk Search 10-24-2013 0 3 | 0 | 3 | ||
| I have this event and I'm trying to send it to the nullQueue if it contains SYSTEM. 2013-10-24 15:02:34,Major,REMOVE... by cdupuis123 Path Finder in Splunk Search 10-24-2013 0 1 | 0 | 1 | ||
| i have events with two fields: origin and duration i would like to present a table with the count of each origin, al... by ytl Path Finder in Splunk Search 10-24-2013 0 1 | 0 | 1 | ||
| Hello, I am new to Splunk and trying to come up with a way that would grab the usernames in certain lines (21_ubl) o... by brywilk_umich Path Finder in Splunk Search 10-24-2013 0 4 | 0 | 4 |