Splunk Search

Splunk Search
Community Activity
richnavis
Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick.. www-ber 10/18/2...
by richnavis Contributor in Splunk Search 10-24-2013
0 3
0
3
cdupuis123
I have this event and I'm trying to send it to the nullQueue if it contains SYSTEM. 2013-10-24 15:02:34,Major,REMOVE...
by cdupuis123 Path Finder in Splunk Search 10-24-2013
0 1
0
1
ytl
i have events with two fields: origin and duration i would like to present a table with the count of each origin, al...
by ytl Path Finder in Splunk Search 10-24-2013
0 1
0
1
brywilk_umich
Hello, I am new to Splunk and trying to come up with a way that would grab the usernames in certain lines (21_ubl) o...
by brywilk_umich Path Finder in Splunk Search 10-24-2013
0 4
0
4
hartfoml
Here is my DNS raw data: Oct 17 19:47:09 ns1 named[15517]: 17-Oct-2013 19:47:09.314 queries: client xxx.xxx.xxx.xxx#...
by hartfoml Motivator in Splunk Search 10-24-2013
1 4
1
4
lohit
Hi , I have some forwarders installed in my environment and want to calculate the peak time in which log sources for...
by lohit Path Finder in Splunk Search 10-24-2013
1 5
1
5
Nisha18789
I have a site and errors on that site are being recorded in splunk. I basically need to filter out those error which ...
by Nisha18789 Builder in Splunk Search 10-24-2013
0 6
0
6
nekb1958
Hi the following search eval test=7200 | convert timeformat="%H:%M:%S" ctime(test) | table test gives me 03:00:00 ...
by nekb1958 Path Finder in Splunk Search 10-24-2013
0 4
0
4
lohit
Hello everyone, I have around 20 forwarders (Universal) in my env and configued to forward data to Splunk Indexer. I...
by lohit Path Finder in Splunk Search 10-24-2013
0 1
0
1
tim9gray
Hi All, I am monitoring files that land in the same directory that I wish to be considered as different source types...
by tim9gray Explorer in Splunk Search 10-23-2013
0 13
0
13
the_wolverine
I'd like to run the following search on my indexer to calculate compression. It works in UI, but not in CLI. I have...
by the_wolverine Champion in Splunk Search 10-23-2013
0 2
0
2
tscanlon
Setting up Splunk I'm getting rsyslog messages showing up fine but when I point a little test log4j app at it I start...
by tscanlon Engager in Splunk Search 10-23-2013
0 2
0
2
tnconners
Background: We have an existing indexer, that we have added a lot of data to. We would like to cut down on the amount...
by tnconners Explorer in Splunk Search 10-23-2013
0 3
0
3
tfitzgerald15
This has been giving me headaches for a long time now, and it's pretty simple. So, for reference, this search works a...
by tfitzgerald15 Explorer in Splunk Search 10-23-2013
0 3
0
3
splunknovice201
I have a duration field in seconds. I wanted the format to be D+hh:mm:ss, so I used this: eval dur_hhmmss=tostring(D...
by splunknovice201 New Member in Splunk Search 10-23-2013
0 2
0
2
ejdavis
The props.conf and transforms.conf files that should be modified are under /etc/system/local, correct? We have been ...
by ejdavis Path Finder in Splunk Search 10-23-2013
0 13
0
13
echojacques
I've been playing around with eval, transaction, and stats and I still can't figure this one out... so I'm asking for...
by echojacques Builder in Splunk Search 10-23-2013
0 5
0
5
jeffreygaraygay
I get the error "Error in 'join' command: Usage: join <options> (<join-fields>)? [subsearch]" when running the follow...
by jeffreygaraygay Explorer in Splunk Search 10-23-2013
0 1
0
1
bowesmana
I've spent a long time reading, but am not sure the best way to do this. I have events, which contain username-xxx,...
by SplunkTrust SplunkTrust in Splunk Search 10-23-2013
0 4
0
4
jdastmalchi_spl
The flags such as exclude as explained in http://docs.splunk.com/Documentation/Splunk/6.0/Troubleshooting/ContactSplu...
by jdastmalchi_spl Splunk Employee Splunk Employee in Splunk Search 10-23-2013
1 1
1
1
kaddupa1
Hello, we are using SSO with LDAP based users for authentication on our search heads. On our search head; how do we ...
by kaddupa1 Explorer in Splunk Search 10-23-2013
1 2
1
2
srajanbabu
I have a query as source="C:\Data\acctdata\snm4-logger.log" "Customer has successfully retrieved file"| rex "::\s(?\S...
by srajanbabu Explorer in Splunk Search 10-23-2013
0 2
0
2
lohit
Hi all, I have around 8 hosts in my splunk and i searching for a report which will list out operating systems type...
by lohit Path Finder in Splunk Search 10-23-2013
0 8
0
8
gimbil
Hi All, I have multiple cases with my date: some have empty src value: e.g, id=abc src= lr=2 some does not have src ...
by gimbil Explorer in Splunk Search 10-22-2013
0 1
0
1
phoenixdigital
I have a chicken and egg issue here which I am having trouble resolving. I have a search which returns data for each...
by phoenixdigital Builder in Splunk Search 10-22-2013
0 6
0
6
Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...