Splunk Search

Splunk Search
Community Activity
bckq
I have about 150-200 scheduled searches that runs every minute. Most of searches look for data from 15 minutes till n...
by bckq Path Finder in Splunk Search 10-18-2013
1 5
1
5
tkwaller
Hello I'm trying to get the search to find a transaction and within that transaction is information like brokerID, l...
by tkwaller Builder in Splunk Search 10-18-2013
0 2
0
2
a212830
Hi, I have an inputs.conf that has the following whitelist: whitelist = (?i)vpxd-\d{5}\.log The 5 was originally a...
by a212830 Champion in Splunk Search 10-18-2013
0 1
0
1
srajanbabu
I am new to spluk, I have the below sample log and would like to arrive statistics on userwise how many files/Bytes r...
by srajanbabu Explorer in Splunk Search 10-18-2013
0 12
0
12
srajanbabu
I have a search as source="C:\\Data\\acctdata\\snm4-logger.log" | transaction FILENAME_FIELD keepevicted=true| where...
by srajanbabu Explorer in Splunk Search 10-18-2013
0 1
0
1
ESIMatNeforce
Hello, I have recently changed the computername of my Domaincontroller. When I make a splunk search with "failed pass...
by ESIMatNeforce Path Finder in Splunk Search 10-18-2013
0 2
0
2
ejpulsar
Hi! I need to build realtime search which tracks if NO events with particular P_LOGIN_NAME are received in last 15 m...
by ejpulsar Path Finder in Splunk Search 10-18-2013
0 1
0
1
nilampakhare
Can we write custom python commands in splunk ..
by nilampakhare New Member in Splunk Search 10-18-2013
0 1
0
1
Nicksyboy
I want to use rex to figure out the pattern for a url. The URL looks something like - text . The other 2 urls are h...
by Nicksyboy Explorer in Splunk Search 10-18-2013
0 1
0
1
tferro999
I'm trying to graph the total number of hits to our website alongside the total number of hits to a subset of pages w...
by tferro999 New Member in Splunk Search 10-17-2013
0 4
0
4
AlexMcDuffMille
I have a log that outputs a table every day of issues that occur between two parties. I'm able to split the output t...
by AlexMcDuffMille Communicator in Splunk Search 10-17-2013
0 2
0
2
jlixfeld
I have syslog data that looks like so: 2013-10-17T12:37:01.608054-04:00 fw01.77MowatAv01.YYZ %ASA-1-106021: Deny SCT...
by jlixfeld Path Finder in Splunk Search 10-17-2013
0 1
0
1
wpreston
How and where does Splunk store user's preferences (like selected fields, last used time range, that kind of thing)? ...
by wpreston Motivator in Splunk Search 10-17-2013
0 2
0
2
xvxt006
Hi, Can we combine data from different Apps?
by xvxt006 Contributor in Splunk Search 10-17-2013
0 1
0
1
wood1986
How to count the size of json array of a single event For example {"a" : [{"b": true}, {"b": true}, {"c": true}]} n...
by wood1986 Explorer in Splunk Search 10-17-2013
2 3
2
3
thirumalreddyb
Hi, I'm struck with a question. I have 3 GB of data coming in every day. I'm not sure which segmentation to follow. I...
by thirumalreddyb Communicator in Splunk Search 10-17-2013
0 2
0
2
mcbradford
I have a search I use to associate a "likely" user to an IP search query | dedup src | fields src user |inputlookup ...
by mcbradford Contributor in Splunk Search 10-17-2013
0 1
0
1
henryt1
Hello, I need to put together a report that involves counting certain characters in a field within Splunk. For insta...
by henryt1 Path Finder in Splunk Search 10-17-2013
0 6
0
6
rdownie
If I have a lookup table that contains the following: mstring,category %-mdfa,network %-mdfb,network %cam,camera %-a...
by rdownie Communicator in Splunk Search 10-17-2013
0 2
0
2
mkelderm
My query shows only values when it finds an event. I want also the 0 events per span in my chart. I thought this was ...
by mkelderm Path Finder in Splunk Search 10-17-2013
0 1
0
1
philallen1
Hi There is a checkbox in my app that turns a comparison column to a set of data on or off. When the user enters th...
by philallen1 Path Finder in Splunk Search 10-17-2013
0 2
0
2
lmachetman
I am trying to extract a field from the below logging BBFH_SAPI=2012-10-16=11:13:14=I=05612=REQUESTS: 1220 Answered ...
by lmachetman Explorer in Splunk Search 10-17-2013
0 2
0
2
sc0tt
I continually receive the error that I have reached the maximum number of historical searches (current=16 maximum=16)...
by sc0tt Builder in Splunk Search 10-17-2013
0 2
0
2
sanyonhhh
Query used: index=[server]| transaction Extract startswith="Value Extract Starting." endswith="extraction completed....
by sanyonhhh New Member in Splunk Search 10-16-2013
0 1
0
1
tristanmatthews
I have two indexes one contains objects of interest and things I don't care about, all_results, and the other is a li...
by tristanmatthews Path Finder in Splunk Search 10-16-2013
0 1
0
1
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors