Splunk Search

Splunk Search
Community Activity
ppurokit
I have a search result which returns me the following Username,TimeOnVPN user1,185.25 user2,1920.25 ... ... ... user...
by ppurokit Path Finder in Splunk Search 10-06-2013
0 2
0
2
thinksplunk
2013-09-20 16:53:04,723 INFO[Thread-3]EndTime=20/09/2013 16:53:04 TransactionID=A, Event=completed, Result=sent 2013...
by thinksplunk Engager in Splunk Search 10-04-2013
0 2
0
2
ChhayaV
hi this is mt search index=tm_idx host="server" "finished executing normally" | rex field=_raw "(?i)Process\s\"(?<P...
by ChhayaV Communicator in Splunk Search 10-04-2013
0 4
0
4
radomo
Hello I'm breaking my brain for make one thing. I recovery the data from External database, in this point no problem...
by radomo Explorer in Splunk Search 10-03-2013
0 2
0
2
TobiasBoone
In order to query from an external firewall log that contains say "badwebsite.com" and join those results back throug...
by TobiasBoone Communicator in Splunk Search 10-03-2013
3 6
3
6
Mag2sub
Not able to see login fields when launching splunk web ... Javascript enabled in browser and no iptables issue etc ...
by Mag2sub Path Finder in Splunk Search 10-03-2013
1 16
1
16
cschafer1
I apolagize for the simplicity of this question. I have scowered all over splunk answers and could find or make sense...
by cschafer1 New Member in Splunk Search 10-03-2013
0 3
0
3
aportela_work
Does anyone know how to generate a report listing all fields (from an index) and their respective info (example follo...
by aportela_work Explorer in Splunk Search 10-03-2013
0 3
0
3
DaClyde
I get the following error for all of my searches after upgrading from 5.0.4 to 6.0: Write access to the proxy endpoi...
by DaClyde Contributor in Splunk Search 10-03-2013
0 7
0
7
rudy_dom
Soo - I got this great search to show how many hosts at each location we are getting logs from. I want to only disp...
by rudy_dom Engager in Splunk Search 10-03-2013
0 1
0
1
RVDowning
source="PerfMetrics" "OPEN PLAN" OSArch=64-bit PlanMode=Server | transaction Guid startswith="OPEN PLAN START" endsw...
by RVDowning Contributor in Splunk Search 10-03-2013
0 2
0
2
bbthesplunk
My company leverages background images to describe our security architecture around inbound email and on quarterly ba...
by bbthesplunk Explorer in Splunk Search 10-03-2013
0 1
0
1
Ravman
Hi What is the syntax using subquery to get all rows having the same correlation id that of an inbound call with a gi...
by Ravman New Member in Splunk Search 10-03-2013
0 1
0
1
RVDowning
I want to search for all records where some field value is greater than X where X is some number. A number of searche...
by RVDowning Contributor in Splunk Search 10-02-2013
0 3
0
3
ww9rivers
[RESOLVED] The extract was defined in the transforms.conf in an app which had the "Sharing for config file-only objec...
by ww9rivers Contributor in Splunk Search 10-02-2013
0 3
0
3
hatim
I have a splunk server and ssh access to a server with read-only access to logs. I can ssh from the machine on which ...
by hatim New Member in Splunk Search 10-02-2013
0 2
0
2
shilpi
I have a logger like below and I need to extract the alphanumeric word from this line- "My employeeID E1233244345 is...
by shilpi New Member in Splunk Search 10-02-2013
0 2
0
2
responsys_cm
I have a search inputs a fairly large lookup table (150 MB). The execution costs are shown as: Execution costs Dura...
by responsys_cm Builder in Splunk Search 10-02-2013
0 1
0
1
mkarimi
I'm writing a search query that needs to look for a specific word SPECIFIC_WORD in the logs of host HOST_X and then d...
by mkarimi Path Finder in Splunk Search 10-02-2013
0 2
0
2
lain179
I am creating a failed login report from WMI security log entires. My temporary search command looks like: sourcety...
by lain179 Communicator in Splunk Search 10-02-2013
0 5
0
5
ralphmct
As title. I'm using the setup.xml and the admin/passwords endpoint, though I would create a custom endpoint if needed...
by ralphmct Path Finder in Splunk Search 10-02-2013
0 1
0
1
javierlf
I have a syslog where I want to extract only these 3 events: 1) Engine Busy Utilization CPU Busy I/O Busy ...
by javierlf Explorer in Splunk Search 10-02-2013
0 2
0
2
fgilain
Hello, i need to find the REGEX to allow me to filter what splunk will index. As it is firewall Logs, it gererates ...
by fgilain Engager in Splunk Search 10-02-2013
0 11
0
11
kevinshipley
In the following log I want to extract the second instance of the "Security ID" field. I have tried a few different r...
by kevinshipley New Member in Splunk Search 10-02-2013
0 6
0
6
yuwtennis
Hi! I would like to ask question regarding to Splunk 6. Is it possible to use the configuration files(search.conf ,...
by yuwtennis Communicator in Splunk Search 10-02-2013
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...