Splunk Search

Splunk Search
Community Activity
Jason
What search commands are supported by real-time searches? I can't find this information in the manual.
by Jason Motivator in Splunk Search 09-27-2013
0 4
0
4
jonbalderston
I have this working: | lookup SensitiveGroups.csv Target_Account_Name OUTPUT CSV_Priority | search CSV_Priority="Low...
by jonbalderston Explorer in Splunk Search 09-27-2013
0 3
0
3
timmalos
Hi I got a Radial gauge going to 1 to 4 like this <module name="HiddenChartFormatter"> <param name="charting.ch...
by timmalos Communicator in Splunk Search 09-27-2013
0 1
0
1
Narj
Hi all, I'm doing some RADIUS stuff and notice there are a load of fields popping up that seem to be provided by ano...
by Narj Path Finder in Splunk Search 09-27-2013
1 5
1
5
Jason
I am trying to join in some status information in real-time against a static list of data, but getting an error when ...
by Jason Motivator in Splunk Search 09-27-2013
0 14
0
14
rereeser
Hi, I've got some data that reports the number of users once per day, like: users=1000 users=1500 users=9001 I'm tr...
by rereeser Explorer in Splunk Search 09-27-2013
0 2
0
2
tfitzgerald15
Hey guys. So I need to display a dashboard panel with a single line, the total count of all hits from the Palo Altos ...
by tfitzgerald15 Explorer in Splunk Search 09-26-2013
0 2
0
2
RVDowning
Is there any point in periodically updating Sampledata.zip, and if so how does one best go about it?
by RVDowning Contributor in Splunk Search 09-26-2013
0 6
0
6
fuzzy_rocks
I would like to chart a count of how many distinct days users logged into our system within the past 7 days. When I t...
by fuzzy_rocks Explorer in Splunk Search 09-26-2013
0 2
0
2
cheukkay
Hey guys , I have created a subsearch for my firewall log files : sourcetype="honetnet" [search sourcetype ="honetn...
by cheukkay Engager in Splunk Search 09-26-2013
0 1
0
1
ChhayaV
Hi, I've requirement where in the process like proces1, process2 need to be on y-axis and corresponding time on x-ax...
by ChhayaV Communicator in Splunk Search 09-26-2013
0 1
0
1
ChhayaV
hi, I want to add some seconds in the current _time. Is there any build in function for it? e.g_time=23:03:39.022 a...
by ChhayaV Communicator in Splunk Search 09-26-2013
0 10
0
10
justinfranks
Hey all, I've searched for an answer to this but cannot see one, so apologies if this has been answered before. Som...
by justinfranks Path Finder in Splunk Search 09-25-2013
0 4
0
4
wyang6
[subsearch]: Search auto-finalized after time limit reached (60 seconds). Results may be incomplete. How can I ...
by wyang6 Path Finder in Splunk Search 09-25-2013
2 4
2
4
JWBailey
I would like to perform search time field extraction on text that is already being stored in a field to break it up i...
by JWBailey Communicator in Splunk Search 09-25-2013
0 2
0
2
mileven
Currently doing a search and converting results from KB to MB but I only want to see 2 decimal places not 6 as it's c...
by mileven Explorer in Splunk Search 09-25-2013
0 2
0
2
jedatt01
I have a csv data source with example values as follows MAC_ID, SSID AAAA.AAAA.AAAA, TEST BBBB.BBBB.BBBB, TEST CCCC....
by jedatt01 Builder in Splunk Search 09-25-2013
0 5
0
5
royimad
Hello, I have a search like this: sourcetype="mysource" | stats count by field I need to show zero if the field doesn...
by royimad Builder in Splunk Search 09-25-2013
0 4
0
4
hexx
I have noticed that when users leave browsers open on the summary dashboard of the search app (http://host.example.co...
by hexx Splunk Employee Splunk Employee in Splunk Search 09-25-2013
11 8
11
8
martin_mueller
I want to have a Simple XML dashboard with twelve rows (one chart each, two per working day, scheduled every weekend)...
by SplunkTrust SplunkTrust in Splunk Search 09-24-2013
1 2
1
2
wsw70
Hi, Now that I know, thanks to R.Turk, how to sort stacked bar charts I wanted to pick a top 5 of the results. This ...
by wsw70 Communicator in Splunk Search 09-24-2013
0 4
0
4
nverma
I have installed 'splunk-5.0.4-172409-x64-release.msi' in my local machine (Windows-7, 64 bit) as Local System User. ...
by nverma Engager in Splunk Search 09-24-2013
0 6
0
6
Armyeric
In my search on a display: index="stuff" severity="high" OR severity="medium" | top attacker limit=20 | geoip attac...
by Armyeric Path Finder in Splunk Search 09-24-2013
0 2
0
2
xvxt006
Hi, We have a filed called BOTs which extracts all the legitimate BOTs (which have +http://.... in the user agent)...
by xvxt006 Contributor in Splunk Search 09-24-2013
0 7
0
7
hartfoml
I am using the top command to see splunkd resource use just like SOS I would like to see the total CPU and MEMORY us...
by hartfoml Motivator in Splunk Search 09-24-2013
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...