| Hi, I have a transform like this - it works fine except when I need to look up a field [specialLogFile] REGEX = ^([... by mplungjan Path Finder in Splunk Search 09-11-2013 0 2 | 0 | 2 | ||
| I have syslog files that are in the directory structure of system/Hosts/year/month/day I've been able to get the ind... by pljulien New Member in Splunk Search 09-11-2013 0 1 | 0 | 1 | ||
| My query is the following index="_internal" | table host | stats values(host) output: values(host) host1 host2 I w... by ERICKWONG Explorer in Splunk Search 09-10-2013 0 6 | 0 | 6 | ||
| We have a dashboard that I would like to use tstats to generate the data, and run a search ever 2 minutes using tscol... by sf_user_199 Path Finder in Splunk Search 09-10-2013 1 2 | 1 | 2 | ||
| Is there a way to use a database lookup in the way you would using inputlookup? If I wanted to just dump the contents... by rdownie Communicator in Splunk Search 09-10-2013 1 1 | 1 | 1 | ||
| Is it possible in inputs.conf in windows machine to use host=$ I tried using: host=$computername but in the inde... by parth_jec Path Finder in Splunk Search 09-10-2013 3 1 | 3 | 1 | ||
| Hi, What is the difference between last(X) and latest(X) functions for stats. I tried both in searches and i get sam... by strive Influencer in Splunk Search 09-10-2013 3 2 | 3 | 2 | ||
| Splunk Version : 4.3.4 OS : Redhat Message : SavedSplunker - Max alive instance count=1 reached for saved search_id... by joy76 Path Finder in Splunk Search 09-10-2013 1 1 | 1 | 1 | ||
| I need to have a search that uses: index="pt_app_siebel" SWEMethod="ReconfigureCXProd" starttime=9/6/2013:00:00:00 l... by TiagoMatos Path Finder in Splunk Search 09-10-2013 0 5 | 0 | 5 | ||
| Hello everyone, I have a table like the below example: || Protocol || Count || || TCP || 500 || || UDP || 200 || ... by ppurokit Path Finder in Splunk Search 09-10-2013 0 1 | 0 | 1 | ||
| Hi, I am planning to capture all the URIs with word chaser (case in sensitive). I have used this | regex uri="(?i)C... by xvxt006 Contributor in Splunk Search 09-10-2013 0 6 | 0 | 6 | ||
| Hello, I have a table that returns with these fields: AvgLow and AvgLowNOW, but they appear many times, like this Av... by TiagoMatos Path Finder in Splunk Search 09-10-2013 0 6 | 0 | 6 | ||
| Good Day! Given the following data... srcdst1.2.3.49.8.7.61.2.3.49.8.7.61.2.3.49.8.7.64.3.2.16.7.8.91.2.3.45.6.7.8 ... by splunkhelp Explorer in Splunk Search 09-10-2013 1 1 | 1 | 1 | ||
| I have a map with Map and a SetMulitmap and I'm not really familiar with splunk at the moment. So how do I search i... by mirjam_labrenz New Member in Splunk Search 09-10-2013 0 1 | 0 | 1 | ||
| I am looking for regex to capture all the URIs which includes "chaser" (case insensitive). I have used this <base s... by xvxt006 Contributor in Splunk Search 09-09-2013 0 2 | 0 | 2 | ||
| I'm pretty new to Splunk, so hopefully this is an easy question. I've looked all over the community questions and I ... by whathuh New Member in Splunk Search 09-09-2013 0 2 | 0 | 2 | ||
| Greetings, My journey continues. Now I would like to have a lookup match either the source or destination IP to an ... by ccsfdave Builder in Splunk Search 09-09-2013 0 3 | 0 | 3 | ||
| The following gives me exactly what I want host=****** Failed_Reason minutesago=15 | rex "\>(?<Failed_Reason>.*?)\<"... by ebailey Communicator in Splunk Search 09-09-2013 0 4 | 0 | 4 | ||
| how can I do a ratio search not based on count, but based on src_bytes (inbound traffic) to get a ratio for two field... by jaywilwk Engager in Splunk Search 09-09-2013 0 11 | 0 | 11 | ||
| Hi, I am want to get all the events ending with a referrer url of the below format. http://www.company.com/product/... by xvxt006 Contributor in Splunk Search 09-09-2013 0 7 | 0 | 7 | ||
| Hello. I want to be able to add subsearches in the same row. Example: Search #1.....| append [search #2....] | app... by Bryan_Rye New Member in Splunk Search 09-09-2013 0 1 | 0 | 1 | ||
| Newbie here, so please be kind! Not sure if this is even possible, but I need to find out if a user has never logged... by gsd New Member in Splunk Search 09-09-2013 0 11 | 0 | 11 | ||
| I am trying to use Case to rename taged events like this tag=audit OR tag=cleared "" | eval Event=case( tag == audit... by hartfoml Motivator in Splunk Search 09-09-2013 0 8 | 0 | 8 | ||
| Hi, I have rails requests which take more then 15 sec. Rails write to the production.log in 2 steps. It seem that sp... by aviramradai Explorer in Splunk Search 09-08-2013 0 1 | 0 | 1 | ||
| I have been using a complex search query (it's difficult for me to post it here without exposing internal information... by rtadams89 Contributor in Splunk Search 09-06-2013 2 4 | 2 | 4 |