Splunk Search

Splunk Search
Community Activity
jrodriguezap
Hi all, I would like to set the transforms.conf started indexing log files when they exceed the 100 lines per second ...
by jrodriguezap Contributor in Splunk Search 09-15-2013
0 3
0
3
shreeCS
Hi, I have uploaded csv files for indexing and creating reports.Here is the sample entries: Date A B ...
by shreeCS New Member in Splunk Search 09-15-2013
0 5
0
5
plambert
I have log entries that look effectively like this: (I have to break the URLs so I can even post this, how annoying.....
by plambert Engager in Splunk Search 09-15-2013
0 1
0
1
DavidGuarneri
I have the following search in an alert that triggers every 15 minutes: source="C:\logs\path\*.log" | chart count ov...
by DavidGuarneri Path Finder in Splunk Search 09-14-2013
0 9
0
9
kserra_splunk
splunk is currently locking the dll libeay32.dll from the wrong directory. this is causing our main security product ...
by kserra_splunk Splunk Employee Splunk Employee in Splunk Search 09-13-2013
4 1
4
1
DavidGuarneri
I have a source type where iis logs copied from another server to the forwarder are being recorded in UTC but not ind...
by DavidGuarneri Path Finder in Splunk Search 09-13-2013
0 3
0
3
howyagoin
Hi, I'm likely going about my search in the wrong way, but I'm trying to create a table of data which draws upon a s...
by howyagoin Contributor in Splunk Search 09-13-2013
0 3
0
3
cgbsplunk
I want to be able to do a search of an index with search parameters returned from a database lookup. An example woul...
by cgbsplunk Explorer in Splunk Search 09-13-2013
0 6
0
6
tb5821
The concept seems simply yet there doesn't seem to be a straightforward way of doing it. I have URL which I want splu...
by tb5821 Communicator in Splunk Search 09-13-2013
0 1
0
1
BertKraan
Hello, splunk newbie here, I have tens of servers named like abc01, abc02 .... abc20. Now i would like to search for...
by BertKraan Engager in Splunk Search 09-13-2013
0 3
0
3
ChhayaV
hi, these are my searches index=tm_idx host="audit" | timechart count by Process usenull="f" index=tm_idx host="au...
by ChhayaV Communicator in Splunk Search 09-13-2013
1 2
1
2
keerthana_k
Hi, We are using Splunk version 5.0.4 in our application. In order to bucket our data and display the buckets in pro...
by keerthana_k Communicator in Splunk Search 09-13-2013
0 1
0
1
luthfi49
Hi all, When I use query : mysearch | stats avg(X) It is supposed that the result is the average value of field X in...
by luthfi49 Explorer in Splunk Search 09-13-2013
0 3
0
3
ltruesda
I have an index of events where each event is associated with a user. I want to produce a table where each row repre...
by ltruesda Explorer in Splunk Search 09-12-2013
0 3
0
3
cycheng
In http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Stats, I found that there is an optional argumen...
by cycheng Path Finder in Splunk Search 09-12-2013
1 1
1
1
sajoseph
HI, I have a dashboard query which is like this. index=elf |search * | chart count(eval(event_type="3000")) AS AUDIT...
by sajoseph Explorer in Splunk Search 09-12-2013
0 1
0
1
adrianathome
I have a field on my events that has the following: john,12345,mark,2356,maria,4567 rachel,8883,john2,488475 nothing...
by adrianathome Communicator in Splunk Search 09-12-2013
0 3
0
3
gjohnson
Forgive me if this has been asked before, but I am trying to do a lookup using geoip (maxmind database) to resolve IP...
by gjohnson New Member in Splunk Search 09-12-2013
0 3
0
3
jackykitkit
I would like to know can I configure splunk to receive syslog in Single Input (UDP:514) with multiple host and multip...
by jackykitkit New Member in Splunk Search 09-12-2013
0 1
0
1
wbordeau
I want to hide peaks in timechart that do not exceed a certain threshold. I'm trying the below query but am not havi...
by wbordeau Explorer in Splunk Search 09-12-2013
0 1
0
1
lbrindise
Have never used Splunk; just looking to see if something is possible. I not only want to monitor the things that Splu...
by lbrindise New Member in Splunk Search 09-12-2013
0 1
0
1
vbumgarner
Is it possible to have a lookup table keyed off of an extracted field? Given the props: [foo] EXTRACT-bu = ^(?<bu>....
by vbumgarner Contributor in Splunk Search 09-12-2013
1 6
1
6
john
source="D:\\SplunkLogs\\HI_IR.xml"|xmlkv|xpath "//HI_IN//IMK[TY_ID="\234\"]//RE_N" outfield=RE_N|stats values(RE_N) ...
by john Communicator in Splunk Search 09-12-2013
0 1
0
1
harsh1734
hi, by running this query in search field index="New" "Phase * ended" | table phaseinformation , phase_ended , datet...
by harsh1734 New Member in Splunk Search 09-12-2013
0 3
0
3
samiomer
hello, I was wondering how to set up Splunk's RSS to support conditional gets (so that my reader when setup correct...
by samiomer Path Finder in Splunk Search 09-12-2013
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...