Splunk Search

Splunk Search
Community Activity
vbumgarner
Is it possible to have a lookup table keyed off of an extracted field? Given the props: [foo] EXTRACT-bu = ^(?<bu>....
by vbumgarner Contributor in Splunk Search 09-12-2013
1 6
1
6
john
source="D:\\SplunkLogs\\HI_IR.xml"|xmlkv|xpath "//HI_IN//IMK[TY_ID="\234\"]//RE_N" outfield=RE_N|stats values(RE_N) ...
by john Communicator in Splunk Search 09-12-2013
0 1
0
1
harsh1734
hi, by running this query in search field index="New" "Phase * ended" | table phaseinformation , phase_ended , datet...
by harsh1734 New Member in Splunk Search 09-12-2013
0 3
0
3
samiomer
hello, I was wondering how to set up Splunk's RSS to support conditional gets (so that my reader when setup correct...
by samiomer Path Finder in Splunk Search 09-12-2013
0 1
0
1
rgcurry
I have a dashboard panel that displays the number of user sessions on a web server in a column chart. The user wants ...
by rgcurry Contributor in Splunk Search 09-12-2013
0 3
0
3
keerthana_k
Hi, We have scheduled saved search running every 5 minutes to create summary index. In our test setup we get 200 lo...
by keerthana_k Communicator in Splunk Search 09-12-2013
0 1
0
1
lguinn2
Okay, I am sure that I have done something stupid, but I can NOT figure it out! This search works and returns about ...
by Legend in Splunk Search 09-12-2013
1 3
1
3
shreeCS
Hi, I have csv file uploaded on to splunk.Here is the sample entries Intime Outtime 8:33 17:39 8:38 17:40 8:33 ...
by shreeCS New Member in Splunk Search 09-12-2013
0 2
0
2
ChhayaV
hi, this is my query index=tm_idx host="server" sourcetype="TM_Test_10" | rex field=msg "(?i)TM1\sserver\sload\s...
by ChhayaV Communicator in Splunk Search 09-12-2013
0 1
0
1
gstewart
Problem: Huge list of IP addresses across multiple subnets, how to group and list in order of subnets. This is what ...
by gstewart Explorer in Splunk Search 09-11-2013
0 3
0
3
madhack
I've configured a CSV lookup and an automatic lookup on Splunk 5.0.4 that work on one of my search heads (let's call ...
by madhack Explorer in Splunk Search 09-11-2013
1 6
1
6
hartfoml
I have my DNS and DHCP logs in one file and I would like to set "TZ = UTC" on the sourcetype. My problem is what wou...
by hartfoml Motivator in Splunk Search 09-11-2013
0 3
0
3
lbogle
Hello Splunkers, I'm trying to run a search against some logs that include a wild carded hostname, two error messages...
by lbogle Contributor in Splunk Search 09-11-2013
0 2
0
2
linu1988
Hello, I have a dashboard for windows event viewer. There are two pulldowns which populates the relevant fields. But ...
by linu1988 Champion in Splunk Search 09-11-2013
0 8
0
8
yitzarad
Hi. For some reasons, I turned off SSL for Splunk REST API. Everything is fine, except the Splunk DB Connect app. j...
by yitzarad Path Finder in Splunk Search 09-11-2013
4 4
4
4
philallen1
My current Splunk search looks like this: sourcetype="ContributionWebApiUat" DbResponseTime=* | chart values(DbRespo...
by philallen1 Path Finder in Splunk Search 09-11-2013
0 1
0
1
theeven
In my search I am at a stage where I have something like below. USERID EVENT STATUS 1 HELLO PASS 2 HELLO F...
by theeven Explorer in Splunk Search 09-11-2013
1 9
1
9
mkelderm
Due to some mistake, I am getting this messages: received event for unconfigured/disabled/deleted index='2013-03-10 ...
by mkelderm Path Finder in Splunk Search 09-11-2013
0 6
0
6
mplungjan
Hi, I have a transform like this - it works fine except when I need to look up a field [specialLogFile] REGEX = ^([...
by mplungjan Path Finder in Splunk Search 09-11-2013
0 2
0
2
pljulien
I have syslog files that are in the directory structure of system/Hosts/year/month/day I've been able to get the ind...
by pljulien New Member in Splunk Search 09-11-2013
0 1
0
1
ERICKWONG
My query is the following index="_internal" | table host | stats values(host) output: values(host) host1 host2 I w...
by ERICKWONG Explorer in Splunk Search 09-10-2013
0 6
0
6
sf_user_199
We have a dashboard that I would like to use tstats to generate the data, and run a search ever 2 minutes using tscol...
by sf_user_199 Path Finder in Splunk Search 09-10-2013
1 2
1
2
rdownie
Is there a way to use a database lookup in the way you would using inputlookup? If I wanted to just dump the contents...
by rdownie Communicator in Splunk Search 09-10-2013
1 1
1
1
parth_jec
Is it possible in inputs.conf in windows machine to use host=$ I tried using: host=$computername but in the inde...
by parth_jec Path Finder in Splunk Search 09-10-2013
3 1
3
1
strive
Hi, What is the difference between last(X) and latest(X) functions for stats. I tried both in searches and i get sam...
by strive Influencer in Splunk Search 09-10-2013
3 2
3
2
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors