| Is it possible to have a lookup table keyed off of an extracted field? Given the props: [foo] EXTRACT-bu = ^(?<bu>.... by vbumgarner Contributor in Splunk Search 09-12-2013 1 6 | 1 | 6 | ||
| source="D:\\SplunkLogs\\HI_IR.xml"|xmlkv|xpath "//HI_IN//IMK[TY_ID="\234\"]//RE_N" outfield=RE_N|stats values(RE_N) ... by john Communicator in Splunk Search 09-12-2013 0 1 | 0 | 1 | ||
| hi, by running this query in search field index="New" "Phase * ended" | table phaseinformation , phase_ended , datet... by harsh1734 New Member in Splunk Search 09-12-2013 0 3 | 0 | 3 | ||
| hello, I was wondering how to set up Splunk's RSS to support conditional gets (so that my reader when setup correct... by samiomer Path Finder in Splunk Search 09-12-2013 0 1 | 0 | 1 | ||
| I have a dashboard panel that displays the number of user sessions on a web server in a column chart. The user wants ... by rgcurry Contributor in Splunk Search 09-12-2013 0 3 | 0 | 3 | ||
| Hi, We have scheduled saved search running every 5 minutes to create summary index. In our test setup we get 200 lo... by keerthana_k Communicator in Splunk Search 09-12-2013 0 1 | 0 | 1 | ||
| Okay, I am sure that I have done something stupid, but I can NOT figure it out! This search works and returns about ... by lguinn2 Legend in Splunk Search 09-12-2013 1 3 | 1 | 3 | ||
| Hi, I have csv file uploaded on to splunk.Here is the sample entries Intime Outtime 8:33 17:39 8:38 17:40 8:33 ... by shreeCS New Member in Splunk Search 09-12-2013 0 2 | 0 | 2 | ||
| hi, this is my query index=tm_idx host="server" sourcetype="TM_Test_10" | rex field=msg "(?i)TM1\sserver\sload\s... by ChhayaV Communicator in Splunk Search 09-12-2013 0 1 | 0 | 1 | ||
| Problem: Huge list of IP addresses across multiple subnets, how to group and list in order of subnets. This is what ... by gstewart Explorer in Splunk Search 09-11-2013 0 3 | 0 | 3 | ||
| I've configured a CSV lookup and an automatic lookup on Splunk 5.0.4 that work on one of my search heads (let's call ... by madhack Explorer in Splunk Search 09-11-2013 1 6 | 1 | 6 | ||
| I have my DNS and DHCP logs in one file and I would like to set "TZ = UTC" on the sourcetype. My problem is what wou... by hartfoml Motivator in Splunk Search 09-11-2013 0 3 | 0 | 3 | ||
| Hello Splunkers, I'm trying to run a search against some logs that include a wild carded hostname, two error messages... by lbogle Contributor in Splunk Search 09-11-2013 0 2 | 0 | 2 | ||
| Hello, I have a dashboard for windows event viewer. There are two pulldowns which populates the relevant fields. But ... by linu1988 Champion in Splunk Search 09-11-2013 0 8 | 0 | 8 | ||
| Hi. For some reasons, I turned off SSL for Splunk REST API. Everything is fine, except the Splunk DB Connect app. j... by yitzarad Path Finder in Splunk Search 09-11-2013 4 4 | 4 | 4 | ||
| My current Splunk search looks like this: sourcetype="ContributionWebApiUat" DbResponseTime=* | chart values(DbRespo... by philallen1 Path Finder in Splunk Search 09-11-2013 0 1 | 0 | 1 | ||
| In my search I am at a stage where I have something like below. USERID EVENT STATUS 1 HELLO PASS 2 HELLO F... by theeven Explorer in Splunk Search 09-11-2013 1 9 | 1 | 9 | ||
| Due to some mistake, I am getting this messages: received event for unconfigured/disabled/deleted index='2013-03-10 ... by mkelderm Path Finder in Splunk Search 09-11-2013 0 6 | 0 | 6 | ||
| Hi, I have a transform like this - it works fine except when I need to look up a field [specialLogFile] REGEX = ^([... by mplungjan Path Finder in Splunk Search 09-11-2013 0 2 | 0 | 2 | ||
| I have syslog files that are in the directory structure of system/Hosts/year/month/day I've been able to get the ind... by pljulien New Member in Splunk Search 09-11-2013 0 1 | 0 | 1 | ||
| My query is the following index="_internal" | table host | stats values(host) output: values(host) host1 host2 I w... by ERICKWONG Explorer in Splunk Search 09-10-2013 0 6 | 0 | 6 | ||
| We have a dashboard that I would like to use tstats to generate the data, and run a search ever 2 minutes using tscol... by sf_user_199 Path Finder in Splunk Search 09-10-2013 1 2 | 1 | 2 | ||
| Is there a way to use a database lookup in the way you would using inputlookup? If I wanted to just dump the contents... by rdownie Communicator in Splunk Search 09-10-2013 1 1 | 1 | 1 | ||
| Is it possible in inputs.conf in windows machine to use host=$ I tried using: host=$computername but in the inde... by parth_jec Path Finder in Splunk Search 09-10-2013 3 1 | 3 | 1 | ||
| Hi, What is the difference between last(X) and latest(X) functions for stats. I tried both in searches and i get sam... by strive Influencer in Splunk Search 09-10-2013 3 2 | 3 | 2 |