Splunk Search

Splunk Search
Community Activity
cycheng
In http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Stats, I found that there is an optional argumen...
by cycheng Path Finder in Splunk Search 09-12-2013
1 1
1
1
sajoseph
HI, I have a dashboard query which is like this. index=elf |search * | chart count(eval(event_type="3000")) AS AUDIT...
by sajoseph Explorer in Splunk Search 09-12-2013
0 1
0
1
adrianathome
I have a field on my events that has the following: john,12345,mark,2356,maria,4567 rachel,8883,john2,488475 nothing...
by adrianathome Communicator in Splunk Search 09-12-2013
0 3
0
3
gjohnson
Forgive me if this has been asked before, but I am trying to do a lookup using geoip (maxmind database) to resolve IP...
by gjohnson New Member in Splunk Search 09-12-2013
0 3
0
3
jackykitkit
I would like to know can I configure splunk to receive syslog in Single Input (UDP:514) with multiple host and multip...
by jackykitkit New Member in Splunk Search 09-12-2013
0 1
0
1
wbordeau
I want to hide peaks in timechart that do not exceed a certain threshold. I'm trying the below query but am not havi...
by wbordeau Explorer in Splunk Search 09-12-2013
0 1
0
1
lbrindise
Have never used Splunk; just looking to see if something is possible. I not only want to monitor the things that Splu...
by lbrindise New Member in Splunk Search 09-12-2013
0 1
0
1
vbumgarner
Is it possible to have a lookup table keyed off of an extracted field? Given the props: [foo] EXTRACT-bu = ^(?<bu>....
by vbumgarner Contributor in Splunk Search 09-12-2013
1 6
1
6
john
source="D:\\SplunkLogs\\HI_IR.xml"|xmlkv|xpath "//HI_IN//IMK[TY_ID="\234\"]//RE_N" outfield=RE_N|stats values(RE_N) ...
by john Communicator in Splunk Search 09-12-2013
0 1
0
1
harsh1734
hi, by running this query in search field index="New" "Phase * ended" | table phaseinformation , phase_ended , datet...
by harsh1734 New Member in Splunk Search 09-12-2013
0 3
0
3
samiomer
hello, I was wondering how to set up Splunk's RSS to support conditional gets (so that my reader when setup correct...
by samiomer Path Finder in Splunk Search 09-12-2013
0 1
0
1
rgcurry
I have a dashboard panel that displays the number of user sessions on a web server in a column chart. The user wants ...
by rgcurry Contributor in Splunk Search 09-12-2013
0 3
0
3
keerthana_k
Hi, We have scheduled saved search running every 5 minutes to create summary index. In our test setup we get 200 lo...
by keerthana_k Communicator in Splunk Search 09-12-2013
0 1
0
1
lguinn2
Okay, I am sure that I have done something stupid, but I can NOT figure it out! This search works and returns about ...
by Legend in Splunk Search 09-12-2013
1 3
1
3
shreeCS
Hi, I have csv file uploaded on to splunk.Here is the sample entries Intime Outtime 8:33 17:39 8:38 17:40 8:33 ...
by shreeCS New Member in Splunk Search 09-12-2013
0 2
0
2
ChhayaV
hi, this is my query index=tm_idx host="server" sourcetype="TM_Test_10" | rex field=msg "(?i)TM1\sserver\sload\s...
by ChhayaV Communicator in Splunk Search 09-12-2013
0 1
0
1
gstewart
Problem: Huge list of IP addresses across multiple subnets, how to group and list in order of subnets. This is what ...
by gstewart Explorer in Splunk Search 09-11-2013
0 3
0
3
madhack
I've configured a CSV lookup and an automatic lookup on Splunk 5.0.4 that work on one of my search heads (let's call ...
by madhack Explorer in Splunk Search 09-11-2013
1 6
1
6
hartfoml
I have my DNS and DHCP logs in one file and I would like to set "TZ = UTC" on the sourcetype. My problem is what wou...
by hartfoml Motivator in Splunk Search 09-11-2013
0 3
0
3
lbogle
Hello Splunkers, I'm trying to run a search against some logs that include a wild carded hostname, two error messages...
by lbogle Contributor in Splunk Search 09-11-2013
0 2
0
2
linu1988
Hello, I have a dashboard for windows event viewer. There are two pulldowns which populates the relevant fields. But ...
by linu1988 Champion in Splunk Search 09-11-2013
0 8
0
8
yitzarad
Hi. For some reasons, I turned off SSL for Splunk REST API. Everything is fine, except the Splunk DB Connect app. j...
by yitzarad Path Finder in Splunk Search 09-11-2013
4 4
4
4
philallen1
My current Splunk search looks like this: sourcetype="ContributionWebApiUat" DbResponseTime=* | chart values(DbRespo...
by philallen1 Path Finder in Splunk Search 09-11-2013
0 1
0
1
theeven
In my search I am at a stage where I have something like below. USERID EVENT STATUS 1 HELLO PASS 2 HELLO F...
by theeven Explorer in Splunk Search 09-11-2013
1 9
1
9
mkelderm
Due to some mistake, I am getting this messages: received event for unconfigured/disabled/deleted index='2013-03-10 ...
by mkelderm Path Finder in Splunk Search 09-11-2013
0 6
0
6
Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...