Splunk Search

Splunk Search
Community Activity
ChhayaV
hi, these are my searches index=tm_idx host="audit" | timechart count by Process usenull="f" index=tm_idx host="au...
by ChhayaV Communicator in Splunk Search 09-13-2013
1 2
1
2
keerthana_k
Hi, We are using Splunk version 5.0.4 in our application. In order to bucket our data and display the buckets in pro...
by keerthana_k Communicator in Splunk Search 09-13-2013
0 1
0
1
luthfi49
Hi all, When I use query : mysearch | stats avg(X) It is supposed that the result is the average value of field X in...
by luthfi49 Explorer in Splunk Search 09-13-2013
0 3
0
3
ltruesda
I have an index of events where each event is associated with a user. I want to produce a table where each row repre...
by ltruesda Explorer in Splunk Search 09-12-2013
0 3
0
3
cycheng
In http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Stats, I found that there is an optional argumen...
by cycheng Path Finder in Splunk Search 09-12-2013
1 1
1
1
sajoseph
HI, I have a dashboard query which is like this. index=elf |search * | chart count(eval(event_type="3000")) AS AUDIT...
by sajoseph Explorer in Splunk Search 09-12-2013
0 1
0
1
adrianathome
I have a field on my events that has the following: john,12345,mark,2356,maria,4567 rachel,8883,john2,488475 nothing...
by adrianathome Communicator in Splunk Search 09-12-2013
0 3
0
3
gjohnson
Forgive me if this has been asked before, but I am trying to do a lookup using geoip (maxmind database) to resolve IP...
by gjohnson New Member in Splunk Search 09-12-2013
0 3
0
3
jackykitkit
I would like to know can I configure splunk to receive syslog in Single Input (UDP:514) with multiple host and multip...
by jackykitkit New Member in Splunk Search 09-12-2013
0 1
0
1
wbordeau
I want to hide peaks in timechart that do not exceed a certain threshold. I'm trying the below query but am not havi...
by wbordeau Explorer in Splunk Search 09-12-2013
0 1
0
1
lbrindise
Have never used Splunk; just looking to see if something is possible. I not only want to monitor the things that Splu...
by lbrindise New Member in Splunk Search 09-12-2013
0 1
0
1
vbumgarner
Is it possible to have a lookup table keyed off of an extracted field? Given the props: [foo] EXTRACT-bu = ^(?<bu>....
by vbumgarner Contributor in Splunk Search 09-12-2013
1 6
1
6
john
source="D:\\SplunkLogs\\HI_IR.xml"|xmlkv|xpath "//HI_IN//IMK[TY_ID="\234\"]//RE_N" outfield=RE_N|stats values(RE_N) ...
by john Communicator in Splunk Search 09-12-2013
0 1
0
1
harsh1734
hi, by running this query in search field index="New" "Phase * ended" | table phaseinformation , phase_ended , datet...
by harsh1734 New Member in Splunk Search 09-12-2013
0 3
0
3
samiomer
hello, I was wondering how to set up Splunk's RSS to support conditional gets (so that my reader when setup correct...
by samiomer Path Finder in Splunk Search 09-12-2013
0 1
0
1
rgcurry
I have a dashboard panel that displays the number of user sessions on a web server in a column chart. The user wants ...
by rgcurry Contributor in Splunk Search 09-12-2013
0 3
0
3
keerthana_k
Hi, We have scheduled saved search running every 5 minutes to create summary index. In our test setup we get 200 lo...
by keerthana_k Communicator in Splunk Search 09-12-2013
0 1
0
1
lguinn2
Okay, I am sure that I have done something stupid, but I can NOT figure it out! This search works and returns about ...
by Legend in Splunk Search 09-12-2013
1 3
1
3
shreeCS
Hi, I have csv file uploaded on to splunk.Here is the sample entries Intime Outtime 8:33 17:39 8:38 17:40 8:33 ...
by shreeCS New Member in Splunk Search 09-12-2013
0 2
0
2
ChhayaV
hi, this is my query index=tm_idx host="server" sourcetype="TM_Test_10" | rex field=msg "(?i)TM1\sserver\sload\s...
by ChhayaV Communicator in Splunk Search 09-12-2013
0 1
0
1
gstewart
Problem: Huge list of IP addresses across multiple subnets, how to group and list in order of subnets. This is what ...
by gstewart Explorer in Splunk Search 09-11-2013
0 3
0
3
madhack
I've configured a CSV lookup and an automatic lookup on Splunk 5.0.4 that work on one of my search heads (let's call ...
by madhack Explorer in Splunk Search 09-11-2013
1 6
1
6
hartfoml
I have my DNS and DHCP logs in one file and I would like to set "TZ = UTC" on the sourcetype. My problem is what wou...
by hartfoml Motivator in Splunk Search 09-11-2013
0 3
0
3
lbogle
Hello Splunkers, I'm trying to run a search against some logs that include a wild carded hostname, two error messages...
by lbogle Contributor in Splunk Search 09-11-2013
0 2
0
2
linu1988
Hello, I have a dashboard for windows event viewer. There are two pulldowns which populates the relevant fields. But ...
by linu1988 Champion in Splunk Search 09-11-2013
0 8
0
8
Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...
Top Solution Authors