Splunk Search

Splunk Search
Community Activity
hartfoml
I have my DNS and DHCP logs in one file and I would like to set "TZ = UTC" on the sourcetype. My problem is what wou...
by hartfoml Motivator in Splunk Search 09-11-2013
0 3
0
3
lbogle
Hello Splunkers, I'm trying to run a search against some logs that include a wild carded hostname, two error messages...
by lbogle Contributor in Splunk Search 09-11-2013
0 2
0
2
linu1988
Hello, I have a dashboard for windows event viewer. There are two pulldowns which populates the relevant fields. But ...
by linu1988 Champion in Splunk Search 09-11-2013
0 8
0
8
yitzarad
Hi. For some reasons, I turned off SSL for Splunk REST API. Everything is fine, except the Splunk DB Connect app. j...
by yitzarad Path Finder in Splunk Search 09-11-2013
4 4
4
4
philallen1
My current Splunk search looks like this: sourcetype="ContributionWebApiUat" DbResponseTime=* | chart values(DbRespo...
by philallen1 Path Finder in Splunk Search 09-11-2013
0 1
0
1
theeven
In my search I am at a stage where I have something like below. USERID EVENT STATUS 1 HELLO PASS 2 HELLO F...
by theeven Explorer in Splunk Search 09-11-2013
1 9
1
9
mkelderm
Due to some mistake, I am getting this messages: received event for unconfigured/disabled/deleted index='2013-03-10 ...
by mkelderm Path Finder in Splunk Search 09-11-2013
0 6
0
6
mplungjan
Hi, I have a transform like this - it works fine except when I need to look up a field [specialLogFile] REGEX = ^([...
by mplungjan Path Finder in Splunk Search 09-11-2013
0 2
0
2
pljulien
I have syslog files that are in the directory structure of system/Hosts/year/month/day I've been able to get the ind...
by pljulien New Member in Splunk Search 09-11-2013
0 1
0
1
ERICKWONG
My query is the following index="_internal" | table host | stats values(host) output: values(host) host1 host2 I w...
by ERICKWONG Explorer in Splunk Search 09-10-2013
0 6
0
6
sf_user_199
We have a dashboard that I would like to use tstats to generate the data, and run a search ever 2 minutes using tscol...
by sf_user_199 Path Finder in Splunk Search 09-10-2013
1 2
1
2
rdownie
Is there a way to use a database lookup in the way you would using inputlookup? If I wanted to just dump the contents...
by rdownie Communicator in Splunk Search 09-10-2013
1 1
1
1
parth_jec
Is it possible in inputs.conf in windows machine to use host=$ I tried using: host=$computername but in the inde...
by parth_jec Path Finder in Splunk Search 09-10-2013
3 1
3
1
strive
Hi, What is the difference between last(X) and latest(X) functions for stats. I tried both in searches and i get sam...
by strive Influencer in Splunk Search 09-10-2013
3 2
3
2
joy76
Splunk Version : 4.3.4 OS : Redhat Message : SavedSplunker - Max alive instance count=1 reached for saved search_id...
by joy76 Path Finder in Splunk Search 09-10-2013
1 1
1
1
TiagoMatos
I need to have a search that uses: index="pt_app_siebel" SWEMethod="ReconfigureCXProd" starttime=9/6/2013:00:00:00 l...
by TiagoMatos Path Finder in Splunk Search 09-10-2013
0 5
0
5
ppurokit
Hello everyone, I have a table like the below example: || Protocol || Count || || TCP || 500 || || UDP || 200 || ...
by ppurokit Path Finder in Splunk Search 09-10-2013
0 1
0
1
xvxt006
Hi, I am planning to capture all the URIs with word chaser (case in sensitive). I have used this | regex uri="(?i)C...
by xvxt006 Contributor in Splunk Search 09-10-2013
0 6
0
6
TiagoMatos
Hello, I have a table that returns with these fields: AvgLow and AvgLowNOW, but they appear many times, like this Av...
by TiagoMatos Path Finder in Splunk Search 09-10-2013
0 6
0
6
splunkhelp
Good Day! Given the following data... srcdst1.2.3.49.8.7.61.2.3.49.8.7.61.2.3.49.8.7.64.3.2.16.7.8.91.2.3.45.6.7.8 ...
by splunkhelp Explorer in Splunk Search 09-10-2013
1 1
1
1
mirjam_labrenz
I have a map with Map and a SetMulitmap and I'm not really familiar with splunk at the moment. So how do I search i...
by mirjam_labrenz New Member in Splunk Search 09-10-2013
0 1
0
1
xvxt006
I am looking for regex to capture all the URIs which includes "chaser" (case insensitive). I have used this <base s...
by xvxt006 Contributor in Splunk Search 09-09-2013
0 2
0
2
whathuh
I'm pretty new to Splunk, so hopefully this is an easy question. I've looked all over the community questions and I ...
by whathuh New Member in Splunk Search 09-09-2013
0 2
0
2
ccsfdave
Greetings, My journey continues. Now I would like to have a lookup match either the source or destination IP to an ...
by ccsfdave Builder in Splunk Search 09-09-2013
0 3
0
3
ebailey
The following gives me exactly what I want host=****** Failed_Reason minutesago=15 | rex "\>(?<Failed_Reason>.*?)\<"...
by ebailey Communicator in Splunk Search 09-09-2013
0 4
0
4
Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors