Splunk Search

Splunk Search
Community Activity
TiagoMatos
Hello, I have a table that returns with these fields: AvgLow and AvgLowNOW, but they appear many times, like this Av...
by TiagoMatos Path Finder in Splunk Search 09-10-2013
0 6
0
6
splunkhelp
Good Day! Given the following data... srcdst1.2.3.49.8.7.61.2.3.49.8.7.61.2.3.49.8.7.64.3.2.16.7.8.91.2.3.45.6.7.8 ...
by splunkhelp Explorer in Splunk Search 09-10-2013
1 1
1
1
mirjam_labrenz
I have a map with Map and a SetMulitmap and I'm not really familiar with splunk at the moment. So how do I search i...
by mirjam_labrenz New Member in Splunk Search 09-10-2013
0 1
0
1
xvxt006
I am looking for regex to capture all the URIs which includes "chaser" (case insensitive). I have used this <base s...
by xvxt006 Contributor in Splunk Search 09-09-2013
0 2
0
2
whathuh
I'm pretty new to Splunk, so hopefully this is an easy question. I've looked all over the community questions and I ...
by whathuh New Member in Splunk Search 09-09-2013
0 2
0
2
ccsfdave
Greetings, My journey continues. Now I would like to have a lookup match either the source or destination IP to an ...
by ccsfdave Builder in Splunk Search 09-09-2013
0 3
0
3
ebailey
The following gives me exactly what I want host=****** Failed_Reason minutesago=15 | rex "\>(?<Failed_Reason>.*?)\<"...
by ebailey Communicator in Splunk Search 09-09-2013
0 4
0
4
jaywilwk
how can I do a ratio search not based on count, but based on src_bytes (inbound traffic) to get a ratio for two field...
by jaywilwk Engager in Splunk Search 09-09-2013
0 11
0
11
xvxt006
Hi, I am want to get all the events ending with a referrer url of the below format. http://www.company.com/product/...
by xvxt006 Contributor in Splunk Search 09-09-2013
0 7
0
7
Bryan_Rye
Hello. I want to be able to add subsearches in the same row. Example: Search #1.....| append [search #2....] | app...
by Bryan_Rye New Member in Splunk Search 09-09-2013
0 1
0
1
gsd
Newbie here, so please be kind! Not sure if this is even possible, but I need to find out if a user has never logged...
by gsd New Member in Splunk Search 09-09-2013
0 11
0
11
hartfoml
I am trying to use Case to rename taged events like this tag=audit OR tag=cleared "" | eval Event=case( tag == audit...
by hartfoml Motivator in Splunk Search 09-09-2013
0 8
0
8
aviramradai
Hi, I have rails requests which take more then 15 sec. Rails write to the production.log in 2 steps. It seem that sp...
by aviramradai Explorer in Splunk Search 09-08-2013
0 1
0
1
rtadams89
I have been using a complex search query (it's difficult for me to post it here without exposing internal information...
by rtadams89 Contributor in Splunk Search 09-06-2013
2 4
2
4
rmcdougal
I am attempting to setup an alert to warn me of license usage but I am receiving bogus information back. This is sea...
by rmcdougal Path Finder in Splunk Search 09-06-2013
1 7
1
7
kenchisho
Hi guys... I have been working on a few splunk apps during the last 6 months... in that time i have ran into a pecul...
by kenchisho Path Finder in Splunk Search 09-06-2013
0 5
0
5
xvxt006
Hi, I am extracting a field and when i have .*? i am getting right value. But when i have .* it is giving unnecessar...
by xvxt006 Contributor in Splunk Search 09-06-2013
0 5
0
5
fbl_itcs
Hi, let's say we have an event with the following information: "Network Information: Client Address: ee:fa:23:12...
by fbl_itcs Path Finder in Splunk Search 09-06-2013
0 5
0
5
cwl
イベントをインデックスする前に特定のフィールドの内容を transforms.conf 内の REGEX で加工しているが、4500適度(かそれ以上)の文字のイベントに対し、REGEXで指定した正規表現が正しく処理されない。
by cwl Contributor in Splunk Search 09-05-2013
0 1
0
1
theouhuios
Hello I have a string like this a SysStatsUtilizationDiskSpace=17.60% /, SysStatsUtilizationDiskSpace=11.25% /stor...
by theouhuios Motivator in Splunk Search 09-05-2013
0 1
0
1
jericksonpf
Hi, I have a field called UserID appearing in my searches that in two of my sourcetypes within the same index. Ive s...
by jericksonpf Path Finder in Splunk Search 09-05-2013
0 9
0
9
hartfoml
I am looking for logon errors from both windows and nix systems and trying to get as much data to match up as proposa...
by hartfoml Motivator in Splunk Search 09-05-2013
0 4
0
4
werz
Where do I need to place a copy of the popup.js script in order to override it? Is it even possible? I have tried pl...
by werz New Member in Splunk Search 09-05-2013
0 1
0
1
Simon_Shelston
I'd like to clear my search history. How do I do that?
by Simon_Shelston Splunk Employee Splunk Employee in Splunk Search 09-05-2013
10 4
10
4
sbsbb
I have a first search, that return "system1" Then I want to use that value, to get the appropriate value out of a su...
by sbsbb Builder in Splunk Search 09-05-2013
0 6
0
6
Get Updates on the Splunk Community!

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...