Splunk Search

Splunk Search
Community Activity
ttrumm
Hi, I have a search: source="/var/log/mail.log" to="*mail.com" OR from="*@mail.com" How can i build report where...
by ttrumm New Member in Splunk Search 08-22-2013
0 1
0
1
royimad
Hello, I have a text extracted in a field called MessageBody , the text contains multilines not a single lines and f...
by royimad Builder in Splunk Search 08-22-2013
0 2
0
2
jel_splunk
Hi When doing a query like so * | timechart span=1d count I would expect the intervals on the x-axis to be 1 day p...
by jel_splunk Explorer in Splunk Search 08-22-2013
1 7
1
7
awsdcuser
I recently updated Cisco Firewalls and Cisco IPS apps to the latest versions (2.0 and 2.0.0). Now when I perform a se...
by awsdcuser Explorer in Splunk Search 08-21-2013
1 7
1
7
jrodriguezap
Hello. Appreciate your support, in the file transforms.conf REGEX try to make a log of all without "webfilter" and se...
by jrodriguezap Contributor in Splunk Search 08-21-2013
0 10
0
10
drapkin11
The following search returns results: "context" But this one does not: regex "context" And neither does thi...
by drapkin11 Explorer in Splunk Search 08-21-2013
0 3
0
3
tpederson
I need help building a chart that has a dynamic baseline based on the last 30 days of data. Over that baseline, I wo...
by tpederson Path Finder in Splunk Search 08-21-2013
0 1
0
1
alange
(Splunk 4.3.2, in case it makes a difference) I'm using rex to extract a sequence of digits, and I'd like Splunk to ...
by alange Explorer in Splunk Search 08-21-2013
0 4
0
4
the_wolverine
I have spun up a new index in Production and want to quickly test that it is properly configured. I'd like to confir...
by the_wolverine Champion in Splunk Search 08-21-2013
0 1
0
1
royimad
I have a text that contains anything followed by a word that start with either XPOS, POS and HF and ended by - Exa...
by royimad Builder in Splunk Search 08-21-2013
0 9
0
9
royimad
I have a file that contains consecutive - example: somefields - anything - anything - ... - anything ABC DEF 2323...
by royimad Builder in Splunk Search 08-21-2013
0 1
0
1
crazyeva
hello I have my log form as multi lines breaked with an empty line thanks to ziegfried, I have devided each event suc...
by crazyeva Contributor in Splunk Search 08-21-2013
0 8
0
8
msarro
Hey everyone. This is my first time working with data like this, so I'm a little bit lost. Here is a sample: System ...
by msarro Builder in Splunk Search 08-21-2013
0 1
0
1
echojacques
So I have this REGEX statement in a transforms.conf file: REGEX = (service=53|service=5101) I'm new to REGEX but I ...
by echojacques Builder in Splunk Search 08-21-2013
0 8
0
8
responsys_cm
I'm trying to get Splunk to login to a MS SQL database and execute a stored procedure based upon data in the events. ...
by responsys_cm Builder in Splunk Search 08-21-2013
0 3
0
3
tevgey23
Hello, I wanted to know what would be the best way to extract the st (stratum) field from the NTP event (in this ca...
by tevgey23 Explorer in Splunk Search 08-21-2013
0 4
0
4
a212830
Hi, I'm trying to use the field extractor to create some field. When I click on an event, and choose "Extract fields...
by a212830 Champion in Splunk Search 08-21-2013
0 3
0
3
gelica
Hi, I'm having some issues with timechart. I'm overriding _time in props.conf, since my timestamp is extracted from ...
by gelica Communicator in Splunk Search 08-21-2013
0 2
0
2
tyronetv
I have a set of two logs that share a common field (RID). One log contains the "user" actions while the other log co...
by tyronetv Communicator in Splunk Search 08-21-2013
0 6
0
6
happy035
Hello, I'm trying to compose search, that will show me srcIP, dstIP, count by dstIP like this: srcIP dstIP ...
by happy035 Explorer in Splunk Search 08-21-2013
0 2
0
2
Armyeric
I have the search: index="weblogs" filter_result!="-" useragent="* (compatible; MSIE 10.6; )" OR useragent=" (compat...
by Armyeric Path Finder in Splunk Search 08-21-2013
0 3
0
3
ephemeric
Greetz, Does anyone know if multiple SEDCMDs are supported at index time in props.conf? Also, can I implement this ...
by ephemeric Contributor in Splunk Search 08-21-2013
1 4
1
4
timmalos
Hey. I have these kind of datas every one week : "SilkWorm48000",SwitchWWN ,160,"SwSerialNumber","http://UrlManageme...
by timmalos Communicator in Splunk Search 08-21-2013
0 5
0
5
a212830
Hi, I need to check to see if a list of users (150+) have logged in recently. The data comes in via syslog, and I'v...
by a212830 Champion in Splunk Search 08-20-2013
0 1
0
1
cpeteman
I want to remove a string from _raw that appears as a field in Splunk say host. For example if I have the _raw messag...
by cpeteman Contributor in Splunk Search 08-20-2013
7 7
7
7
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...