Splunk Search

Splunk Search
Community Activity
msarro
Hey everyone. This is my first time working with data like this, so I'm a little bit lost. Here is a sample: System ...
by msarro Builder in Splunk Search 08-21-2013
0 1
0
1
echojacques
So I have this REGEX statement in a transforms.conf file: REGEX = (service=53|service=5101) I'm new to REGEX but I ...
by echojacques Builder in Splunk Search 08-21-2013
0 8
0
8
responsys_cm
I'm trying to get Splunk to login to a MS SQL database and execute a stored procedure based upon data in the events. ...
by responsys_cm Builder in Splunk Search 08-21-2013
0 3
0
3
tevgey23
Hello, I wanted to know what would be the best way to extract the st (stratum) field from the NTP event (in this ca...
by tevgey23 Explorer in Splunk Search 08-21-2013
0 4
0
4
a212830
Hi, I'm trying to use the field extractor to create some field. When I click on an event, and choose "Extract fields...
by a212830 Champion in Splunk Search 08-21-2013
0 3
0
3
gelica
Hi, I'm having some issues with timechart. I'm overriding _time in props.conf, since my timestamp is extracted from ...
by gelica Communicator in Splunk Search 08-21-2013
0 2
0
2
tyronetv
I have a set of two logs that share a common field (RID). One log contains the "user" actions while the other log co...
by tyronetv Communicator in Splunk Search 08-21-2013
0 6
0
6
happy035
Hello, I'm trying to compose search, that will show me srcIP, dstIP, count by dstIP like this: srcIP dstIP ...
by happy035 Explorer in Splunk Search 08-21-2013
0 2
0
2
Armyeric
I have the search: index="weblogs" filter_result!="-" useragent="* (compatible; MSIE 10.6; )" OR useragent=" (compat...
by Armyeric Path Finder in Splunk Search 08-21-2013
0 3
0
3
ephemeric
Greetz, Does anyone know if multiple SEDCMDs are supported at index time in props.conf? Also, can I implement this ...
by ephemeric Contributor in Splunk Search 08-21-2013
1 4
1
4
timmalos
Hey. I have these kind of datas every one week : "SilkWorm48000",SwitchWWN ,160,"SwSerialNumber","http://UrlManageme...
by timmalos Communicator in Splunk Search 08-21-2013
0 5
0
5
a212830
Hi, I need to check to see if a list of users (150+) have logged in recently. The data comes in via syslog, and I'v...
by a212830 Champion in Splunk Search 08-20-2013
0 1
0
1
cpeteman
I want to remove a string from _raw that appears as a field in Splunk say host. For example if I have the _raw messag...
by cpeteman Contributor in Splunk Search 08-20-2013
7 7
7
7
harsh1734
hi , in my log files their is field known as CPU TIME.. which has values:- Jan 16 12:51:35 Phase 1 ended (674 seco...
by harsh1734 New Member in Splunk Search 08-20-2013
0 1
0
1
jbouch03
I am relatively new to Splunk and I am trying to create a percent of error metric. I have two log sources that have a...
by jbouch03 Path Finder in Splunk Search 08-20-2013
0 2
0
2
FRoth
I try to search for Windows logins in which the "Workstation Name" is different from the "ComputerName". The problem...
by FRoth Contributor in Splunk Search 08-20-2013
0 1
0
1
flora123
hi! I want to get the highest daily traffic by day, so I try this as below ... | convert timeformat="%Y/%m/%d" ctime...
by flora123 Path Finder in Splunk Search 08-19-2013
0 6
0
6
crazyeva
i am still confused after reading the reference for example i fabricated some data and search with "|transaction host...
by crazyeva Contributor in Splunk Search 08-19-2013
0 6
0
6
ssankeneni
I'm trying to set up a alert If I don't see a log message with in 15 minutes span of time. I extracted a filed from ...
by ssankeneni Communicator in Splunk Search 08-19-2013
0 10
0
10
alcm_b
In *NIX, there is a command grep -f 'long_list_of_regex' 'my_log_file' , which reads a list of search commands from...
by alcm_b Engager in Splunk Search 08-19-2013
0 2
0
2
timmalos
Hi. Im using a Saved Search in a dashboard and cant manage to find if what i want to do is possible. I want my searc...
by timmalos Communicator in Splunk Search 08-19-2013
0 3
0
3
timmalos
Hi I got a complex situation i'll try to explain best as possible: I have some jobs events. I group them by Policy. I...
by timmalos Communicator in Splunk Search 08-19-2013
0 6
0
6
harsh1734
hi, i have installed python sdk and in ./splunkrc file given user name and passwd so that it can connect my splunk .....
by harsh1734 New Member in Splunk Search 08-19-2013
0 1
0
1
makeoshimi_chan
searchコマンドのstarttimeおよびendtimeオプションでミリ秒を使用したいのですが、可能でしょうか? 具体的には、08/16/2013:20:07:34.645以前のデータを検索したいです search endtim...
by makeoshimi_chan New Member in Splunk Search 08-19-2013
0 5
0
5
ChhayaV
Hi, I have a search query which includes subsearch as follows: host="sharepoint" | rex field=msg "\sMore\sinformat...
by ChhayaV Communicator in Splunk Search 08-18-2013
1 3
1
3
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...