| Thread Info | |||||
|---|---|---|---|---|---|
| 
        I am using a tail db command to pull events from a Oracle database every hour. I was able to pull in all of the data ...
        
         
           by 
           
                
                    
                        knewter
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               06-21-2013
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        I'm trying to figure out how to analyze and manage specific records in the _fishbucket index.  
  I have big director...
        
         
           by 
           
                
                    
                        pembleton
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-06-2013
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        Hi all, I'm pulling some logs in from Windows perfmon. All was going well, but now I am seeing the following error me...
        
         
           by 
           
                
                    
                        BenjaminWyatt
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-03-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Arg this is so frustrating. 
  I cant find the nix_action_lookup and I can't find the IDS config. 
  How do i trouble...
        
         
           by 
           
                
                    
                        hartfoml
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I am running a query via a created dashboard on one of my production databases. I defined this in the DB Connect app,...
        
         
           by 
           
                
                    
                        Karunamon
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-18-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Can anybody enlighten me on why the form below (shortened) works when it's designed exactly this way, but not in any ...
        
         
           by 
           
                
                    
                        usd0872
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-02-2013
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        We're trying to compare searches from our Security source, trying to see if someone hasn't logged in within the last ...
        
         
           by 
           
                
                    
                        mhamill
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  when trying to filter a high EPS feed with a lookup I am experiencing quite some performance issues. Are are k...
        
         
           by 
           
                
                    
                        Olli1919
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hello, 
  We have the following table with this search but would like to drill down to a table with just the ticket d...
        
         
           by 
           
                
                    
                        aaronkorn
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               07-30-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Greetz, 
  Is it possible to search a range of bucket ids? 
  I have moved a lot of warm/cold buckets and scrubbed th...
        
         
           by 
           
                
                    
                        ephemeric
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               05-22-2012
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        One of our users has a lookup requirement that I'm struggling to find a workable solution. They want to have a number...
        
         
           by 
           
                
                    
                        samhughe
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-01-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I would like to create a timechart with an SLA value. 
  I have tried this search sourcetype=foo | eval sla=50 | time...
        
         
           by 
           
                
                    
                        hartfoml
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               01-16-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi All 
  I've got a very bad csv to index, which is basically a csv with 63 columns and tildes as separators, becaus...
        
         
           by 
           
                
                    
                        Simon
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               07-09-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        hi, 
  I have a log files which are having columns that are not fixed. if first log entry has col1,col2,col3 then nex...
        
         
           by 
           
                
                    
                        ChhayaV
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        How would CPU core load or CPU core sizing be split between a search head and its peer indexer when "searches with re...
        
         
           by 
           
                
                    
                        Mag2sub
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello, 
  We have the following search in a chart but the dates are sorting alphabetically rather than numerically. i...
        
         
           by 
           
                
                    
                        aaronkorn
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        All, 
  I'm wondering if there is a way to change my configuration files to ignore the capitalization of a field. For...
        
         
           by 
           
                
                    
                        bruceclarke
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        What I want is:  
  ... | stats avg(eval(MyValue!=0)) as Avg
 
  It doesn't work that way (Avg is always 1.0). 
  Of ...
        
         
           by 
           
                
                    
                        greg
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-27-2012
             
           
         
        | 
		
		0
   | 
	  
	  9
	 | |||
| 
        Hello, 
  We have the following chart which displays current ticket counts over the last 7 days for different groups ...
        
         
           by 
           
                
                    
                        aaronkorn
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               07-30-2013
             
           
         
        | 
		
		2
   | 
	  
	  10
	 | |||
| 
        Hi 
  I know that splunk automatically creates default fields like host,sourcetype,index at index time.And also the s...
        
         
           by 
           
                
                    
                        adityapavan18
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-02-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        hi, 
  I want to do a lookup to a CSV file which is having multi line field value when i upload a file for lookup its...
        
         
           by 
           
                
                    
                        ChhayaV
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-04-2013
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi, 
  I have built an app that aggregates data into a summary index. The app also provides a query that searches for...
        
         
           by 
           
                
                    
                        cwacha
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I would like to use function case and regex together and extract the value of capturing group in one field e.g. http_...
        
         
           by 
           
                
                    
                        splunkuser2013
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        hi, 
  Is there any performance impact if i use inline search instead of saved one?  
  Thanks and Regards
        
         
           by 
           
                
                    
                        ChhayaV
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-05-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hey, quite a long post, but I'm going crazy here trying to solve this problem: I have a connection log of: id, userna...
        
         
           by 
           
                
                    
                        pembleton
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-04-2013
             
           
         
        | 
		
		1
   | 
	  
	  2
	 |