Splunk Search

Splunk Search
Community Activity
cpeteman
I want to remove a string from _raw that appears as a field in Splunk say host. For example if I have the _raw messag...
by cpeteman Contributor in Splunk Search 08-20-2013
7 7
7
7
harsh1734
hi , in my log files their is field known as CPU TIME.. which has values:- Jan 16 12:51:35 Phase 1 ended (674 seco...
by harsh1734 New Member in Splunk Search 08-20-2013
0 1
0
1
jbouch03
I am relatively new to Splunk and I am trying to create a percent of error metric. I have two log sources that have a...
by jbouch03 Path Finder in Splunk Search 08-20-2013
0 2
0
2
FRoth
I try to search for Windows logins in which the "Workstation Name" is different from the "ComputerName". The problem...
by FRoth Contributor in Splunk Search 08-20-2013
0 1
0
1
flora123
hi! I want to get the highest daily traffic by day, so I try this as below ... | convert timeformat="%Y/%m/%d" ctime...
by flora123 Path Finder in Splunk Search 08-19-2013
0 6
0
6
crazyeva
i am still confused after reading the reference for example i fabricated some data and search with "|transaction host...
by crazyeva Contributor in Splunk Search 08-19-2013
0 6
0
6
ssankeneni
I'm trying to set up a alert If I don't see a log message with in 15 minutes span of time. I extracted a filed from ...
by ssankeneni Communicator in Splunk Search 08-19-2013
0 10
0
10
alcm_b
In *NIX, there is a command grep -f 'long_list_of_regex' 'my_log_file' , which reads a list of search commands from...
by alcm_b Engager in Splunk Search 08-19-2013
0 2
0
2
timmalos
Hi. Im using a Saved Search in a dashboard and cant manage to find if what i want to do is possible. I want my searc...
by timmalos Communicator in Splunk Search 08-19-2013
0 3
0
3
timmalos
Hi I got a complex situation i'll try to explain best as possible: I have some jobs events. I group them by Policy. I...
by timmalos Communicator in Splunk Search 08-19-2013
0 6
0
6
harsh1734
hi, i have installed python sdk and in ./splunkrc file given user name and passwd so that it can connect my splunk .....
by harsh1734 New Member in Splunk Search 08-19-2013
0 1
0
1
makeoshimi_chan
searchコマンドのstarttimeおよびendtimeオプションでミリ秒を使用したいのですが、可能でしょうか? 具体的には、08/16/2013:20:07:34.645以前のデータを検索したいです search endtim...
by makeoshimi_chan New Member in Splunk Search 08-19-2013
0 5
0
5
ChhayaV
Hi, I have a search query which includes subsearch as follows: host="sharepoint" | rex field=msg "\sMore\sinformat...
by ChhayaV Communicator in Splunk Search 08-18-2013
1 3
1
3
BenisLion
Hi, I am new to Splunk, And I'm trying to get the latest 6 months's data(about 11,000 datas), and store into Mongo db...
by BenisLion Engager in Splunk Search 08-18-2013
0 1
0
1
rakesh_498115
Hi.. I am interseted in creating a feedback form for my splunk app. i had the html page and the php code for the sam...
by rakesh_498115 Motivator in Splunk Search 08-17-2013
0 2
0
2
abhayneilam
I am getting the following warning while running my big query : auto-finalized after time limit ( 30 seconds ) reac...
by abhayneilam Contributor in Splunk Search 08-17-2013
0 2
0
2
rettops
We have performance problems. Looking at one of the search logs, I see that it ends with 08-16-2013 14:00:55.172 IN...
by rettops Path Finder in Splunk Search 08-16-2013
3 2
3
2
supersleepwalke
How do I get all the individual event times from a transaction and have them in a multivalue field as part of the tra...
by supersleepwalke Communicator in Splunk Search 08-16-2013
0 1
0
1
splunkpoornima
I want to find the time difference between the transactions,display as a chart My data will look like this Mon Sep ...
by splunkpoornima Communicator in Splunk Search 08-16-2013
0 5
0
5
andywins
I'm seeing three seconds of latency introduced to each search when using ~3,500 indexes. Here's the scenario: ~3,00...
by andywins Explorer in Splunk Search 08-16-2013
1 11
1
11
mikelanghorst
I have events that I'm joining together via transaction. Once in a transaction a field can have multiple values. Ho...
by mikelanghorst Motivator in Splunk Search 08-16-2013
0 2
0
2
pero1234
How to put | search splunk_web_service="574.357430" before | rex command in drilldown table? I mean, after click on ...
by pero1234 Path Finder in Splunk Search 08-16-2013
0 3
0
3
Matthias_BY
Hello, i have a scripted lookup which is working fine. i configured in the lookups that the field name is called cli...
by Matthias_BY Communicator in Splunk Search 08-16-2013
0 2
0
2
msmapper
I am trying create some new logging formats for some new data and I want to ensure it Splunk friendly, so I can do a ...
by msmapper Path Finder in Splunk Search 08-16-2013
0 2
0
2
Simon
Hi all, I've got 16k and growing values in a CSV. I'd like to search for events matching those values, like tag::ev...
by Simon Contributor in Splunk Search 08-16-2013
0 1
0
1
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...