Splunk Search

Splunk Search
Community Activity
ryastrebov
Hello splunkers! I create sourcetype and I extract some fields by Field Extraction menu. I copy the props.conf file ...
by ryastrebov Communicator in Splunk Search 08-16-2013
0 2
0
2
appleman
サーチをする際に、カスタム時間で時間を指定し(○月○日の断面等)、出た結果に対し、更にそれから1週間前のデータと比べるサーチ文をご教授下さい。 sourcetype=A | stats count by host | append ...
by appleman Contributor in Splunk Search 08-16-2013
0 6
0
6
mw
I have a scripted lookup which is part of an app that I've written and it works perfectly. What's the proper way to ...
by mw Splunk Employee Splunk Employee in Splunk Search 08-15-2013
0 1
0
1
dictudatacom
Hi, I want to extract the 'subjects' from my SMTP maillog but the regex I have built doesn't seem to work. I have bui...
by dictudatacom New Member in Splunk Search 08-15-2013
0 6
0
6
suepfarrell
Hi Our fields have a space between the field name and the information we want to . The two searches I have tried ar...
by suepfarrell New Member in Splunk Search 08-15-2013
0 5
0
5
moffitt
I want to query my access logs to learn where the majority of my traffic is coming from in 1 second buckets. This is ...
by moffitt Engager in Splunk Search 08-15-2013
1 4
1
4
vermicknid
Hi there! Being new and still struggling mightily to master Splunk, I have an immediate need to create a search/repo...
by vermicknid New Member in Splunk Search 08-15-2013
0 3
0
3
a212830
Hi, Do real-time searches read events before they enter the indexer?
by a212830 Champion in Splunk Search 08-15-2013
0 2
0
2
snabi
So i have two saved search queries 1. sourcetype="x" "attempted" source="y" | stats count 2. sourcetype="x" "Failed...
by snabi Explorer in Splunk Search 08-15-2013
1 2
1
2
christian_l
Hi there, I'd like to modify the default search form of Splunk (flashtimeline view) for a new app. Therefore I'd lik...
by christian_l Path Finder in Splunk Search 08-15-2013
0 1
0
1
skjelmose
Hi there, I have an errp log from aix that i want to process and determine on with side of the cluster we had proble...
by skjelmose New Member in Splunk Search 08-15-2013
0 5
0
5
hobbes3
I'm playing with the Splunk tutorial data and I have this query that shows the top 5 customer per purchased product a...
by hobbes3 Explorer in Splunk Search 08-15-2013
0 1
0
1
dirkbaumann
Hi together, I have found the following fill_summray_index.py script under: http://wiki.splunk.com/Community:Summary_...
by dirkbaumann Explorer in Splunk Search 08-15-2013
0 1
0
1
cmahan
I need to run weekly reports that show all Error Messages that have occurred and have it split by the computernames a...
by cmahan Path Finder in Splunk Search 08-15-2013
0 8
0
8
rakesh_498115
Hi . I have using a form with a textbox and search button ? wat ever the data i given in textbox it should be added ...
by rakesh_498115 Motivator in Splunk Search 08-15-2013
0 2
0
2
dominiquevocat
We have customized our internal applications to a custom key=value schema and it usually works well. Splunk usually r...
by SplunkTrust SplunkTrust in Splunk Search 08-15-2013
0 4
0
4
avishayh
I am trying to display in one table a difference from a performance log to a specific service from 2 diffrent times (...
by avishayh Explorer in Splunk Search 08-15-2013
0 2
0
2
dbashyam
Hi, I am looking for a splunk search to find which IP's are connecting to port 9997? index=sys_*prod source=netstat...
by dbashyam Explorer in Splunk Search 08-15-2013
0 2
0
2
kisa
Hi, I'm performing a search using advanced xml that returns a key/value pair (among other things). E.g. Filename=so...
by kisa Explorer in Splunk Search 08-15-2013
0 10
0
10
edrad80
Hi I have a basic XML file returning, Date-time value and a value in seconds see example("GmtDateTime":"2013-08-14 0...
by edrad80 New Member in Splunk Search 08-15-2013
0 2
0
2
taozi021
for example: if the current time 5:23:20 PM, how can i get the time 4:55:00 PM. and if the current time 5:26:12 PM, h...
by taozi021 Explorer in Splunk Search 08-14-2013
1 5
1
5
hartfoml
Anyone have a suggestion on how I can add a digital clock or even a world clock to the header in the default view for...
by hartfoml Motivator in Splunk Search 08-14-2013
0 2
0
2
cpeteman
I want regex to remove all numbers from _raw message. Right now I have the search * |rex mode=sed "s/ \d{1,}//g" |t...
by cpeteman Contributor in Splunk Search 08-14-2013
0 1
0
1
leznx
Hi, I have one problem here. I need to create a search with 2 groups, and create a chart with result. Example, ...
by leznx Engager in Splunk Search 08-14-2013
0 6
0
6
bdstark
I am trying to create a field extraction using the manger to extract the equivalent of: sourcetype=jsonLogs | rex fi...
by bdstark New Member in Splunk Search 08-14-2013
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...