Splunk Search

Splunk Search
Community Activity
cwacha
Hi, I have built an app that aggregates data into a summary index. The app also provides a query that searches for t...
by cwacha Path Finder in Splunk Search 08-05-2013
0 1
0
1
splunkuser2013
I would like to use function case and regex together and extract the value of capturing group in one field e.g. http_...
by splunkuser2013 New Member in Splunk Search 08-05-2013
0 3
0
3
ChhayaV
hi, Is there any performance impact if i use inline search instead of saved one? Thanks and Regards
by ChhayaV Communicator in Splunk Search 08-05-2013
0 1
0
1
pembleton
Hey, quite a long post, but I'm going crazy here trying to solve this problem: I have a connection log of: id, userna...
by pembleton Path Finder in Splunk Search 08-05-2013
1 2
1
2
jsash1
Hi, I have a requirement for an event detection engine which is able to identify a string (e.g. username) in a parti...
by jsash1 New Member in Splunk Search 08-04-2013
0 3
0
3
craigcook
I've just started using summary indexes - I have two searches that work as expected on querying data in just the prev...
by craigcook New Member in Splunk Search 08-04-2013
0 1
0
1
kailun92
Hi all, I need to join two table up and do a count of rain. Below is my search query is there anything wrong ? I can'...
by kailun92 Communicator in Splunk Search 08-03-2013
0 6
0
6
Lowell
I have a questions about custom search commands and the streaming_preop option. Is there some reason why the preopt ...
by Lowell Super Champion in Splunk Search 08-02-2013
1 1
1
1
michartmann
We want to restrict certain usergroups possibility to search in Splunk based on a dynamic parameter For instance Me...
by michartmann Engager in Splunk Search 08-02-2013
1 4
1
4
ssehgal
Is there a way to limit the length of the results for a particular field? For example, if the URL/ref field is 100cha...
by ssehgal Explorer in Splunk Search 08-02-2013
1 1
1
1
ssehgal
hello i have a problem with splunk results. in some of the RAW logs i have a field called as "ref" and in some logs i...
by ssehgal Explorer in Splunk Search 08-02-2013
0 1
0
1
msarro
Here is our situation, we handle calls. Every call generates a record. We would like to find out, over the span of 1 ...
by msarro Builder in Splunk Search 08-02-2013
0 1
0
1
gnoellbn
Hello, I'm trying to show login stats from different sources by user. Those two sources d'on't show user with the sa...
by gnoellbn Explorer in Splunk Search 08-02-2013
0 1
0
1
gnoellbn
Hello, I'm trying to run the following search in order to list all the failed connection. In our parc we have compu...
by gnoellbn Explorer in Splunk Search 08-02-2013
0 2
0
2
gelica
Hi, When I'm indexing my logs, I extract a field called "file_date" from my source. The field is of the form 2013-07...
by gelica Communicator in Splunk Search 08-02-2013
0 3
0
3
antlefebvre
This is my scenario When I so a search on my event log there are 2 events for the same user. I have extracted the fi...
by antlefebvre Communicator in Splunk Search 08-02-2013
0 3
0
3
TiagoMatos
Hello! I'm trying to make a timechart with this: sourcetype=processedsiebel NOT error*| eval X =replace(SWEMethod, ...
by TiagoMatos Path Finder in Splunk Search 08-02-2013
0 4
0
4
AlexBryant
I am working with the fields srcip and malware-type. I need to show how many instances of each type of malware have b...
by AlexBryant Path Finder in Splunk Search 08-02-2013
0 3
0
3
rhelie
Hello, I am new to Splunk and I set it up and configured my Sonicwall TZ200 to send syslog information to it. That w...
by rhelie Engager in Splunk Search 08-02-2013
1 2
1
2
harsh1734
hi, in my log files there is a field name cpu time with different time values like 57.682 sec,0.572 sec and among the...
by harsh1734 New Member in Splunk Search 08-02-2013
0 3
0
3
zoh
How to replace from right. for example I want to replace string "3:12:34" to "3 hours 12 minutes 34 seconds". but in ...
by zoh Explorer in Splunk Search 08-02-2013
0 1
0
1
splunkmeuser
sourcetype="apache-access" | rex "(?i)\(.*?; (?P\w+)(?=/)" | top 100 FIELDNAME i'm using the above to get informatio...
by splunkmeuser New Member in Splunk Search 08-01-2013
0 1
0
1
shangshin
Hi, I am using splunk 5.0.3 but found fields can't be extracted automatically on the splunk UI. To test, I loaded the...
by shangshin Builder in Splunk Search 08-01-2013
1 5
1
5
clintla
Trying to parse out a set of stanza Node 1 Device 1 Healthy Device 2 Healthy Device 3 Healthy Node 2 Device 1 He...
by clintla Contributor in Splunk Search 08-01-2013
0 2
0
2
tnconners
I'm working on developing an app for a client, I'm looking to display the alerts that have fired (like it would appea...
by tnconners Explorer in Splunk Search 08-01-2013
0 3
0
3
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors