Thread Info | |||||
---|---|---|---|---|---|
Hi,
I am a new user to splunk.
Our splunk data consists of lines like:
engine id=
error1
en...
by
atevs
New Member
in
Splunk Search
07-28-2013
|
0
|
1
| |||
I have this search query sourcetype="CurrentWeatherSGMap" Message="Yishun" | eval Description=case(current_summary="R...
by
sbnoobbb
Path Finder
in
Splunk Search
07-18-2013
|
0
|
3
| |||
Hi All,
I have been writing some search queries and now i have written a search query for which im getting a no of...
by
ppurokit
Path Finder
in
Splunk Search
07-19-2013
|
0
|
2
| |||
Hi,
I am using multiple sources in a single search command and i want to rename the _raw field of one of the sourc...
by
Zyon
Engager
in
Splunk Search
07-27-2013
|
0
|
2
| |||
I'm seeing a number of very large files building up in /opt/splunk/var/spool/splunk:
drwx------ 2 root root 4096 ...
by
responsys_cm
Builder
in
Splunk Search
02-26-2013
|
1
|
4
| |||
Hi everyone, Been trying to get regex syntax to behave. What I have below works. It only shows events that are from t...
by
schnibitz
New Member
in
Splunk Search
07-24-2013
|
0
|
1
| |||
I would like to take the following lines in my props.conf file, and at Search Time, use these Field Extractions to Se...
by
jmsiegma
Path Finder
in
Splunk Search
07-26-2013
|
0
|
1
| |||
I'm in search of the above tips on how to solve?
by
wudu0517
New Member
in
Splunk Search
07-22-2013
|
0
|
7
| |||
I have setup a field extraction that parses OC4J Apache logs of the following format and extracts the ecid:
index=...
by
ravishankarr
Explorer
in
Splunk Search
07-24-2013
|
0
|
4
| |||
Greetings,
I have a saved & shared search URL that has the SID in it. The search has long expired, and I'd like to...
by
davidpaper
Contributor
in
Splunk Search
07-26-2013
|
4
|
1
| |||
I feel like this should be a piece of cake with distinct count. I'd like to turn this into a more elegant search:
...
by
cpeteman
Contributor
in
Splunk Search
07-26-2013
|
0
|
4
| |||
I've read many a post and either I'm just not getting it or it's just not the answer. I want to index the daily catal...
by
jchilovich
New Member
in
Splunk Search
07-23-2013
|
0
|
5
| |||
In in my host field I have several different addresses, 4 of these addresses are from Location1 and the rest are from...
by
rlautman
Path Finder
in
Splunk Search
07-25-2013
|
0
|
3
| |||
In our splunk instance I believe the props.config file is set to UTC as that is what most of our logs are in but we d...
by
tb5821
Communicator
in
Splunk Search
07-26-2013
|
0
|
2
| |||
Hello,
I'm trying to report a number of different stats however only one of the stats needs to be by month. All of...
by
timmoammo
New Member
in
Splunk Search
07-25-2013
|
0
|
3
| |||
Hi! I would like to know the frequency of each value of a certain field inside a transaction, for example: my event a...
by
emaccaferri
Communicator
in
Splunk Search
07-23-2013
|
0
|
8
| |||
The following query construct populates a summary index:
source=1.log OR source=2.log |
eval _time = case(source ...
by
lpolo
Motivator
in
Splunk Search
06-13-2013
|
1
|
3
| |||
I have done testing the calculated fields for Splunk DB Connect in my local machine. Basically I added props.conf fil...
by
dan60201
Explorer
in
Splunk Search
07-23-2013
|
0
|
7
| |||
Hi All,
Am trying to find the usage of correlation. When i try my search using coorelation, it gives me an output,...
by
Paul_tcs
Explorer
in
Splunk Search
07-22-2013
|
0
|
1
| |||
I've got a long-running search that's spending more time than necessary in command.search.typer. I say more time than...
by
sowings
Splunk Employee
in
Splunk Search
07-17-2013
|
1
|
4
| |||
I'm sure this is easy to do, but I'm a bit stumped. Say I have a search like this:
http_status="500" | stats count...
by
vragosta
Path Finder
in
Splunk Search
07-25-2013
|
3
|
6
| |||
Hi,
we're trying to use a little piece of JavaScript (put in application.js) to perform column hiding for SimpleRe...
by
stefano_guidoba
Communicator
in
Splunk Search
07-24-2013
|
1
|
7
| |||
Hello. My query looks like ...| timechart count by type And I have values tupe_a, type_b and so on. When I call them...
by
0range
Communicator
in
Splunk Search
07-25-2013
|
0
|
2
| |||
Hello everyone,
I have a splunk request that creates a table with two fields X and Y and i want to deduplicate lin...
by
ddarmand
Communicator
in
Splunk Search
07-11-2013
|
0
|
3
| |||
If I have a log which is in JSON format and contains array in JSON, can Splunk extract values in this array? For exam...
by
haobin
Explorer
in
Splunk Search
11-24-2010
|
4
|
4
|