Splunk Search

Splunk Search
Community Activity
RobertRi
Hi I would like to get all sourcetypes for a specific app, which have normaly one index. So I tried this search in...
by RobertRi Communicator in Splunk Search 07-30-2013
0 4
0
4
royimad
I have the following search sourcetype = "DevicesInfo" | stats values(DeviceSubType) as series | makemv delim="," se...
by royimad Builder in Splunk Search 07-30-2013
0 1
0
1
preben12
I have an event with a field = message_id. I have to count the number of occurrences of this id based on a input lis...
by preben12 Communicator in Splunk Search 07-29-2013
1 3
1
3
mqueddeng
Hi there, I have a text box input (SearchTextSetting module) where users can enter in a number, which is then used f...
by mqueddeng Engager in Splunk Search 07-29-2013
0 1
0
1
alekz78
Looking for the count of events matching every eventtype combination. For instance: Given 5 events (e1..e5) that mat...
by alekz78 New Member in Splunk Search 07-29-2013
0 1
0
1
phoeniix
We are having a problem where requests are being sent to webservices but never return. I want to get a list of sessi...
by phoeniix Engager in Splunk Search 07-29-2013
0 4
0
4
richnavis
From time to time, I would need to blast the folders in the dispatch folder. Can anyone shed some light on the nami...
by richnavis Contributor in Splunk Search 07-29-2013
0 2
0
2
jmascherino
I have a log4j server log with multiple lines formatted similar to the following: "10.1.1.1" "AUTH-USER" "22/Jul/201...
by jmascherino Engager in Splunk Search 07-29-2013
0 2
0
2
gnovak
I'm trying to use lookups to do a keyword search and I can't grasp my brain around the right way to do this. I've go...
by gnovak Builder in Splunk Search 07-29-2013
0 9
0
9
narabhut
I have fields in the format of LOG_ID, DEVICE_DATA, USERNAME, that I'd like to extract, and I'd like to exclude the d...
by narabhut Explorer in Splunk Search 07-29-2013
0 4
0
4
ortega
The user can search normally but cannot search real-time. It gets the following message: [HTTP 403] Client is not au...
by ortega Engager in Splunk Search 07-29-2013
1 4
1
4
ddarmand
Hello, How can i add a logout button into my navigation bar ? Thanks you, Damien
by ddarmand Communicator in Splunk Search 07-29-2013
0 3
0
3
sbnoobbb
I have a query that has a interval of few mins there are some duplicated results during that hour. When I use dedup i...
by sbnoobbb Path Finder in Splunk Search 07-29-2013
0 4
0
4
HelpMePlease
I have my xml data HERE, I need to extract using Splunk IFX, Generated pattern (regex). Example Xml: (22/7)17:53 Ac...
by HelpMePlease Explorer in Splunk Search 07-28-2013
0 2
0
2
Zyon
Hi, Currently, my Splunk search is: sourcetype="Blacklist" OR sourcetype="log" | eval blacklisted=if(sourcetype=="B...
by Zyon Engager in Splunk Search 07-28-2013
0 4
0
4
atevs
Hi, I am a new user to splunk. Our splunk data consists of lines like: engine id= error1 engine id= error3 engi...
by atevs New Member in Splunk Search 07-28-2013
0 1
0
1
sbnoobbb
I have this search query sourcetype="CurrentWeatherSGMap" Message="Yishun" | eval Description=case(current_summary="R...
by sbnoobbb Path Finder in Splunk Search 07-28-2013
0 3
0
3
ppurokit
Hi All, I have been writing some search queries and now i have written a search query for which im getting a no of e...
by ppurokit Path Finder in Splunk Search 07-28-2013
0 2
0
2
Zyon
Hi, I am using multiple sources in a single search command and i want to rename the _raw field of one of the source ...
by Zyon Engager in Splunk Search 07-27-2013
0 2
0
2
responsys_cm
I'm seeing a number of very large files building up in /opt/splunk/var/spool/splunk: drwx------ 2 root root 4...
by responsys_cm Builder in Splunk Search 07-27-2013
1 4
1
4
schnibitz
Hi everyone, Been trying to get regex syntax to behave. What I have below works. It only shows events that are from...
by schnibitz New Member in Splunk Search 07-27-2013
0 1
0
1
jmsiegma
I would like to take the following lines in my props.conf file, and at Search Time, use these Field Extractions to Se...
by jmsiegma Path Finder in Splunk Search 07-27-2013
0 1
0
1
wudu0517
0
7
ravishankarr
I have setup a field extraction that parses OC4J Apache logs of the following format and extracts the ecid: index="a...
by ravishankarr Explorer in Splunk Search 07-26-2013
0 4
0
4
davidpaper
Greetings, I have a saved & shared search URL that has the SID in it. The search has long expired, and I'd like to ...
by davidpaper Contributor in Splunk Search 07-26-2013
4 1
4
1
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors