Splunk Search

Splunk Search
Community Activity
hartfoml
Arg this is so frustrating. I cant find the nix_action_lookup and I can't find the IDS config. How do i troubleshoo...
by hartfoml Motivator in Splunk Search 08-06-2013
0 4
0
4
Karunamon
I am running a query via a created dashboard on one of my production databases. I defined this in the DB Connect app,...
by Karunamon Explorer in Splunk Search 08-06-2013
0 4
0
4
usd0872
Can anybody enlighten me on why the form below (shortened) works when it's designed exactly this way, but not in any ...
by usd0872 Path Finder in Splunk Search 08-06-2013
1 2
1
2
mhamill
We're trying to compare searches from our Security source, trying to see if someone hasn't logged in within the last ...
by mhamill Engager in Splunk Search 08-06-2013
0 2
0
2
Olli1919
Hi, when trying to filter a high EPS feed with a lookup I am experiencing quite some performance issues. Are are kno...
by Olli1919 Path Finder in Splunk Search 08-06-2013
0 5
0
5
aaronkorn
Hello, We have the following table with this search but would like to drill down to a table with just the ticket det...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 08-06-2013
0 2
0
2
ephemeric
Greetz, Is it possible to search a range of bucket ids? I have moved a lot of warm/cold buckets and scrubbed the id...
by ephemeric Contributor in Splunk Search 08-06-2013
0 2
0
2
samhughe
One of our users has a lookup requirement that I'm struggling to find a workable solution. They want to have a numbe...
by samhughe Path Finder in Splunk Search 08-06-2013
0 4
0
4
hartfoml
I would like to create a timechart with an SLA value. I have tried this search sourcetype=foo | eval sla=50 | timech...
by hartfoml Motivator in Splunk Search 08-06-2013
0 4
0
4
Simon
Hi All I've got a very bad csv to index, which is basically a csv with 63 columns and tildes as separators, because ...
by Simon Contributor in Splunk Search 08-05-2013
0 2
0
2
ChhayaV
hi, I have a log files which are having columns that are not fixed. if first log entry has col1,col2,col3 then next ...
by ChhayaV Communicator in Splunk Search 08-05-2013
0 2
0
2
Mag2sub
How would CPU core load or CPU core sizing be split between a search head and its peer indexer when "searches with re...
by Mag2sub Path Finder in Splunk Search 08-05-2013
0 2
0
2
aaronkorn
Hello, We have the following search in a chart but the dates are sorting alphabetically rather than numerically. ie ...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 08-05-2013
0 2
0
2
bruceclarke
All, I'm wondering if there is a way to change my configuration files to ignore the capitalization of a field. For ...
by bruceclarke Contributor in Splunk Search 08-05-2013
0 3
0
3
greg
What I want is: ... | stats avg(eval(MyValue!=0)) as Avg It doesn't work that way (Avg is always 1.0). Of course...
by greg Communicator in Splunk Search 08-05-2013
0 9
0
9
aaronkorn
Hello, We have the following chart which displays current ticket counts over the last 7 days for different groups bu...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 08-05-2013
2 10
2
10
adityapavan18
Hi I know that splunk automatically creates default fields like host,sourcetype,index at index time.And also the sp...
by adityapavan18 Contributor in Splunk Search 08-05-2013
0 2
0
2
ChhayaV
hi, I want to do a lookup to a CSV file which is having multi line field value when i upload a file for lookup its g...
by ChhayaV Communicator in Splunk Search 08-05-2013
0 4
0
4
cwacha
Hi, I have built an app that aggregates data into a summary index. The app also provides a query that searches for t...
by cwacha Path Finder in Splunk Search 08-05-2013
0 1
0
1
splunkuser2013
I would like to use function case and regex together and extract the value of capturing group in one field e.g. http_...
by splunkuser2013 New Member in Splunk Search 08-05-2013
0 3
0
3
ChhayaV
hi, Is there any performance impact if i use inline search instead of saved one? Thanks and Regards
by ChhayaV Communicator in Splunk Search 08-05-2013
0 1
0
1
pembleton
Hey, quite a long post, but I'm going crazy here trying to solve this problem: I have a connection log of: id, userna...
by pembleton Path Finder in Splunk Search 08-05-2013
1 2
1
2
jsash1
Hi, I have a requirement for an event detection engine which is able to identify a string (e.g. username) in a parti...
by jsash1 New Member in Splunk Search 08-04-2013
0 3
0
3
craigcook
I've just started using summary indexes - I have two searches that work as expected on querying data in just the prev...
by craigcook New Member in Splunk Search 08-04-2013
0 1
0
1
kailun92
Hi all, I need to join two table up and do a count of rain. Below is my search query is there anything wrong ? I can'...
by kailun92 Communicator in Splunk Search 08-03-2013
0 6
0
6
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...