Splunk Search

Splunk Search
Community Activity
cpeteman
Two Splunk users have saved basically the same search: searchterms | stats count by punct | table punct,count | appe...
by cpeteman Contributor in Splunk Search 07-30-2013
2 3
2
3
mookiie2005
Our search head becomes unresponsive after a few hours of operation. We then have to physically restart the server. ...
by mookiie2005 Communicator in Splunk Search 07-30-2013
0 6
0
6
AndreyRyabov
Hi. There is a query that retrieves the name of XML element. It doesn't work as intended. The expected result for the...
by AndreyRyabov New Member in Splunk Search 07-30-2013
0 3
0
3
naveenurs
Example 1: uatoken0=Linux uatoken1=U uatoken2=Android uatoken3=en-us Example 2: uatoken0=Linux uatoken1=Android...
by naveenurs Explorer in Splunk Search 07-30-2013
0 9
0
9
CorpusCallosum
Hi guys I am doing an experiment in my local splunk. I imported some http logs including attack patterns. And I am t...
by CorpusCallosum Explorer in Splunk Search 07-30-2013
1 3
1
3
shangshin
Hi, The event in my Log always has a prefix yyyy-MM-dd hh:mm:ss,SSS e.g. 2013-07-30 07:12:11,649 To have...
by shangshin Builder in Splunk Search 07-30-2013
0 3
0
3
xvxt006
Hi, we have a cookie that we pass in the web logs. Sometimes some of the requests are not sending the cookie itself....
by xvxt006 Contributor in Splunk Search 07-30-2013
1 2
1
2
vr46
timechartコマンドで、span=2hを指定するとグラフの開始時刻が必ず23:00から始まります。 これを00:00からグラフ表示することはできるでしょうか? 以下の検索コマンドを実行しています。 earliest=-7d@d...
by vr46 New Member in Splunk Search 07-30-2013
0 4
0
4
appleman
サーチ文の中で、グラフを作成する為に自分でtime rangeを作成する方法はございますでしょうか。 例えば以下のようなサーチの場合で、結果ででてくる時間を1~10分間、11~20分間、21~30分間のようにグループ分けして、 チャー...
by appleman Contributor in Splunk Search 07-30-2013
0 3
0
3
RobertRi
Hi I would like to get all sourcetypes for a specific app, which have normaly one index. So I tried this search in...
by RobertRi Communicator in Splunk Search 07-30-2013
0 4
0
4
royimad
I have the following search sourcetype = "DevicesInfo" | stats values(DeviceSubType) as series | makemv delim="," se...
by royimad Builder in Splunk Search 07-30-2013
0 1
0
1
preben12
I have an event with a field = message_id. I have to count the number of occurrences of this id based on a input lis...
by preben12 Communicator in Splunk Search 07-29-2013
1 3
1
3
mqueddeng
Hi there, I have a text box input (SearchTextSetting module) where users can enter in a number, which is then used f...
by mqueddeng Engager in Splunk Search 07-29-2013
0 1
0
1
alekz78
Looking for the count of events matching every eventtype combination. For instance: Given 5 events (e1..e5) that mat...
by alekz78 New Member in Splunk Search 07-29-2013
0 1
0
1
phoeniix
We are having a problem where requests are being sent to webservices but never return. I want to get a list of sessi...
by phoeniix Engager in Splunk Search 07-29-2013
0 4
0
4
richnavis
From time to time, I would need to blast the folders in the dispatch folder. Can anyone shed some light on the nami...
by richnavis Contributor in Splunk Search 07-29-2013
0 2
0
2
jmascherino
I have a log4j server log with multiple lines formatted similar to the following: "10.1.1.1" "AUTH-USER" "22/Jul/201...
by jmascherino Engager in Splunk Search 07-29-2013
0 2
0
2
gnovak
I'm trying to use lookups to do a keyword search and I can't grasp my brain around the right way to do this. I've go...
by gnovak Builder in Splunk Search 07-29-2013
0 9
0
9
narabhut
I have fields in the format of LOG_ID, DEVICE_DATA, USERNAME, that I'd like to extract, and I'd like to exclude the d...
by narabhut Explorer in Splunk Search 07-29-2013
0 4
0
4
ortega
The user can search normally but cannot search real-time. It gets the following message: [HTTP 403] Client is not au...
by ortega Engager in Splunk Search 07-29-2013
1 4
1
4
ddarmand
Hello, How can i add a logout button into my navigation bar ? Thanks you, Damien
by ddarmand Communicator in Splunk Search 07-29-2013
0 3
0
3
sbnoobbb
I have a query that has a interval of few mins there are some duplicated results during that hour. When I use dedup i...
by sbnoobbb Path Finder in Splunk Search 07-29-2013
0 4
0
4
HelpMePlease
I have my xml data HERE, I need to extract using Splunk IFX, Generated pattern (regex). Example Xml: (22/7)17:53 Ac...
by HelpMePlease Explorer in Splunk Search 07-28-2013
0 2
0
2
Zyon
Hi, Currently, my Splunk search is: sourcetype="Blacklist" OR sourcetype="log" | eval blacklisted=if(sourcetype=="B...
by Zyon Engager in Splunk Search 07-28-2013
0 4
0
4
atevs
Hi, I am a new user to splunk. Our splunk data consists of lines like: engine id= error1 engine id= error3 engi...
by atevs New Member in Splunk Search 07-28-2013
0 1
0
1
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors