Splunk Search

Splunk Search
Community Activity
HelpMePlease
I have my xml data HERE, I need to extract using Splunk IFX, Generated pattern (regex). Example Xml: (22/7)17:53 Ac...
by HelpMePlease Explorer in Splunk Search 07-28-2013
0 2
0
2
Zyon
Hi, Currently, my Splunk search is: sourcetype="Blacklist" OR sourcetype="log" | eval blacklisted=if(sourcetype=="B...
by Zyon Engager in Splunk Search 07-28-2013
0 4
0
4
atevs
Hi, I am a new user to splunk. Our splunk data consists of lines like: engine id= error1 engine id= error3 engi...
by atevs New Member in Splunk Search 07-28-2013
0 1
0
1
sbnoobbb
I have this search query sourcetype="CurrentWeatherSGMap" Message="Yishun" | eval Description=case(current_summary="R...
by sbnoobbb Path Finder in Splunk Search 07-28-2013
0 3
0
3
ppurokit
Hi All, I have been writing some search queries and now i have written a search query for which im getting a no of e...
by ppurokit Path Finder in Splunk Search 07-28-2013
0 2
0
2
Zyon
Hi, I am using multiple sources in a single search command and i want to rename the _raw field of one of the source ...
by Zyon Engager in Splunk Search 07-27-2013
0 2
0
2
responsys_cm
I'm seeing a number of very large files building up in /opt/splunk/var/spool/splunk: drwx------ 2 root root 4...
by responsys_cm Builder in Splunk Search 07-27-2013
1 4
1
4
schnibitz
Hi everyone, Been trying to get regex syntax to behave. What I have below works. It only shows events that are from...
by schnibitz New Member in Splunk Search 07-27-2013
0 1
0
1
jmsiegma
I would like to take the following lines in my props.conf file, and at Search Time, use these Field Extractions to Se...
by jmsiegma Path Finder in Splunk Search 07-27-2013
0 1
0
1
wudu0517
0
7
ravishankarr
I have setup a field extraction that parses OC4J Apache logs of the following format and extracts the ecid: index="a...
by ravishankarr Explorer in Splunk Search 07-26-2013
0 4
0
4
davidpaper
Greetings, I have a saved & shared search URL that has the SID in it. The search has long expired, and I'd like to ...
by davidpaper Contributor in Splunk Search 07-26-2013
4 1
4
1
cpeteman
I feel like this should be a piece of cake with distinct count. I'd like to turn this into a more elegant search: s...
by cpeteman Contributor in Splunk Search 07-26-2013
0 4
0
4
jchilovich
I've read many a post and either I'm just not getting it or it's just not the answer. I want to index the daily catal...
by jchilovich New Member in Splunk Search 07-26-2013
0 5
0
5
rlautman
In in my host field I have several different addresses, 4 of these addresses are from Location1 and the rest are from...
by rlautman Path Finder in Splunk Search 07-26-2013
0 3
0
3
tb5821
In our splunk instance I believe the props.config file is set to UTC as that is what most of our logs are in but we d...
by tb5821 Communicator in Splunk Search 07-26-2013
0 2
0
2
timmoammo
Hello, I'm trying to report a number of different stats however only one of the stats needs to be by month. All of t...
by timmoammo New Member in Splunk Search 07-26-2013
0 3
0
3
emaccaferri
Hi! I would like to know the frequency of each value of a certain field inside a transaction, for example: my event a...
by emaccaferri Communicator in Splunk Search 07-26-2013
0 8
0
8
lpolo
The following query construct populates a summary index: source=1.log OR source=2.log | eval _time = case(source ==...
by lpolo Motivator in Splunk Search 07-25-2013
1 3
1
3
dan60201
I have done testing the calculated fields for Splunk DB Connect in my local machine. Basically I added props.conf fil...
by dan60201 Explorer in Splunk Search 07-25-2013
0 7
0
7
Paul_tcs
Hi All, Am trying to find the usage of correlation. When i try my search using coorelation, it gives me an output, b...
by Paul_tcs Explorer in Splunk Search 07-25-2013
0 1
0
1
sowings
I've got a long-running search that's spending more time than necessary in command.search.typer. I say more time than...
by sowings Splunk Employee Splunk Employee in Splunk Search 07-25-2013
1 4
1
4
vragosta
I'm sure this is easy to do, but I'm a bit stumped. Say I have a search like this: http_status="500" | stats count ...
by vragosta Path Finder in Splunk Search 07-25-2013
3 6
3
6
stefano_guidoba
Hi, we're trying to use a little piece of JavaScript (put in application.js) to perform column hiding for SimpleResu...
by stefano_guidoba Communicator in Splunk Search 07-25-2013
1 7
1
7
0range
Hello. My query looks like ...| timechart count by type And I have values tupe_a, type_b and so on. When I call them...
by 0range Communicator in Splunk Search 07-25-2013
0 2
0
2
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors