Splunk Search

Splunk Search
Community Activity
sushil909
Hi, I have a file containing events in the format given below Time system parameter value 12jun2013:14:00:00 system1...
by sushil909 Explorer in Splunk Search 07-23-2013
1 10
1
10
laurendonaghy
I am hoping to anonymize a set of data that is sorted into different folders. I found this command, and I was hoping...
by laurendonaghy New Member in Splunk Search 07-22-2013
0 1
0
1
narabhut
I need to convert _time (in this format: 12/1/12 12:00:00.000 AM) to milliseconds since 1970 (unix time). I'm using c...
by narabhut Explorer in Splunk Search 07-22-2013
0 1
0
1
meatago
Spluk is indexing records from DNS Debug logs just fine, but I'd like to extract and transform the domain names in th...
by meatago Explorer in Splunk Search 07-22-2013
2 5
2
5
glsplunk
I've been trying variations of this: /opt/splunk/bin/splunk search "10.3.16.31" -latest_time '-4h@h' but it doesn't l...
by glsplunk New Member in Splunk Search 07-22-2013
0 2
0
2
dang
I'm attempting to figure out the average reboot times of a server with the following search: index=main host=MYSERVE...
by dang Path Finder in Splunk Search 07-22-2013
1 2
1
2
kmattern
I have two lookup tables.The first is a list of all New York Customers and looks like the first listing below. The s...
by kmattern Builder in Splunk Search 07-22-2013
0 3
0
3
jameshgibson
We have a system that produces several GB of logs per day. Of that there is only maybe a few MB that contains informa...
by jameshgibson Path Finder in Splunk Search 07-22-2013
0 2
0
2
gelica
Hi, I have events of the form ---- name ---- Drive: C: Free Space: 894.1 GB Total Space: 953.1 GB Drive: D: Free S...
by gelica Communicator in Splunk Search 07-21-2013
0 4
0
4
labani
I want to work with splunk in linux environment. I am using splunk version 5.0.3 and i have installed splunk app for ...
by labani Explorer in Splunk Search 07-21-2013
0 3
0
3
mikelanghorst
I've been thinking alot lately about the possibility of changing the Linux scheduler for the filesystems on my hot & ...
by mikelanghorst Motivator in Splunk Search 07-21-2013
1 2
1
2
HelpMePlease
I had a x-axis displayed over date_hour. 00,01,02... Is is possible to change it to display on a 3hour basis (00,03,0...
by HelpMePlease Explorer in Splunk Search 07-21-2013
1 5
1
5
szaboszilard
Hi! I need some help, to build an app. How can I generate an event from search (or dashboard) and put it in specifi...
by szaboszilard Path Finder in Splunk Search 07-21-2013
0 1
0
1
cheukkay
I have a firewall log and I would like to get the top 10 ports of a unique field named SPT(source port). After retrie...
by cheukkay Engager in Splunk Search 07-21-2013
0 2
0
2
sbnoobbb
Hi, Please take a look at my table below which i came up with using this search command sourcetype="json_onemap" |...
by sbnoobbb Path Finder in Splunk Search 07-20-2013
1 3
1
3
eulalie
So I have a bunch of data and somoene has decided they'd like to know the average turn around time for events. I can...
by eulalie New Member in Splunk Search 07-20-2013
0 1
0
1
trkalva
Hi. i have field input_source_file and I need to make it a comma separated field so that I can group by that and sou...
by trkalva Engager in Splunk Search 07-20-2013
0 1
0
1
Ravan
Hi , Can we replace space in multi-value filed with comma ..? Ex : field : host current Values : server1 server2 s...
by Ravan Path Finder in Splunk Search 07-20-2013
0 2
0
2
jambajuice
I've created a lookup table that has three fields, nessus_id,osvdb_id,cve_id. The osvdb_id and cve_id fields are mul...
by jambajuice Communicator in Splunk Search 07-20-2013
2 1
2
1
jalfrey
I am looking at firewall logs. The destination port appears twice in some log lines. I want a search that will show m...
by jalfrey Communicator in Splunk Search 07-19-2013
0 3
0
3
aholzer
What is the best method for managing a list of fields that will be used to populate (at least, but not limited to) a ...
by aholzer Motivator in Splunk Search 07-19-2013
0 6
0
6
bansi
From the url http://blogs.splunk.com/2009/09/14/enriching-data-with-db-lookups-part-2/ i read the following excerpt...
by bansi Path Finder in Splunk Search 07-18-2013
0 1
0
1
gpanicker
I have a dashboard with pulldown menu and I want to call different saved searches depending upon the selection. Is th...
by gpanicker Explorer in Splunk Search 07-18-2013
1 8
1
8
spiketide
While creating a saved search or a custom dashboard through one of the apps, is there a way to make sure that the nam...
by spiketide Engager in Splunk Search 07-18-2013
0 1
0
1
rshoward
Though "| eval myfield=entropy(somefield)" would be awesome, it doesn't exist (yet?). Is there a known method for thi...
by rshoward Path Finder in Splunk Search 07-18-2013
4 7
4
7
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...