Splunk Search

Splunk Search
Community Activity
Jason
I'm looking at a client system right now that has the following: the event has a timestamp of 18:00:00the Splunk ext...
by Jason Motivator in Splunk Search 07-14-2013
0 1
0
1
marcokrueger
I have some events that are urgent for my transaction but after that I dont need them anymore. Can I remove them fro...
by marcokrueger Path Finder in Splunk Search 07-13-2013
0 1
0
1
andrew_rush
We've just added a new index and under the manager menus it shows that there are events and data in the index. When w...
by andrew_rush New Member in Splunk Search 07-12-2013
0 2
0
2
ivantn21
Is there a way to detect if a host clicked on a link from and email that hey received? Assume sourcetypes for web and...
by ivantn21 Explorer in Splunk Search 07-12-2013
0 1
0
1
kmattern
On a daily basis a series of publications are distributed to a number of different accounts. The list of publications...
by kmattern Builder in Splunk Search 07-12-2013
2 4
2
4
smileyge
When I do a search on events and lookup to a file, I get all the outputs on the left as fields and I can filter and s...
by smileyge Path Finder in Splunk Search 07-12-2013
0 1
0
1
Regengott
I have a bunch of log files from a honeypot. In this logfiles, I have IP-Adresses which appear almost every day and s...
by Regengott New Member in Splunk Search 07-12-2013
0 5
0
5
darpohsh
I would like to be able to extract some details from the logs, namely "AR1" and "SIN" as 2 fields and a 3rd field wit...
by darpohsh New Member in Splunk Search 07-12-2013
0 3
0
3
cdupuis123
So I'm attempting to drop events from the windows security logs at the indexer so I've created a props.conf that is t...
by cdupuis123 Path Finder in Splunk Search 07-12-2013
0 8
0
8
marcokrueger
Hi, I have a problem to understand mvzip. For example the query sourcetype="at-json-traces" "aGAfJ22UVSK_" | spath |...
by marcokrueger Path Finder in Splunk Search 07-12-2013
0 2
0
2
allen_edmondson
I have outputted events in csv format, and have a field which has carriage returns in it. How can use regex to remove...
by allen_edmondson Explorer in Splunk Search 07-11-2013
1 3
1
3
strive
Hi, We have a CSV file containing names and ids. Same name can be present for multiple ids. Name Id A 1 B ...
by strive Influencer in Splunk Search 07-11-2013
0 1
0
1
ma_anand1984
Hi Splunk base users, Do you think it will be a good idea if splunk provides a UNIQUE id to find an event like a pri...
by ma_anand1984 Contributor in Splunk Search 07-11-2013
1 6
1
6
JoeSco27
Is there a way to search over a set of data from lets say a month ago and then lay it on top of the same set of data ...
by JoeSco27 Communicator in Splunk Search 07-11-2013
0 3
0
3
mhenrick
Hi Guys, Right now I'm trying to set up a Splunk query to look for a series of Unix commands within either a multi-v...
by mhenrick New Member in Splunk Search 07-11-2013
0 5
0
5
cpeteman
Hey all, So the following seems to be a problem correctly piping stats stuff. Right now mean and sum will always be ...
by cpeteman Contributor in Splunk Search 07-11-2013
0 5
0
5
bcarlson
Good Morning! I am trying to build calculated fields that will create a wireless roamer cost report. The report is ...
by bcarlson New Member in Splunk Search 07-11-2013
0 2
0
2
CCoomber
Hi, after a search I have a table like this: row VAL count 1 0 169 2 1 3 3 4 4 4 9 1 5 10 12 ...
by CCoomber Engager in Splunk Search 07-11-2013
0 3
0
3
erstexas
Hello, I am working with Nessus data and I am trying to pull a software list from the results. Nessus exports this ...
by erstexas Path Finder in Splunk Search 07-11-2013
0 8
0
8
RVDowning
stats count as #PlanOpen, count(eval(NumRows < 50)) as SmallPlans , count(eval(NumRows>=50 AND NumRows <200)) as Me...
by RVDowning Contributor in Splunk Search 07-11-2013
0 3
0
3
shri_27
Hi All, I want count of word "ERROR" in the group of events for which i have used transaction command! my search que...
by shri_27 Path Finder in Splunk Search 07-11-2013
1 8
1
8
hylee
I use the code below, and it works.. sourcetype="splunk_page_request" | transaction session_id maxspan=3s and I wan...
by hylee Explorer in Splunk Search 07-10-2013
0 2
0
2
hylee
When I put below sourcetype="splunk_page_search" | top limit=10 keyword the result.. 1 AAA 2 aaa 3 BBB 4 ...
by hylee Explorer in Splunk Search 07-10-2013
0 2
0
2
hylee
When I put "sourcetype="splunk_member_info2" | timechart count" on SEARCH, the result shows monthly result. (Log is ...
by hylee Explorer in Splunk Search 07-10-2013
0 4
0
4
shalabyak
I got this message after running a few searches: "The maximum number of historical concurrent system-wide searches ha...
by shalabyak New Member in Splunk Search 07-10-2013
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...