Splunk Search

Splunk Search
Community Activity
tmarlette
This should be easy, I honestly just don't remember how I did this in the past. In the "Searches & Reports" menu, the...
by tmarlette Motivator in Splunk Search 06-18-2013
0 2
0
2
bkeeley
Hi, I am trying to search the windows security log for any logs where account_name field contains fire (case insensi...
by bkeeley Engager in Splunk Search 06-18-2013
0 5
0
5
ghs_bcarroll
I currently logged the following data Description=Windows Support Tools InstallDate=20120126 InstallDate2=NULL Name...
by ghs_bcarroll New Member in Splunk Search 06-18-2013
0 7
0
7
mzorzi
My XML file looks like ( I have added spaces for formatting ) < contentOwner> < gln>113456789< /gln> < contentO...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 06-18-2013
0 1
0
1
treinke
I am importing a XML file. There is a few values in the XML that I would like to be alerted on. Well, I would like ...
by treinke Builder in Splunk Search 06-18-2013
0 1
0
1
pjaguilarjr
I've uploaded a few .csv files as lookup tables that have a month-date timestamp column, but I'm not able to get splu...
by pjaguilarjr New Member in Splunk Search 06-18-2013
0 7
0
7
ebailey
I can group the correct events into a transaction using the transaction command but now I need to be able to narrow t...
by ebailey Communicator in Splunk Search 06-17-2013
0 2
0
2
JoeSco27
I have a field called DATE and it is returning values yyyy-mm-dd HH:MM:SS. I am trying to chop off the hours, min, s...
by JoeSco27 Communicator in Splunk Search 06-17-2013
0 3
0
3
pgissiner
I have configured a field lookup on our test server to return a readable name for event codes in our logs. Doing so w...
by pgissiner Engager in Splunk Search 06-17-2013
0 1
0
1
markmcd
I have a search that returns the number of 'views' of a product by day using a 'search xyz |bucket _time span=1d |sta...
by markmcd Path Finder in Splunk Search 06-17-2013
0 5
0
5
dhargaurav
I want to run 2 select statements in one search. something like select * from my_table; select * from your_table; W...
by dhargaurav Engager in Splunk Search 06-17-2013
0 3
0
3
agodoy
I am using eval foo = mvcount(split(field,"")) to count the number of characters in a field at search time. Is there ...
by agodoy Communicator in Splunk Search 06-17-2013
0 4
0
4
jalfrey
In my log data I get lines that look like this: dst=10.0.59.59:80:X1 dst=255.255.255.255:67:X0 dst=10.0.59.59:9060:X1...
by jalfrey Communicator in Splunk Search 06-17-2013
0 12
0
12
responsys_cm
We're finding that when large files are downloaded from the Internet, the application whitelisting client reports a "...
by responsys_cm Builder in Splunk Search 06-17-2013
0 3
0
3
xvxt006
Hi, I want to get the count of errors. So i have a query to get the count by status where status is greater than 400....
by xvxt006 Contributor in Splunk Search 06-17-2013
0 3
0
3
mark112
I am writing to ask a question, which is probably an easy one. I am curious, how would you search for all occurances ...
by mark112 Engager in Splunk Search 06-17-2013
0 2
0
2
xvxt006
Hi, we want to output only certain fields from a transaction in a tabular format. For example, we want only uri, sta...
by xvxt006 Contributor in Splunk Search 06-17-2013
0 5
0
5
Kdeep
When I search my results I want it to update the field accordingly. For example in my case when i search my Audit lo...
by Kdeep New Member in Splunk Search 06-17-2013
0 2
0
2
xxhavok1xx
Hi, every night my server team brings down specific groups of servers and performs maintenance on them. Sometime late...
by xxhavok1xx Explorer in Splunk Search 06-16-2013
0 2
0
2
adomila
Hi, Basically, I'm trying to correlate 2 datasources with 2 fields. For example, I have datasource1 and datasource2 t...
by adomila Explorer in Splunk Search 06-16-2013
0 11
0
11
ssorlie
I'm using Splunk to interrogate web logs. Users of our site can select one or more parameters in their data requests...
by ssorlie New Member in Splunk Search 06-16-2013
0 2
0
2
stokecoll
Guys, apologies if this has already been asked before and there is a KB article for this. We are looking to archive ...
by stokecoll New Member in Splunk Search 06-14-2013
0 1
0
1
tomwahab
Hello, Can Splunk search client machines System log that has Event ID 7? We need to scan and retrieve hostnames that...
by tomwahab New Member in Splunk Search 06-14-2013
0 5
0
5
Jordan_Brough
I'd like to select the earliest events broken down by category. i.e. I would like to see something like this: error...
by Jordan_Brough Path Finder in Splunk Search 06-14-2013
0 3
0
3
allan_newton
I have two sourcetypes src_type_data and src_type_scale. src_type_data contains two fields -----------------------...
by allan_newton Path Finder in Splunk Search 06-14-2013
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...