Splunk Search

Splunk Search
Community Activity
treinke
I am importing a XML file. There is a few values in the XML that I would like to be alerted on. Well, I would like ...
by treinke Builder in Splunk Search 06-18-2013
0 1
0
1
pjaguilarjr
I've uploaded a few .csv files as lookup tables that have a month-date timestamp column, but I'm not able to get splu...
by pjaguilarjr New Member in Splunk Search 06-18-2013
0 7
0
7
ebailey
I can group the correct events into a transaction using the transaction command but now I need to be able to narrow t...
by ebailey Communicator in Splunk Search 06-17-2013
0 2
0
2
JoeSco27
I have a field called DATE and it is returning values yyyy-mm-dd HH:MM:SS. I am trying to chop off the hours, min, s...
by JoeSco27 Communicator in Splunk Search 06-17-2013
0 3
0
3
pgissiner
I have configured a field lookup on our test server to return a readable name for event codes in our logs. Doing so w...
by pgissiner Engager in Splunk Search 06-17-2013
0 1
0
1
markmcd
I have a search that returns the number of 'views' of a product by day using a 'search xyz |bucket _time span=1d |sta...
by markmcd Path Finder in Splunk Search 06-17-2013
0 5
0
5
dhargaurav
I want to run 2 select statements in one search. something like select * from my_table; select * from your_table; W...
by dhargaurav Engager in Splunk Search 06-17-2013
0 3
0
3
agodoy
I am using eval foo = mvcount(split(field,"")) to count the number of characters in a field at search time. Is there ...
by agodoy Communicator in Splunk Search 06-17-2013
0 4
0
4
jalfrey
In my log data I get lines that look like this: dst=10.0.59.59:80:X1 dst=255.255.255.255:67:X0 dst=10.0.59.59:9060:X1...
by jalfrey Communicator in Splunk Search 06-17-2013
0 12
0
12
responsys_cm
We're finding that when large files are downloaded from the Internet, the application whitelisting client reports a "...
by responsys_cm Builder in Splunk Search 06-17-2013
0 3
0
3
xvxt006
Hi, I want to get the count of errors. So i have a query to get the count by status where status is greater than 400....
by xvxt006 Contributor in Splunk Search 06-17-2013
0 3
0
3
mark112
I am writing to ask a question, which is probably an easy one. I am curious, how would you search for all occurances ...
by mark112 Engager in Splunk Search 06-17-2013
0 2
0
2
xvxt006
Hi, we want to output only certain fields from a transaction in a tabular format. For example, we want only uri, sta...
by xvxt006 Contributor in Splunk Search 06-17-2013
0 5
0
5
Kdeep
When I search my results I want it to update the field accordingly. For example in my case when i search my Audit lo...
by Kdeep New Member in Splunk Search 06-17-2013
0 2
0
2
xxhavok1xx
Hi, every night my server team brings down specific groups of servers and performs maintenance on them. Sometime late...
by xxhavok1xx Explorer in Splunk Search 06-16-2013
0 2
0
2
adomila
Hi, Basically, I'm trying to correlate 2 datasources with 2 fields. For example, I have datasource1 and datasource2 t...
by adomila Explorer in Splunk Search 06-16-2013
0 11
0
11
ssorlie
I'm using Splunk to interrogate web logs. Users of our site can select one or more parameters in their data requests...
by ssorlie New Member in Splunk Search 06-16-2013
0 2
0
2
stokecoll
Guys, apologies if this has already been asked before and there is a KB article for this. We are looking to archive ...
by stokecoll New Member in Splunk Search 06-14-2013
0 1
0
1
tomwahab
Hello, Can Splunk search client machines System log that has Event ID 7? We need to scan and retrieve hostnames that...
by tomwahab New Member in Splunk Search 06-14-2013
0 5
0
5
Jordan_Brough
I'd like to select the earliest events broken down by category. i.e. I would like to see something like this: error...
by Jordan_Brough Path Finder in Splunk Search 06-14-2013
0 3
0
3
allan_newton
I have two sourcetypes src_type_data and src_type_scale. src_type_data contains two fields -----------------------...
by allan_newton Path Finder in Splunk Search 06-14-2013
0 1
0
1
hartfoml
so I can grep the look-up table to find an entry I can see the contents of the look-up table by doing this | inp...
by hartfoml Motivator in Splunk Search 06-14-2013
1 1
1
1
David
How can I specify the default index to use for a specific app? I have an App with a few inputs defined that put all ...
by David Splunk Employee Splunk Employee in Splunk Search 06-14-2013
4 7
4
7
erikross
Hey, was here yesterday, made minor improvements... I have a set of data where each message sent corresponds to an i...
by erikross Explorer in Splunk Search 06-14-2013
0 3
0
3
twistedsixty4
hey all, im working on a network overview dashboard. what i currently have is a saved search showing the last 7 days ...
by twistedsixty4 Path Finder in Splunk Search 06-14-2013
0 3
0
3
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors