| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Hello, I want to count the denials from the same source ip. How can I do this? The Log looks like this: 
  May 28 07:...
        
         
           by 
           
                
                    
                        saschar
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-28-2013
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        My current situation is the following: 
  There are 26 messages that can be sent between three parties. There are 3 p...
        
         
           by 
           
                
                    
                        vanaepi
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-29-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi, 
  We have devices which maintains session information of various users. These devices have a max capacity of ses...
        
         
           by 
           
                
                    
                        strive
                    
                
           
             
             
               Influencer
             
           
           in
           Splunk Search
           
           
              
               05-28-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_...
        
         
           by 
           
                
                    
                        thirumalreddyb
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-28-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello all, 
  I need to create multiple eval fields like this old question: create-multiple-eval-fields-with-wilcards...
        
         
           by 
           
                
                    
                        Fabien05
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-27-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Occassionally we see DNS requests that come in using CamelCase (coMpanY.com or COMpaNy.com, etc.) instead of company....
        
         
           by 
           
                
                    
                        peasead
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-27-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I did a alert to run a script and it runs with fixed variable. But now i want to pass variable (argument  but I don'...
        
         
           by 
           
                
                    
                        Valky
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-27-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, 
  I'm trying to port some SQL queries we wrote to Splunk but whereas with SQL I can specify which columns to joi...
        
         
           by 
           
                
                    
                        brodde
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               05-27-2013
             
           
         
        | 
		
		3
   | 
	  
	  1
	 | |||
| 
        How can I compare an average count of events per minute in last 15 minutes (for example) and the number of events dur...
        
         
           by 
           
                
                    
                        0range
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-27-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hello, all I need to build a correlation table for numeric fields X_1 X_2 ... 
  
  
  
  
  
  
  
  
  
  
  
  
  ...
        
         
           by 
           
                
                    
                        Timeago
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-27-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Does more indexers contribute to the performance of search on search head? I found when i launch a search in the sear...
        
         
           by 
           
                
                    
                        nickcode
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-26-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi everybody, 
  I am new to Splunk. I have a question about Splunk query. 
  Here are some sample logs (timestamp or...
        
         
           by 
           
                
                    
                        fayedong
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               05-24-2013
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I have log lines that I need to group by 4 or 5 fields so that I can find the duration. I am using transaction, but i...
        
         
           by 
           
                
                    
                        lain179
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-24-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Here is my query: source="WinEventLog:Application" OR source="WinEventLog:System" |top limit=10 Type,EventCode, Sourc...
        
         
           by 
           
                
                    
                        MattG
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-24-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I've written an external lookup script that makes a rest call to an API & returns data. The API destination requires ...
        
         
           by 
           
                
                    
                        sf_user_199
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-23-2013
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        Using the Splunk App for *nix on Solair. splunkd has a very high load average. In 15 seconds it did an lstat of 6659 ...
        
         
           by 
           
                
                    
                        fizwit
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-21-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have an automatic lookup in which i need to rename one of the lookup fields.  
  Right now whenever a search runs t...
        
         
           by 
           
                
                    
                        zschmid
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               02-10-2011
             
           
         
        | 
		
		0
   | 
	  
	  12
	 | |||
| 
        How can I automatically create a view based on xml in /views folder? 
  example: put xml file in here. $SPLUNK_HOME/e...
        
         
           by 
           
                
                    
                        mbpenney
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               05-23-2013
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        Hello, 
  Is it possible to include the date in the name of an output file ? example : ... | outputlookup "myname_"+f...
        
         
           by 
           
                
                    
                        Fabien05
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-24-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi All, Is there any possibility to create a unique index number while indexing because i want to search the result o...
        
         
           by 
           
                
                    
                        himanshusinha1
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-24-2013
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I want to create a search that will return all of the logon failure events (based on a set of event IDs, lets say Eve...
        
         
           by 
           
                
                    
                        jchampagne
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-09-2012
             
           
         
        | 
		
		2
   | 
	  
	  3
	 | |||
| 
        Hello all 
  Is there a function to calculate eigenvalue and eigenvector in splunk?
        
         
           by 
           
                
                    
                        Fabien05
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2013
             
           
         
        | 
		
		2
   | 
	  
	  2
	 | |||
| 
        can somebody help on how to import the log file of the below format to splunk ? 
  {"Error":[{"session":abc123,"app_i...
        
         
           by 
           
                
                    
                        msn2507
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-23-2013
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have an oracle log file (i am pasting below one record from the log file) I intend to a table with all possible RET...
        
         
           by 
           
                
                    
                        skpatnaik
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               05-23-2013
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have a few things in my summary in the search app that I'd like to change. 
  Some of my source names are long or o...
        
         
           by 
           
                
                    
                        ackoch
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               05-23-2013
             
           
         
        | 
		
		1
   | 
	  
	  2
	 |