Splunk Search

Splunk Search
Community Activity
strive
Hi, We have devices which maintains session information of various users. These devices have a max capacity of sessi...
by strive Influencer in Splunk Search 05-28-2013
0 3
0
3
thirumalreddyb
There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_...
by thirumalreddyb Communicator in Splunk Search 05-28-2013
0 2
0
2
Fabien05
Hello all, I need to create multiple eval fields like this old question: create-multiple-eval-fields-with-wilcards ...
by Fabien05 Explorer in Splunk Search 05-28-2013
0 2
0
2
peasead
Occassionally we see DNS requests that come in using CamelCase (coMpanY.com or COMpaNy.com, etc.) instead of company....
by peasead Path Finder in Splunk Search 05-27-2013
0 1
0
1
Valky
I did a alert to run a script and it runs with fixed variable. But now i want to pass variable (argument  but I don'...
by Valky Explorer in Splunk Search 05-27-2013
0 1
0
1
brodde
Hi, I'm trying to port some SQL queries we wrote to Splunk but whereas with SQL I can specify which columns to join ...
by brodde Engager in Splunk Search 05-27-2013
3 1
3
1
0range
How can I compare an average count of events per minute in last 15 minutes (for example) and the number of events dur...
by 0range Communicator in Splunk Search 05-27-2013
0 1
0
1
Timeago
Hello, all I need to build a correlation table for numeric fields X_1 X_2 ... ...
by Timeago Explorer in Splunk Search 05-27-2013
0 2
0
2
nickcode
Does more indexers contribute to the performance of search on search head? I found when i launch a search in the sea...
by nickcode Explorer in Splunk Search 05-26-2013
0 1
0
1
fayedong
Hi everybody, I am new to Splunk. I have a question about Splunk query. Here are some sample logs (timestamp order...
by fayedong Engager in Splunk Search 05-25-2013
0 5
0
5
lain179
I have log lines that I need to group by 4 or 5 fields so that I can find the duration. I am using transaction, but i...
by lain179 Communicator in Splunk Search 05-25-2013
0 3
0
3
MattG
Here is my query: source="WinEventLog:Application" OR source="WinEventLog:System" |top limit=10 Type,EventCode, Sourc...
by MattG New Member in Splunk Search 05-24-2013
0 1
0
1
sf_user_199
I've written an external lookup script that makes a rest call to an API & returns data. The API destination requires...
by sf_user_199 Path Finder in Splunk Search 05-24-2013
1 1
1
1
fizwit
Using the Splunk App for *nix on Solair. splunkd has a very high load average. In 15 seconds it did an lstat of 6659...
by fizwit Explorer in Splunk Search 05-24-2013
0 1
0
1
zschmid
I have an automatic lookup in which i need to rename one of the lookup fields. Right now whenever a search runs tha...
by zschmid Path Finder in Splunk Search 05-24-2013
0 12
0
12
mbpenney
How can I automatically create a view based on xml in /views folder? example: put xml file in here. $SPLUNK_HOME/etc...
by mbpenney Engager in Splunk Search 05-24-2013
0 7
0
7
Fabien05
Hello, Is it possible to include the date in the name of an output file ? example : ... | outputlookup "myname_"+fun...
by Fabien05 Explorer in Splunk Search 05-24-2013
0 3
0
3
himanshusinha1
Hi All, Is there any possibility to create a unique index number while indexing because i want to search the result o...
by himanshusinha1 Explorer in Splunk Search 05-24-2013
0 3
0
3
jchampagne
I want to create a search that will return all of the logon failure events (based on a set of event IDs, lets say Eve...
by jchampagne Path Finder in Splunk Search 05-24-2013
2 3
2
3
Fabien05
Hello all Is there a function to calculate eigenvalue and eigenvector in splunk?
by Fabien05 Explorer in Splunk Search 05-24-2013
2 2
2
2
msn2507
can somebody help on how to import the log file of the below format to splunk ? {"Error":[{"session":abc123,"app_id"...
by msn2507 Path Finder in Splunk Search 05-24-2013
0 1
0
1
skpatnaik
I have an oracle log file (i am pasting below one record from the log file) I intend to a table with all possible RET...
by skpatnaik New Member in Splunk Search 05-23-2013
0 2
0
2
ackoch
I have a few things in my summary in the search app that I'd like to change. Some of my source names are long or obs...
by ackoch Explorer in Splunk Search 05-23-2013
1 2
1
2
responsys_cm
I'm trying to use the geoip external lookup script, the one that uses the MAXMIND database. When I run my search, I ...
by responsys_cm Builder in Splunk Search 05-23-2013
2 3
2
3
tb5821
I'm trying to use this niffty regex generator using the perl option. http://txt2re.com/index-java.php3?s=%3CTAG\b[^%3...
by tb5821 Communicator in Splunk Search 05-23-2013
0 3
0
3
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...
Top Solution Authors