Splunk Search

Splunk Search
Community Activity
a212830
Hi, I have a logfile with a timestamp, but no date, being processed by a universal forwarder. How should I handle th...
by a212830 Champion in Splunk Search 05-14-2013
0 1
0
1
rakesh_498115
Hi.. I have a index called "mydata" , sourcetype="my_data" .. my sample event is something likethis 2013-05-12:00...
by rakesh_498115 Motivator in Splunk Search 05-14-2013
0 5
0
5
zachary_hickman
I've been reading into the splunk documentation, but I'm having trouble formatting a search so that I can use it in a...
by zachary_hickman Explorer in Splunk Search 05-14-2013
0 1
0
1
neilamoran
Hi, Not sure if the problem is the way I'm phrasing my query, but I'm having trouble finding anything that seems (to...
by neilamoran Explorer in Splunk Search 05-14-2013
1 2
1
2
sarahh
Hi, i would like to ask if im able to create a search such that i'll be able to show it in my dashboard on how many b...
by sarahh Engager in Splunk Search 05-14-2013
0 1
0
1
jammy3
Hello, We have multiple Citrix VM's that boot from the same master image. We plan to install the universal forwarde...
by jammy3 New Member in Splunk Search 05-13-2013
0 2
0
2
jamesv84
I am adding data from a log file with filename: C:\init97\log\mpinet_init97-20120414-000004.mlg For the timestamp, s...
by jamesv84 Engager in Splunk Search 05-13-2013
1 4
1
4
sanjay_shrestha
Hi, I have following output from a log file. (5/1/13 - 1:36:05.01 PM) Event LOAD 1 Setup (5/1/13 - 1:36:08.01...
by sanjay_shrestha Contributor in Splunk Search 05-13-2013
0 3
0
3
lain179
Hi, I need to set where clause based on certain condition. For example, if value=a, then where should be x>1. If va...
by lain179 Communicator in Splunk Search 05-13-2013
0 6
0
6
rakesh_498115
Hi , i am using the following group name for my dashboard..i wanted to change this name dynamically...i.e wanted to a...
by rakesh_498115 Motivator in Splunk Search 05-13-2013
0 1
0
1
BobM
I want my dashboard to display the contents in multi-lingual environment (Like English, French, Arabic etc..). By de...
by BobM Builder in Splunk Search 05-13-2013
1 2
1
2
tmarlette
is it possible to exclude specific results in a field from the search in the props.conf? I suppose more specifically...
by tmarlette Motivator in Splunk Search 05-13-2013
0 6
0
6
polymorphic
I Cant get this search to work as i wish. This is my search (timespan = -2h@h): sourcetype=stats device_id=13521999...
by polymorphic Communicator in Splunk Search 05-13-2013
0 3
0
3
aswathkhan
I have a table in the oracle database with 120 columns, but when I index the table into splunk using DB Connect only ...
by aswathkhan New Member in Splunk Search 05-13-2013
0 2
0
2
phemmer
Is it possible to strip the date and hostname from the log entry search result that shows up in search? I still want...
by phemmer Path Finder in Splunk Search 05-12-2013
0 4
0
4
lain179
I have a field extracted from log entries, containing time values in GMT. Can I convert the field to PST time? If so,...
by lain179 Communicator in Splunk Search 05-12-2013
1 5
1
5
nmobrien1977
Hi, I have splunk v5.0 running on RHEL and I want to forward all syslog messages %SYS-CONFIG-5 events from splunk to ...
by nmobrien1977 Explorer in Splunk Search 05-11-2013
0 10
0
10
nimakaveh
I have a query like below and I want to compare the result of avg1 with each day result and specify if it is normal o...
by nimakaveh Explorer in Splunk Search 05-10-2013
0 5
0
5
rgarcia3904
I am new to splunk and have been trying to set up my first transforms but I am having some issues. I was hoping to g...
by rgarcia3904 New Member in Splunk Search 05-10-2013
0 6
0
6
amitsehgal
Hi Folks, I need to use conditional stats e.g current: | stats avg(res_time) count(res_time) by transaction requ...
by amitsehgal Path Finder in Splunk Search 05-10-2013
0 5
0
5
rakesh_498115
Hi .. In my Splunk results say i get a lot of numerical values for a field say "A" . Now i want avg of the top 95 va...
by rakesh_498115 Motivator in Splunk Search 05-10-2013
0 8
0
8
Lehanov
Hello Please help me this issue The lookup table 'dm_audit_class_type' does not exist. It is referenced by configu...
by Lehanov Explorer in Splunk Search 05-10-2013
0 2
0
2
balajsoz
Hi I have uploaded a log contains below type of events with time stamp; <[ACTIVE] ExecuteThread: '10' for que...
by balajsoz Path Finder in Splunk Search 05-10-2013
0 1
0
1
clintla
added the table files & definitions w/ just defaults. command is sourcetype="hitachi_poolinfo" host="*0695*" % | r...
by clintla Contributor in Splunk Search 05-09-2013
0 4
0
4
ssudhaiyer
Hi, I'm new to splunk. So, please bear with me if my question is lame and splunk is not meant for such things. I se...
by ssudhaiyer Engager in Splunk Search 05-09-2013
0 2
0
2
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...
Top Solution Authors