Splunk Search

Splunk Search
Community Activity
iKate
Hi everyone, below are several questions and each of them is very important for us. Hope for your help. As written i...
by iKate Builder in Splunk Search 05-08-2013
5 4
5
4
nickcode
Hi All! I'm using Enterprise Trial version of Splunk which allows indexing 500MB data a day. I have once specified a ...
by nickcode Explorer in Splunk Search 05-07-2013
0 6
0
6
jmsiegma
I have created a search for my VPN users, when they connect, from where they connect (SRC IP) and geoip that IP to lo...
by jmsiegma Path Finder in Splunk Search 05-07-2013
1 1
1
1
kbcuait
Hi, here's my search, which includes a conversion from epoch time to a Y-d-m time format: | dbquery "DBNAME" "SELECT...
by kbcuait Explorer in Splunk Search 05-07-2013
0 1
0
1
revatiy
I am new to splunk . I am trying to search some events in splunk,What I want is get all results which have field "c...
by revatiy New Member in Splunk Search 05-07-2013
0 2
0
2
krugger
Hi, I am trying to add a IP address hint to the Active Directory logs. I know it isn't completely reliable, but it i...
by krugger Communicator in Splunk Search 05-07-2013
0 2
0
2
xvxt006
Hi, is there a way to get the number of events per transaction?
by xvxt006 Contributor in Splunk Search 05-07-2013
0 1
0
1
disha
Hi, In my case, Splunk is getting data in by tcp port. I configure the TCP port with sourcetype="myagent". the json f...
by disha Contributor in Splunk Search 05-07-2013
0 1
0
1
jatin_patel
Hi There, I have below data that i will like to extract as key-value pair from a custom event source i have created....
by jatin_patel Path Finder in Splunk Search 05-07-2013
0 5
0
5
dieusplunk
I have this request : sourcetype="accouting" fichier="*.log" | stats count by fichier Here is the result : fichie...
by dieusplunk Engager in Splunk Search 05-07-2013
1 1
1
1
gajananh999
Dear All, I have data like age count 23 76 24 154 25 168 26 140 27 132 28 156 29 152 30 167 31 144 32 133...
by gajananh999 Contributor in Splunk Search 05-07-2013
0 5
0
5
dewald13
I'm trying to create a regex to match the user agent from the following logs. Beginning with "Mozilla/*" and ending a...
by dewald13 Path Finder in Splunk Search 05-07-2013
0 7
0
7
aputz
Hello, I was curious if there was a way to reference a search duration for use within the search? Primarily for use i...
by aputz Path Finder in Splunk Search 05-07-2013
2 2
2
2
TucoRameriz
Hello All, Having some trouble coming up with a way to extract a file with three random characters and a .jnlp exten...
by TucoRameriz Explorer in Splunk Search 05-07-2013
0 7
0
7
cphair
Hello, I have a macro (a subsearch enclosed in square brackets) that I use to filter my initial search. I would lik...
by cphair Builder in Splunk Search 05-07-2013
0 7
0
7
a212830
Hi, I am processing some logs on a universal forwarder, which then sends the data to some indexers, which are search...
by a212830 Champion in Splunk Search 05-06-2013
0 1
0
1
bmorgan
I need to take already summarized data in the logs, aggregate it from a large group of servers, and build an si-type ...
by bmorgan Explorer in Splunk Search 05-06-2013
0 4
0
4
behymejt2012
Hi Everyone, Trying to extract the File Type from Files (ex: pst, xml, etc). I have tried to split it: eval split =...
by behymejt2012 Path Finder in Splunk Search 05-06-2013
0 3
0
3
SonnyB
In the transforms.conf file, how do I support the alternatives on the REGEX line with the corresponding FORMAT line ...
by SonnyB Explorer in Splunk Search 05-06-2013
3 10
3
10
nlfatin
Hi everyone, I am very new to splunk and im trying to map out some car park relevant data on Google Maps app but to n...
by nlfatin New Member in Splunk Search 05-06-2013
0 1
0
1
richnavis
I've created a the following search that returns results when first run using 5 minute real time from the time picker...
by richnavis Contributor in Splunk Search 05-06-2013
0 1
0
1
shangshin
Hi, Is there a parameter to limit the search universe to a particular search peer when executing the search in the se...
by shangshin Builder in Splunk Search 05-06-2013
0 1
0
1
moulinjs
Hello. I would like to create an alert anytime a privileged user account logs in to our domain. I can do separate s...
by moulinjs New Member in Splunk Search 05-06-2013
0 2
0
2
bcarlson
sourcetype="AAA_CDR" bob.com Total_Bytes > 0 | convert timeformat="%j" ctime(Event_Time) AS day | table User, day, To...
by bcarlson New Member in Splunk Search 05-06-2013
0 4
0
4
baisakhiroy
For security reason , in our project we want that the log files (audit logs,developer's logs etc) should not go outsi...
by baisakhiroy New Member in Splunk Search 05-05-2013
0 5
0
5
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors