Splunk Search

Splunk Search
Community Activity
kphillipson
Hello, Been trying to figure this one out and I believe I have made it more complicated than it needs to be. I have t...
by kphillipson Path Finder in Splunk Search 04-18-2013
0 9
0
9
phemmer
I am trying to extract some fields from some reporting data. The reporting data has a field name, and then a bunch of...
by phemmer Path Finder in Splunk Search 04-18-2013
2 2
2
2
perseger
Hi, We have some 3rd party library that writes one stack trace to STDERR which ends up as multiple rows in the log f...
by perseger Explorer in Splunk Search 04-18-2013
0 2
0
2
shri_27
Hi, How to join results of 2 different searchs?? using OR??
by shri_27 Path Finder in Splunk Search 04-18-2013
0 1
0
1
zliu
In $SPLUNK_HOME/etc/apps/search/metadata/meta.local [] access = read : [ admin, can_delete, developer, power, user ]...
by zliu Splunk Employee Splunk Employee in Splunk Search 04-18-2013
2 2
2
2
lqiao
Hi, I have a search as follows: query 1 [search query 2] I find in the internet that Searches that contain subsearc...
by lqiao Explorer in Splunk Search 04-18-2013
0 1
0
1
pradeep0802
Hi Guys, I have here 2 savedsearches, now i want to do a left outer join between both of them. I'm using the followi...
by pradeep0802 New Member in Splunk Search 04-17-2013
0 4
0
4
carmenho92
I followed the example in http://docs.splunk.com/Documentation/Splunk/5.0.2/AdvancedDev/SearchScripts. When I want to...
by carmenho92 New Member in Splunk Search 04-17-2013
0 3
0
3
jona_sc
splunk dbx query error with non-admin Admin user can view the database info and query database. but non-admin user w...
by jona_sc New Member in Splunk Search 04-17-2013
0 1
0
1
rubinod
Hi, I would like to assign fields to a delimited text file which does not contain a header. Lets say an event or ro...
by rubinod Engager in Splunk Search 04-17-2013
1 1
1
1
tmarlette
I have one search, for one event type, and a second search for a second event type. one is 'user login' and the other...
by tmarlette Motivator in Splunk Search 04-17-2013
0 3
0
3
smolcj
Hi, My need is to compare two log files of same pattern . sometimes the log files will be entirely different because ...
by smolcj Builder in Splunk Search 04-17-2013
0 7
0
7
tiny3001
I've got a specific search, that generates two time ranges on a timechart, using the instructions found on this Splun...
by tiny3001 Path Finder in Splunk Search 04-17-2013
1 4
1
4
davidts
I have some Windows perfmon events being indexed every 60s. When I perform a 15min historical search I see all the ev...
by davidts Path Finder in Splunk Search 04-16-2013
1 3
1
3
Lucas_K
Is it possible to control how the web interface sorts table column data? It seems to just sort in ascii or lexical o...
by Lucas_K Motivator in Splunk Search 04-16-2013
0 2
0
2
hartfoml
I want to search for an IDS event like this sourcetype=IDS "MALWARE-CNC" Then I want to use the src_IP and dst_IP ...
by hartfoml Motivator in Splunk Search 04-16-2013
0 10
0
10
ccsfdave
Is there something like a diff command on roles? I am trying to grant as limited as possible access to a custom role...
by ccsfdave Builder in Splunk Search 04-16-2013
0 1
0
1
msarro
Hey everyone. We are trying to figure out call distributions for our network by time zone. The call records we are ta...
by msarro Builder in Splunk Search 04-16-2013
0 4
0
4
rajdiddi
Hi, I have the challenge of pulling log files which come in m-d-yyyy format. Please advise how to advise the splunk...
by rajdiddi New Member in Splunk Search 04-16-2013
0 5
0
5
batzel
How can I take table output like the above and convert it into key=value pairs, so I can eval them further? I came u...
by batzel Engager in Splunk Search 04-16-2013
0 1
0
1
rizzo75
tscollect was leveraged to put data into time series index files. I am able to use tstat to calculate statistics. H...
by rizzo75 Path Finder in Splunk Search 04-16-2013
1 1
1
1
ryastrebov
Hello! I have saved search for 8 days. I need upload search result to csv-file for several days. One day - one csv. I...
by ryastrebov Communicator in Splunk Search 04-16-2013
0 2
0
2
sieutruc
Hello, I get difficult when manipulating XML field name, if i use like: sourcetype="test_xml_as" | table content_ta...
by sieutruc Contributor in Splunk Search 04-16-2013
0 5
0
5
bmgilmore
If I run a search such as the following: sourcetype=access_combined action=purchase | stats sum(price) as Price by p...
by bmgilmore Path Finder in Splunk Search 04-16-2013
1 1
1
1
mikedavem
Hi all, I'm working on an extraction of information into a SQL Server log. I've a field Message that looks like : L...
by mikedavem New Member in Splunk Search 04-16-2013
0 3
0
3
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...