| Hello, I would like to get an alert if the indexing volume for an index drops. I'm thinking something similar this... by splunkiscool1 Engager in Splunk Search 04-15-2013 0 5 | 0 | 5 | ||
| Hi, I need to reference a file distributed by an input app from within the app itself (outputs.conf). I need to conf... by echalex Builder in Splunk Search 04-15-2013 0 5 | 0 | 5 | ||
| I've got a search that looks something like this: search | eval Minutes=case(field<120,"0 to 2", field>=120 AND fiel... by jevenson Path Finder in Splunk Search 04-14-2013 1 3 | 1 | 3 | ||
| I have two sourcetypes A and B - each has a column SERIAL_NUMBER Sourcetype A has over 1000,000 records Sourcetype B... by asarolkar Builder in Splunk Search 04-14-2013 1 6 | 1 | 6 | ||
| I am having 5 applications each having service names few are same. Ex : Application A - Services AA, AB, AC, Applicat... by marellasunil Communicator in Splunk Search 04-13-2013 0 1 | 0 | 1 | ||
| Most of our MS SQL Servers require integrated security and the databases are not on the default instance. Our Splunk ... by reed_kelly Contributor in Splunk Search 04-13-2013 0 2 | 0 | 2 | ||
| Here is the 6 lines in a log file that all come out together in the log but they are each different lines (not wrappe... by lindsaygw New Member in Splunk Search 04-12-2013 0 3 | 0 | 3 | ||
| I use Splunks automated report facility for several reports - but I know have a requirement for a report that goes th... by rlautman Path Finder in Splunk Search 04-12-2013 0 1 | 0 | 1 | ||
| I am trying to get a list of people who have logged in to our system in the last 24 hours. The unix app runs a scrip... by splunk4steve New Member in Splunk Search 04-12-2013 0 6 | 0 | 6 | ||
| I have a search that returns values in a table like this: USERTIMEIPLocationuser1time1ip1loc1user1time2ip1loc1user2t... by rchille Engager in Splunk Search 04-12-2013 0 5 | 0 | 5 | ||
| One of our Splunk searches that just searches for all events in an index for the last 24hrs used to be blazingly fast... by aaronkorn Splunk Employee 0 4 | 0 | 4 | ||
| Hello, We have a search that is looking through a script that calculates the size of directories throughout the day ... by aaronkorn Splunk Employee 2 1 | 2 | 1 | ||
| I locally index data from apache server. I can see events for search sourcetype="access_*" and field extraction works... by andrey2007 Contributor in Splunk Search 04-12-2013 0 3 | 0 | 3 | ||
| Hi. I have an excel dump of incident tickets generated from the ticketing tool. Sample incidents' description from t... by subinj New Member in Splunk Search 04-12-2013 0 10 | 0 | 10 | ||
| How is it possible that an eval expression which its components total weight is 100, breach that expected value? For ... by splunk_zen Builder in Splunk Search 04-12-2013 0 2 | 0 | 2 | ||
| Hi all I need you help because I can't figure out how to solve this problem. Suppose we have a table, made of two ... by betto86 Engager in Splunk Search 04-12-2013 0 1 | 0 | 1 | ||
| I have a regular expression that extract everything that exist between brackets Extraction: (?i) .*? (?P<METHOD>\... by royimad Builder in Splunk Search 04-12-2013 0 5 | 0 | 5 | ||
| How can I get a result out of an eval expression (without falsely decreasing the result computing its components as 0... by splunk_zen Builder in Splunk Search 04-12-2013 0 2 | 0 | 2 | ||
| Hello, I have a table with 4 Header: A B C D I need to show A C D column if B is null and B C D column if A is nul... by royimad Builder in Splunk Search 04-12-2013 0 2 | 0 | 2 | ||
| Hi, I have a working search right now that returns user and host. I am wondering how to remove results where the val... by ccastrapel New Member in Splunk Search 04-11-2013 0 1 | 0 | 1 | ||
| Hi, I am getting events in the form of: __time, app_name, action,udid "2013-04-11 23:26:32","nxTomo HK V0.9","game... by noambz Explorer in Splunk Search 04-11-2013 0 3 | 0 | 3 | ||
| I have a search time query | dbquery OEM "SELECT regexp_replace(d.target_name, '\..*', '') AS output, d.collection_... by arrowsmith3 Path Finder in Splunk Search 04-11-2013 0 1 | 0 | 1 | ||
| I sometimes receive the following error message in my shp environment (4.3.5) when executing a search: ERROR: Reach... by RicoSuave Builder in Splunk Search 04-11-2013 5 2 | 5 | 2 | ||
| I need to back fill an index from a scheduled search but the result set of the scheduled search is quite large. There... by lpolo Motivator in Splunk Search 04-11-2013 0 1 | 0 | 1 | ||
| I would like to return a chart that has LOGIN SUCCESS LOGIN FAILURE and TOTAL LOGIN ATTEMPTS. In my logs I return ... by MattQ Explorer in Splunk Search 04-11-2013 0 1 | 0 | 1 |