Splunk Search

Splunk Search
Community Activity
rstanonik
A search returned 7000 events within one second. By default splunk shows me the most recent events and allows me to n...
by rstanonik Engager in Splunk Search 04-16-2013
0 3
0
3
marellasunil
For another query where I have to use not equal to in a query for string, even not equal to is not working properly i...
by marellasunil Communicator in Splunk Search 04-15-2013
0 3
0
3
kbcuait
Hi, is it possible to broaden a search with something like this: | dbquery "dbname" "SELECT fieldname_(*) FROM table...
by kbcuait Explorer in Splunk Search 04-15-2013
0 4
0
4
Wiggy
Say I have two different logs, source=a.txt and source=b.txt and their format is as follows: Source=a.txt 09-Apr-20...
by Wiggy Splunk Employee Splunk Employee in Splunk Search 04-15-2013
0 1
0
1
jevenson
I'm trying to get a weighted ratio of errors per server. I have a lookup table like this: host,percent server1,25 se...
by jevenson Path Finder in Splunk Search 04-15-2013
0 1
0
1
jevenson
Is there a way to use a lookup table to have a list of host, and use that list to only search logs for those hosts? ...
by jevenson Path Finder in Splunk Search 04-15-2013
1 3
1
3
tomhowe
We are pushing in [json] events with a timestamp field that contains time since epoch in milliseconds, eg: {[-] nam...
by tomhowe New Member in Splunk Search 04-15-2013
0 1
0
1
paycorp
Hello, I was wondering which indexes are included in the daily 500mb limit of the free version? Is it just the main...
by paycorp Engager in Splunk Search 04-15-2013
0 3
0
3
splunkiscool1
Hello, I would like to get an alert if the indexing volume for an index drops. I'm thinking something similar this...
by splunkiscool1 Engager in Splunk Search 04-15-2013
0 5
0
5
echalex
Hi, I need to reference a file distributed by an input app from within the app itself (outputs.conf). I need to conf...
by echalex Builder in Splunk Search 04-15-2013
0 5
0
5
jevenson
I've got a search that looks something like this: search | eval Minutes=case(field<120,"0 to 2", field>=120 AND fiel...
by jevenson Path Finder in Splunk Search 04-14-2013
1 3
1
3
asarolkar
I have two sourcetypes A and B - each has a column SERIAL_NUMBER Sourcetype A has over 1000,000 records Sourcetype B...
by asarolkar Builder in Splunk Search 04-14-2013
1 6
1
6
marellasunil
I am having 5 applications each having service names few are same. Ex : Application A - Services AA, AB, AC, Applicat...
by marellasunil Communicator in Splunk Search 04-13-2013
0 1
0
1
reed_kelly
Most of our MS SQL Servers require integrated security and the databases are not on the default instance. Our Splunk ...
by reed_kelly Contributor in Splunk Search 04-13-2013
0 2
0
2
lindsaygw
Here is the 6 lines in a log file that all come out together in the log but they are each different lines (not wrappe...
by lindsaygw New Member in Splunk Search 04-12-2013
0 3
0
3
rlautman
I use Splunks automated report facility for several reports - but I know have a requirement for a report that goes th...
by rlautman Path Finder in Splunk Search 04-12-2013
0 1
0
1
splunk4steve
I am trying to get a list of people who have logged in to our system in the last 24 hours. The unix app runs a scrip...
by splunk4steve New Member in Splunk Search 04-12-2013
0 6
0
6
rchille
I have a search that returns values in a table like this: USERTIMEIPLocationuser1time1ip1loc1user1time2ip1loc1user2t...
by rchille Engager in Splunk Search 04-12-2013
0 5
0
5
aaronkorn
One of our Splunk searches that just searches for all events in an index for the last 24hrs used to be blazingly fast...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 04-12-2013
0 4
0
4
aaronkorn
Hello, We have a search that is looking through a script that calculates the size of directories throughout the day ...
by aaronkorn Splunk Employee Splunk Employee in Splunk Search 04-12-2013
2 1
2
1
andrey2007
I locally index data from apache server. I can see events for search sourcetype="access_*" and field extraction works...
by andrey2007 Contributor in Splunk Search 04-12-2013
0 3
0
3
subinj
Hi. I have an excel dump of incident tickets generated from the ticketing tool. Sample incidents' description from t...
by subinj New Member in Splunk Search 04-12-2013
0 10
0
10
splunk_zen
How is it possible that an eval expression which its components total weight is 100, breach that expected value? For ...
by splunk_zen Builder in Splunk Search 04-12-2013
0 2
0
2
betto86
Hi all  I need you help because I can't figure out how to solve this problem. Suppose we have a table, made of two ...
by betto86 Engager in Splunk Search 04-12-2013
0 1
0
1
royimad
I have a regular expression that extract everything that exist between brackets Extraction: (?i) .*? (?P<METHOD>\...
by royimad Builder in Splunk Search 04-12-2013
0 5
0
5
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...