Splunk Search

Splunk Search
Community Activity
noambz
Hi, I have the following search which generates the data below: some_search | bucket _time span=1h | stats count ...
by noambz Explorer in Splunk Search 03-20-2013
0 3
0
3
jacs
Can I cluster two Splunk nodes for data availability without having a search head node? In other words, use one or b...
by jacs New Member in Splunk Search 03-20-2013
0 1
0
1
Splunk_U
I have two search heads. I want that if a user logged in to SRCH1 and saved a search and logged off and then looged i...
by Splunk_U Path Finder in Splunk Search 03-20-2013
0 2
0
2
the_wolverine
We have some fields with large unique string values, e.g. EMAIL_SUBJECT, where search performance (particularly on wi...
by the_wolverine Champion in Splunk Search 03-20-2013
0 1
0
1
daniel333
All, I need to compare the results of two different searches and I am lost. Something like this. count( search st...
by daniel333 Builder in Splunk Search 03-20-2013
0 2
0
2
rakesh_498115
props.conf EXTRACT-IPUBMESSAGEID = <L:MESSAGEID>(?<IPUBMESSAGEID>[^<]*)</L:MESSAGEID> EXTRACT-Parse_MESSAGEID = IPUB...
by rakesh_498115 Motivator in Splunk Search 03-20-2013
0 3
0
3
p_basanth
I want to combine the below 2 ouputs into single line | stats count by Domain | stats values(Domain) by Short_Host ...
by p_basanth New Member in Splunk Search 03-20-2013
0 4
0
4
p_basanth
Any pointers on how to extract the third field Event1: <> Event2: the third field is populated with double ...
by p_basanth New Member in Splunk Search 03-20-2013
0 1
0
1
andyspusm
I am extracting a field "ipaddr" which is the result of using "eval" to convert a previously extracted field "nwclien...
by andyspusm Explorer in Splunk Search 03-19-2013
0 2
0
2
dilstn
I have a log files where it contains duplicates like "json from session" log duplicates .. so the log which contains ...
by dilstn Explorer in Splunk Search 03-19-2013
0 4
0
4
p_basanth
Using the below regex I was able to extract first7 fields Need to extract the last 3 fields How to skip the blank <> ...
by p_basanth New Member in Splunk Search 03-19-2013
0 4
0
4
dgadjov
Running this through the Splunk search I get no errors. However when I put this search in my Advance XML I get: misma...
by dgadjov Explorer in Splunk Search 03-19-2013
0 5
0
5
dgadjov
The goal is just to have the percentage pass rate at the bottom of a dynamically named column that contains "Passed" ...
by dgadjov Explorer in Splunk Search 03-19-2013
0 3
0
3
machosplunker
I am trying to filtering results based on hosts which are our hbase zookeepers and region servers. There are 3 hbase ...
by machosplunker Explorer in Splunk Search 03-19-2013
0 3
0
3
basusplunk
Hi, Please help me. Where can I get the latest splunk jar? Thanks, Basu.
by basusplunk New Member in Splunk Search 03-19-2013
0 3
0
3
lpolo
After upgrading to 5.0.1 splunk is reporting this message: "Metadata results from this peer are incomplete: the peer...
by lpolo Motivator in Splunk Search 03-19-2013
4 1
4
1
approachct
We are replacing our existing logging system with Splunk, but we still have the need to load some of these log events...
by approachct Path Finder in Splunk Search 03-19-2013
1 1
1
1
gudavasr
Hi, My transform file: [taskname] REGEX = \b(Task\w+)\b FORMAT = taskname::$1 props.conf REPORT-taskname = tas...
by gudavasr Path Finder in Splunk Search 03-19-2013
0 1
0
1
renuka13
hi, how do i find the difference between two dates which are in the form 12-JAN-2003? How do i first convert months ...
by renuka13 Explorer in Splunk Search 03-19-2013
0 1
0
1
bnafziger
I am a newbie. I'd like an another user's opinion of my logic. Is this the proper syntax for generation of std dev? I...
by bnafziger Engager in Splunk Search 03-19-2013
0 1
0
1
keithtyler
**My mission: Alert networking staff when one of their devices has high log deviation. **How I think it should be do...
by keithtyler New Member in Splunk Search 03-19-2013
0 5
0
5
sbsbb
I have two different indexes, with multiple sources, say source1, source2 How can I define a different Extraction pe...
by sbsbb Builder in Splunk Search 03-19-2013
1 2
1
2
dilstn
I really need of some knowledge about regular expression ,, as how to create own regex or rex ... so suggest me some ...
by dilstn Explorer in Splunk Search 03-19-2013
0 3
0
3
renuka13
Here JAN is String so we can not subtract... is there any command which converts JAN to 1 or FEB to 2 so on please he...
by renuka13 Explorer in Splunk Search 03-19-2013
0 1
0
1
Kai191
Hi, I would like to ask, if my Splunk server very to be deployed on a VM workstation for easy distribution, how can I...
by Kai191 New Member in Splunk Search 03-18-2013
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...