Splunk Search

Splunk Search
Community Activity
rakesh_498115
props.conf EXTRACT-IPUBMESSAGEID = <L:MESSAGEID>(?<IPUBMESSAGEID>[^<]*)</L:MESSAGEID> EXTRACT-Parse_MESSAGEID = IPUB...
by rakesh_498115 Motivator in Splunk Search 03-20-2013
0 3
0
3
p_basanth
I want to combine the below 2 ouputs into single line | stats count by Domain | stats values(Domain) by Short_Host ...
by p_basanth New Member in Splunk Search 03-20-2013
0 4
0
4
p_basanth
Any pointers on how to extract the third field Event1: <> Event2: the third field is populated with double ...
by p_basanth New Member in Splunk Search 03-20-2013
0 1
0
1
andyspusm
I am extracting a field "ipaddr" which is the result of using "eval" to convert a previously extracted field "nwclien...
by andyspusm Explorer in Splunk Search 03-19-2013
0 2
0
2
dilstn
I have a log files where it contains duplicates like "json from session" log duplicates .. so the log which contains ...
by dilstn Explorer in Splunk Search 03-19-2013
0 4
0
4
p_basanth
Using the below regex I was able to extract first7 fields Need to extract the last 3 fields How to skip the blank <> ...
by p_basanth New Member in Splunk Search 03-19-2013
0 4
0
4
dgadjov
Running this through the Splunk search I get no errors. However when I put this search in my Advance XML I get: misma...
by dgadjov Explorer in Splunk Search 03-19-2013
0 5
0
5
dgadjov
The goal is just to have the percentage pass rate at the bottom of a dynamically named column that contains "Passed" ...
by dgadjov Explorer in Splunk Search 03-19-2013
0 3
0
3
machosplunker
I am trying to filtering results based on hosts which are our hbase zookeepers and region servers. There are 3 hbase ...
by machosplunker Explorer in Splunk Search 03-19-2013
0 3
0
3
basusplunk
Hi, Please help me. Where can I get the latest splunk jar? Thanks, Basu.
by basusplunk New Member in Splunk Search 03-19-2013
0 3
0
3
lpolo
After upgrading to 5.0.1 splunk is reporting this message: "Metadata results from this peer are incomplete: the peer...
by lpolo Motivator in Splunk Search 03-19-2013
4 1
4
1
approachct
We are replacing our existing logging system with Splunk, but we still have the need to load some of these log events...
by approachct Path Finder in Splunk Search 03-19-2013
1 1
1
1
gudavasr
Hi, My transform file: [taskname] REGEX = \b(Task\w+)\b FORMAT = taskname::$1 props.conf REPORT-taskname = tas...
by gudavasr Path Finder in Splunk Search 03-19-2013
0 1
0
1
renuka13
hi, how do i find the difference between two dates which are in the form 12-JAN-2003? How do i first convert months ...
by renuka13 Explorer in Splunk Search 03-19-2013
0 1
0
1
bnafziger
I am a newbie. I'd like an another user's opinion of my logic. Is this the proper syntax for generation of std dev? I...
by bnafziger Engager in Splunk Search 03-19-2013
0 1
0
1
keithtyler
**My mission: Alert networking staff when one of their devices has high log deviation. **How I think it should be do...
by keithtyler New Member in Splunk Search 03-19-2013
0 5
0
5
sbsbb
I have two different indexes, with multiple sources, say source1, source2 How can I define a different Extraction pe...
by sbsbb Builder in Splunk Search 03-19-2013
1 2
1
2
dilstn
I really need of some knowledge about regular expression ,, as how to create own regex or rex ... so suggest me some ...
by dilstn Explorer in Splunk Search 03-19-2013
0 3
0
3
renuka13
Here JAN is String so we can not subtract... is there any command which converts JAN to 1 or FEB to 2 so on please he...
by renuka13 Explorer in Splunk Search 03-19-2013
0 1
0
1
Kai191
Hi, I would like to ask, if my Splunk server very to be deployed on a VM workstation for easy distribution, how can I...
by Kai191 New Member in Splunk Search 03-18-2013
0 4
0
4
snickered
I have a sourcetype that has multi-line events. An example looks like this: Jan07 12:45:18.57 | [Info ] | This is th...
by snickered Path Finder in Splunk Search 03-18-2013
0 2
0
2
SonnyB
How to add spacing between multiple eventdata lines of a transaction? Say, for an access_combined type of log, I grou...
by SonnyB Explorer in Splunk Search 03-18-2013
0 5
0
5
neilstuartcraig
Hello all I am trying to create a scheduled search to run every 15 minutes, scanning from -15m to now. This search u...
by neilstuartcraig New Member in Splunk Search 03-18-2013
0 2
0
2
andyk
Is it possible to use _TCP_ROUTING with a UDP input? I can not get it to work. My other "monitor" inputs works fine w...
by andyk Path Finder in Splunk Search 03-18-2013
0 3
0
3
tmarlette
I am trying to extract an IP address into a field, however the same information occurs on two different logs, with tw...
by tmarlette Motivator in Splunk Search 03-18-2013
0 9
0
9
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...