| I am in a clustered indexer environment and some but not all of my indexers are showing this error "The lookup table... by hartfoml Motivator in Splunk Search 02-22-2013 0 4 | 0 | 4 | ||
| So I’m trying to link a couple different fields together to get the data I’m looking for, but it involves a couple st... by whateverman Explorer in Splunk Search 02-21-2013 2 2 | 2 | 2 | ||
| I'm working on a search which should return all events, except those where the "User_Name" or the "Account_Name" fiel... by rtadams89 Contributor in Splunk Search 02-21-2013 2 4 | 2 | 4 | ||
| I found a field, b1, c1, d1, e1 a1 to the search field. What if you want to view the rest of the fields except for e1... by qfjp Explorer in Splunk Search 02-21-2013 0 1 | 0 | 1 | ||
| Hi Support team, I just wanna check with you guys on how to detect if logs stopped from regular source? Best regard... by WilliamF Engager in Splunk Search 02-21-2013 0 1 | 0 | 1 | ||
| I am using a subsearch to qualify an outer search. Simplified, it looks something like this: Index =AAAA [index=AAA... by timpgray Path Finder in Splunk Search 02-21-2013 1 3 | 1 | 3 | ||
| Hey Guys, This is my current search (It looks for SQL I/O delays) = sourcetype="WinEventLog:Application" MSSQLSERVER... by johnpof Path Finder in Splunk Search 02-21-2013 1 7 | 1 | 7 | ||
| How to figure which events are broken or truncated by splunk. I know that the default is 256 lines for multiline even... by mataharry Communicator in Splunk Search 02-21-2013 1 3 | 1 | 3 | ||
| I have an custom search command. It is scheduled to run every 5min. The results are indexed in a summary index. I ne... by lpolo Motivator in Splunk Search 02-21-2013 0 2 | 0 | 2 | ||
| I'm trying to leverage my indexed DHCPD logs to provide additional information about internal IP's that show up in ot... by Adam_Sealey Explorer in Splunk Search 02-21-2013 0 5 | 0 | 5 | ||
| Below is the raw data that am getting. I want to extract the events where category is Error. For this am doing this i... by pdash Path Finder in Splunk Search 02-21-2013 0 6 | 0 | 6 | ||
| I've tried using info from the following 2 KB posts, but I am still having trouble: http://splunk-base.splunk.com/an... by aferone Builder in Splunk Search 02-21-2013 0 5 | 0 | 5 | ||
| Hi, I would like to group my product based on weight. Sample logs are: Product ID | Weight 00368001a1 | 1.4... by yap Explorer in Splunk Search 02-21-2013 0 2 | 0 | 2 | ||
| I'm having trouble with the way Splunk parses some of my logs which has field=value pairs that have values with unquo... by michaelbrunetto New Member in Splunk Search 02-21-2013 0 1 | 0 | 1 | ||
| what is the best way to add these devices dynamically ? We are using autoscale servers, how should we introduce new d... by sara_shafaei New Member in Splunk Search 02-20-2013 0 3 | 0 | 3 | ||
| With the following data: mac_addr=01-02-03-04-05-06, 01-02-03-04-05-07, 01-02-03-04-05-08 Using this search will... by Ron_Naken Splunk Employee 2 6 | 2 | 6 | ||
| It seems that mvfind will only return the index of the first matching value. I would like to return the index of the ... by pkashou Explorer in Splunk Search 02-20-2013 0 1 | 0 | 1 | ||
| The problem I'm facing is that I want a search that comes up with the possibility to set different time modifiers for... by p_splunk Engager in Splunk Search 02-20-2013 0 2 | 0 | 2 | ||
| hello . i want to convert oracle function to splunk search. but i don't know this conversion . here's oracle functi... by rimururu01 New Member in Splunk Search 02-20-2013 0 5 | 0 | 5 | ||
| How can I keep fields of a subsearch so I can add them to a table with the end result? I tried with no success ... [... by javo Explorer in Splunk Search 02-20-2013 0 5 | 0 | 5 | ||
| HI.. I have seen the functions ltrim and rtrim to spaces ..do we have functions to trim new lines.. actually in my ... by rakesh_498115 Motivator in Splunk Search 02-20-2013 0 8 | 0 | 8 | ||
| Is there a way to determine which field extraction (transforms or search rex) was used for a specific sourcetype? by mcm10285 Communicator in Splunk Search 02-20-2013 0 4 | 0 | 4 | ||
| Hi, I want to draw two lines as warning boundaries in a line chart. The string goes "index="ong_poc_index" sourcetyp... by bhavna_jain Engager in Splunk Search 02-20-2013 0 2 | 0 | 2 | ||
| Below is the raw data that am getting. I want to extract the events where category is Error. For this am doing this i... by pdash Path Finder in Splunk Search 02-19-2013 0 2 | 0 | 2 | ||
| Hi We are using Splunk 5.0.2 and have a requirement to show peak bandwidth usage over time. Here is the search th... by lukeh Contributor in Splunk Search 02-19-2013 0 2 | 0 | 2 |