Splunk Search

Splunk Search
Community Activity
nageshreddy81
I am trying to create a custom field using Field-Extraction and Field-Transformation pages of Manager. I am providing...
by nageshreddy81 New Member in Splunk Search 02-25-2013
0 3
0
3
khyoung7410
I'm bringing data from a database every 1 minuite. Data is three kinds. Data type is 1. 2013-02-01 13:12:01;i;OS000...
by khyoung7410 Communicator in Splunk Search 02-25-2013
0 1
0
1
rdownie
If I use: |dbquery mydb "select userid from mydb.people where username = 'jsmith' | rename userid as UID | lookup myd...
by rdownie Communicator in Splunk Search 02-24-2013
0 5
0
5
lemikg
Hi, I don't know if this is the right way to do it, but I have a list of COMMANDS which I have associated a Classifi...
by lemikg Communicator in Splunk Search 02-24-2013
1 3
1
3
kenchisho
Hi guys, I have been playing around trying to match multiple ocurances of a pattern and replace it with a regex in t...
by kenchisho Path Finder in Splunk Search 02-22-2013
0 2
0
2
tnkoehn
Let's say I have log records that look like this Field 1 Field 2 ABC XYZ ABC KLM XYZ ABC...
by tnkoehn Path Finder in Splunk Search 02-22-2013
0 1
0
1
aferone
We run a report every week that counts how many times a firewall policy was used. (A firewall policy is represented ...
by aferone Builder in Splunk Search 02-22-2013
0 5
0
5
dannux
Hi Everyone, I am doing the following search sourcetype="a" OR sourcetype="b" OR sourcetype="c" CPU_IDLE<40 | tim...
by dannux Path Finder in Splunk Search 02-22-2013
0 2
0
2
cphair
Hello, I'm wondering if there's a way to trim characters from an unknown field value during search. I'm tracking pe...
by cphair Builder in Splunk Search 02-22-2013
4 4
4
4
kingsizebk
I cannot seem to "eval" a field obtained from a "rex" and i am pretty sure the field is only digits... this is simili...
by kingsizebk Path Finder in Splunk Search 02-22-2013
0 3
0
3
aapittts
I have raw data that looks like this: (4)example(3)domain(3)com(0). In my search, I've been using a macro that looks ...
by aapittts Path Finder in Splunk Search 02-22-2013
0 1
0
1
lemikg
Hi Splunkers I have two searches I want to compare, but unfortunately can't find my way around it. First is: CPU lo...
by lemikg Communicator in Splunk Search 02-22-2013
0 2
0
2
hartfoml
I am in a clustered indexer environment and some but not all of my indexers are showing this error "The lookup table...
by hartfoml Motivator in Splunk Search 02-22-2013
0 4
0
4
whateverman
So I’m trying to link a couple different fields together to get the data I’m looking for, but it involves a couple st...
by whateverman Explorer in Splunk Search 02-21-2013
2 2
2
2
rtadams89
I'm working on a search which should return all events, except those where the "User_Name" or the "Account_Name" fiel...
by rtadams89 Contributor in Splunk Search 02-21-2013
2 4
2
4
qfjp
I found a field, b1, c1, d1, e1 a1 to the search field. What if you want to view the rest of the fields except for e1...
by qfjp Explorer in Splunk Search 02-21-2013
0 1
0
1
WilliamF
Hi Support team, I just wanna check with you guys on how to detect if logs stopped from regular source? Best regard...
by WilliamF Engager in Splunk Search 02-21-2013
0 1
0
1
timpgray
I am using a subsearch to qualify an outer search. Simplified, it looks something like this: Index =AAAA [index=AAA...
by timpgray Path Finder in Splunk Search 02-21-2013
1 3
1
3
johnpof
Hey Guys, This is my current search (It looks for SQL I/O delays) = sourcetype="WinEventLog:Application" MSSQLSERVER...
by johnpof Path Finder in Splunk Search 02-21-2013
1 7
1
7
mataharry
How to figure which events are broken or truncated by splunk. I know that the default is 256 lines for multiline even...
by mataharry Communicator in Splunk Search 02-21-2013
1 3
1
3
lpolo
I have an custom search command. It is scheduled to run every 5min. The results are indexed in a summary index. I ne...
by lpolo Motivator in Splunk Search 02-21-2013
0 2
0
2
Adam_Sealey
I'm trying to leverage my indexed DHCPD logs to provide additional information about internal IP's that show up in ot...
by Adam_Sealey Explorer in Splunk Search 02-21-2013
0 5
0
5
pdash
Below is the raw data that am getting. I want to extract the events where category is Error. For this am doing this i...
by pdash Path Finder in Splunk Search 02-21-2013
0 6
0
6
aferone
I've tried using info from the following 2 KB posts, but I am still having trouble: http://splunk-base.splunk.com/an...
by aferone Builder in Splunk Search 02-21-2013
0 5
0
5
yap
Hi, I would like to group my product based on weight. Sample logs are: Product ID | Weight 00368001a1 | 1.4...
by yap Explorer in Splunk Search 02-21-2013
0 2
0
2
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors