Splunk Search

Splunk Search
Community Activity
brettcave
Is it possible to build a form with checkboxes to build a query? Something like: < input type="checkbox" token="some...
by brettcave Builder in Splunk Search 02-12-2013
1 6
1
6
mkumarpisl
How to use the NOT operator for combination of two words. In my log I need to eliminate the errors by considering th...
by mkumarpisl New Member in Splunk Search 02-12-2013
0 3
0
3
abishop195
Hey Guys, I have been stuck on the following for a few days and would love some help Trying to perform a search of ...
by abishop195 New Member in Splunk Search 02-12-2013
0 2
0
2
MBerikcurtis
I have a ton of event that contain SourceName="Symantec AntiVirus". How can I exclude these events fro being indexed?
by MBerikcurtis Path Finder in Splunk Search 02-12-2013
0 1
0
1
dabbank
Do I get it right that after the successful setup of the Splunk DB Connect every Splunk user can access the configure...
by dabbank Path Finder in Splunk Search 02-12-2013
2 13
2
13
cmak
I have many fields that end with the regular expression _rate. Ex: Compile_rate Typing_rate I can get all my rates w...
by cmak Contributor in Splunk Search 02-12-2013
1 5
1
5
Cris
Could anyone tell me how to modify the application.css to show multiline fields in multiline format (with CRLF) on a ...
by Cris Explorer in Splunk Search 02-12-2013
0 1
0
1
emiller42
Hello! I have some log files with dynamic naming that I'm having trouble matching with props.conf stanzas. Here are...
by emiller42 Motivator in Splunk Search 02-12-2013
1 7
1
7
toekneeh
I have tried to modify my time.conf to have a static set of dates I can select. I added the following to my time.conf...
by toekneeh Engager in Splunk Search 02-12-2013
0 3
0
3
dbautist
I have the following log snippet with a JSON payload and I want to run a regex such that it extracts the JSON fields ...
by dbautist Explorer in Splunk Search 02-12-2013
0 4
0
4
dshakespeare_sp
test test test
by dshakespeare_sp Splunk Employee Splunk Employee in Splunk Search 02-12-2013
8 4
8
4
mkrauss1
Hi, i have a key value pair say FTYPE=VAL1 and FTYPE=VAL2 and create a timechart with earliest=-1d@d latest=now | ti...
by mkrauss1 Explorer in Splunk Search 02-12-2013
0 1
0
1
nawneel
Hi, I have installed Facebook App in my splunk set up.Currently i am able to get the user specific data using Facebo...
by nawneel Communicator in Splunk Search 02-12-2013
0 1
0
1
byessayian
Here's an example of a string I'm looking for: 15:55:37.732 ( 5436:15032) G-MST: 2000001D "00020000-dff6-5032-e3c7-0...
by byessayian New Member in Splunk Search 02-12-2013
0 2
0
2
tnkoehn
Hopefully this is not too confusing. I need to know how many concurrent calls occurred during the last hour for each ...
by tnkoehn Path Finder in Splunk Search 02-12-2013
1 7
1
7
nugetchar
Hi everyone, I'm posting here because of this: I have a csv-file like this: Thread, start_time_ms, duration 2, 13605...
by nugetchar Explorer in Splunk Search 02-12-2013
1 6
1
6
lemikg
Hi, right now I am having trouble exluding characters like "/, :, 0-9" from my search. I want those excluded I th...
by lemikg Communicator in Splunk Search 02-12-2013
0 5
0
5
opticsplanet
So, I've read an article about Logging best practices: http://dev.splunk.com/view/SP-CAAADP6 One of the recommendati...
by opticsplanet Path Finder in Splunk Search 02-12-2013
0 5
0
5
rick_harrison
I have a JSON format log file. When this is ingested by a single server installation of splunk (4.3.4), fields are c...
by rick_harrison New Member in Splunk Search 02-12-2013
0 1
0
1
Sqig
Hi. Some of our more ... enthusiastic ... users have been scheduling great big searches far too close together and f...
by Sqig Path Finder in Splunk Search 02-11-2013
0 1
0
1
handygecko
I'm new to splunk and I'm still struggling to grasp how it works. I uploaded data from a simple csv file. Data is as ...
by handygecko Explorer in Splunk Search 02-11-2013
0 3
0
3
Xe03kfp
This is what I have ( 2222222 dest_port="*") OR (1111111 src_port="*") | eval disconnect_time=if(match(_raw,"222222...
by Xe03kfp Path Finder in Splunk Search 02-11-2013
1 17
1
17
splunk_learner
Hi, I have a log Audit:[timestamp=01-31-2013 11:51:21.164,user=admin,action=search,info=granted REST: /search/jobs/1...
by splunk_learner Explorer in Splunk Search 02-11-2013
1 6
1
6
cmak
I am looking for a fast way to retrieve all the values for a single field. I have been doing this index=my_index| to...
by cmak Contributor in Splunk Search 02-11-2013
0 3
0
3
sridharanreddy
I am find few challenges to configure LDAP. Please help me out with this error?
by sridharanreddy Explorer in Splunk Search 02-11-2013
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...