Splunk Search

Splunk Search
Community Activity
WilliamF
Hi Support team, I just wanna check with you guys on how to detect if logs stopped from regular source? Best regard...
by WilliamF Engager in Splunk Search 02-21-2013
0 1
0
1
timpgray
I am using a subsearch to qualify an outer search. Simplified, it looks something like this: Index =AAAA [index=AAA...
by timpgray Path Finder in Splunk Search 02-21-2013
1 3
1
3
johnpof
Hey Guys, This is my current search (It looks for SQL I/O delays) = sourcetype="WinEventLog:Application" MSSQLSERVER...
by johnpof Path Finder in Splunk Search 02-21-2013
1 7
1
7
mataharry
How to figure which events are broken or truncated by splunk. I know that the default is 256 lines for multiline even...
by mataharry Communicator in Splunk Search 02-21-2013
1 3
1
3
lpolo
I have an custom search command. It is scheduled to run every 5min. The results are indexed in a summary index. I ne...
by lpolo Motivator in Splunk Search 02-21-2013
0 2
0
2
Adam_Sealey
I'm trying to leverage my indexed DHCPD logs to provide additional information about internal IP's that show up in ot...
by Adam_Sealey Explorer in Splunk Search 02-21-2013
0 5
0
5
pdash
Below is the raw data that am getting. I want to extract the events where category is Error. For this am doing this i...
by pdash Path Finder in Splunk Search 02-21-2013
0 6
0
6
aferone
I've tried using info from the following 2 KB posts, but I am still having trouble: http://splunk-base.splunk.com/an...
by aferone Builder in Splunk Search 02-21-2013
0 5
0
5
yap
Hi, I would like to group my product based on weight. Sample logs are: Product ID | Weight 00368001a1 | 1.4...
by yap Explorer in Splunk Search 02-21-2013
0 2
0
2
michaelbrunetto
I'm having trouble with the way Splunk parses some of my logs which has field=value pairs that have values with unquo...
by michaelbrunetto New Member in Splunk Search 02-21-2013
0 1
0
1
sara_shafaei
what is the best way to add these devices dynamically ? We are using autoscale servers, how should we introduce new d...
by sara_shafaei New Member in Splunk Search 02-20-2013
0 3
0
3
Ron_Naken
With the following data: mac_addr=01-02-03-04-05-06, 01-02-03-04-05-07, 01-02-03-04-05-08 Using this search will...
by Ron_Naken Splunk Employee Splunk Employee in Splunk Search 02-20-2013
2 6
2
6
pkashou
It seems that mvfind will only return the index of the first matching value. I would like to return the index of the ...
by pkashou Explorer in Splunk Search 02-20-2013
0 1
0
1
p_splunk
The problem I'm facing is that I want a search that comes up with the possibility to set different time modifiers for...
by p_splunk Engager in Splunk Search 02-20-2013
0 2
0
2
rimururu01
hello . i want to convert oracle function to splunk search. but i don't know this conversion . here's oracle functi...
by rimururu01 New Member in Splunk Search 02-20-2013
0 5
0
5
javo
How can I keep fields of a subsearch so I can add them to a table with the end result? I tried with no success ... [...
by javo Explorer in Splunk Search 02-20-2013
0 5
0
5
rakesh_498115
HI.. I have seen the functions ltrim and rtrim to spaces ..do we have functions to trim new lines.. actually in my ...
by rakesh_498115 Motivator in Splunk Search 02-20-2013
0 8
0
8
mcm10285
Is there a way to determine which field extraction (transforms or search rex) was used for a specific sourcetype?
by mcm10285 Communicator in Splunk Search 02-20-2013
0 4
0
4
bhavna_jain
Hi, I want to draw two lines as warning boundaries in a line chart. The string goes "index="ong_poc_index" sourcetyp...
by bhavna_jain Engager in Splunk Search 02-20-2013
0 2
0
2
pdash
Below is the raw data that am getting. I want to extract the events where category is Error. For this am doing this i...
by pdash Path Finder in Splunk Search 02-19-2013
0 2
0
2
lukeh
Hi  We are using Splunk 5.0.2 and have a requirement to show peak bandwidth usage over time. Here is the search th...
by lukeh Contributor in Splunk Search 02-19-2013
0 2
0
2
tmeader
There is a configuration file default setting error that was made (and confirmed by Splunk support today when I calle...
by tmeader Contributor in Splunk Search 02-19-2013
4 9
4
9
sumanbej
I have a log file ( generated from the WAS server) having the first line like that : null null null null... Please h...
by sumanbej New Member in Splunk Search 02-19-2013
0 3
0
3
rickytrumper
New splunk user here so I'm not very familiar with how some of the commands work, so I apologize in advance. My sear...
by rickytrumper New Member in Splunk Search 02-19-2013
0 6
0
6
Aakanksha
I want top 10 values from the below query: Problem is , we have applied stats average on multiple column, so simply w...
by Aakanksha Path Finder in Splunk Search 02-19-2013
0 3
0
3
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...