Splunk Search

Splunk Search
Community Activity
mkumarpisl
How to use the NOT operator for combination of two words. In my log I need to eliminate the errors by considering th...
by mkumarpisl New Member in Splunk Search 02-12-2013
0 3
0
3
abishop195
Hey Guys, I have been stuck on the following for a few days and would love some help Trying to perform a search of ...
by abishop195 New Member in Splunk Search 02-12-2013
0 2
0
2
MBerikcurtis
I have a ton of event that contain SourceName="Symantec AntiVirus". How can I exclude these events fro being indexed?
by MBerikcurtis Path Finder in Splunk Search 02-12-2013
0 1
0
1
dabbank
Do I get it right that after the successful setup of the Splunk DB Connect every Splunk user can access the configure...
by dabbank Path Finder in Splunk Search 02-12-2013
2 13
2
13
cmak
I have many fields that end with the regular expression _rate. Ex: Compile_rate Typing_rate I can get all my rates w...
by cmak Contributor in Splunk Search 02-12-2013
1 5
1
5
Cris
Could anyone tell me how to modify the application.css to show multiline fields in multiline format (with CRLF) on a ...
by Cris Explorer in Splunk Search 02-12-2013
0 1
0
1
emiller42
Hello! I have some log files with dynamic naming that I'm having trouble matching with props.conf stanzas. Here are...
by emiller42 Motivator in Splunk Search 02-12-2013
1 7
1
7
toekneeh
I have tried to modify my time.conf to have a static set of dates I can select. I added the following to my time.conf...
by toekneeh Engager in Splunk Search 02-12-2013
0 3
0
3
dbautist
I have the following log snippet with a JSON payload and I want to run a regex such that it extracts the JSON fields ...
by dbautist Explorer in Splunk Search 02-12-2013
0 4
0
4
dshakespeare_sp
test test test
by dshakespeare_sp Splunk Employee Splunk Employee in Splunk Search 02-12-2013
8 4
8
4
mkrauss1
Hi, i have a key value pair say FTYPE=VAL1 and FTYPE=VAL2 and create a timechart with earliest=-1d@d latest=now | ti...
by mkrauss1 Explorer in Splunk Search 02-12-2013
0 1
0
1
nawneel
Hi, I have installed Facebook App in my splunk set up.Currently i am able to get the user specific data using Facebo...
by nawneel Communicator in Splunk Search 02-12-2013
0 1
0
1
byessayian
Here's an example of a string I'm looking for: 15:55:37.732 ( 5436:15032) G-MST: 2000001D "00020000-dff6-5032-e3c7-0...
by byessayian New Member in Splunk Search 02-12-2013
0 2
0
2
tnkoehn
Hopefully this is not too confusing. I need to know how many concurrent calls occurred during the last hour for each ...
by tnkoehn Path Finder in Splunk Search 02-12-2013
1 7
1
7
nugetchar
Hi everyone, I'm posting here because of this: I have a csv-file like this: Thread, start_time_ms, duration 2, 13605...
by nugetchar Explorer in Splunk Search 02-12-2013
1 6
1
6
lemikg
Hi, right now I am having trouble exluding characters like "/, :, 0-9" from my search. I want those excluded I th...
by lemikg Communicator in Splunk Search 02-12-2013
0 5
0
5
opticsplanet
So, I've read an article about Logging best practices: http://dev.splunk.com/view/SP-CAAADP6 One of the recommendati...
by opticsplanet Path Finder in Splunk Search 02-12-2013
0 5
0
5
rick_harrison
I have a JSON format log file. When this is ingested by a single server installation of splunk (4.3.4), fields are c...
by rick_harrison New Member in Splunk Search 02-12-2013
0 1
0
1
Sqig
Hi. Some of our more ... enthusiastic ... users have been scheduling great big searches far too close together and f...
by Sqig Path Finder in Splunk Search 02-11-2013
0 1
0
1
handygecko
I'm new to splunk and I'm still struggling to grasp how it works. I uploaded data from a simple csv file. Data is as ...
by handygecko Explorer in Splunk Search 02-11-2013
0 3
0
3
Xe03kfp
This is what I have ( 2222222 dest_port="*") OR (1111111 src_port="*") | eval disconnect_time=if(match(_raw,"222222...
by Xe03kfp Path Finder in Splunk Search 02-11-2013
1 17
1
17
splunk_learner
Hi, I have a log Audit:[timestamp=01-31-2013 11:51:21.164,user=admin,action=search,info=granted REST: /search/jobs/1...
by splunk_learner Explorer in Splunk Search 02-11-2013
1 6
1
6
cmak
I am looking for a fast way to retrieve all the values for a single field. I have been doing this index=my_index| to...
by cmak Contributor in Splunk Search 02-11-2013
0 3
0
3
sridharanreddy
I am find few challenges to configure LDAP. Please help me out with this error?
by sridharanreddy Explorer in Splunk Search 02-11-2013
0 3
0
3
stephan_berger
Hello Splunk Community, I have a question regarding this query (excerpt from the great splunk book): earliest...
by stephan_berger Explorer in Splunk Search 02-10-2013
0 9
0
9
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...