Splunk Search

Splunk Search
Community Activity
fitchjo
I see that this is something that others have had a problem with, but I need help adapting the regex to pull multiple...
by fitchjo New Member in Splunk Search 01-02-2013
0 3
0
3
robK123
Every day I run a search that finds any users who have had at least 5 failed login attempts source="secure" sshd "pa...
by robK123 Explorer in Splunk Search 01-02-2013
0 1
0
1
robK123
Hello, I have a search that covers 7 days of data showing when users failed to login 5 or more times but I want to k...
by robK123 Explorer in Splunk Search 01-02-2013
0 3
0
3
dadi
hi guys, I've this following command that works perfectly in search query, but doesn't work in macro: .... | lookup ...
by dadi Path Finder in Splunk Search 01-02-2013
1 9
1
9
robK123
I have this search I want to only display results for when the sum(failures) is higher than 4 how can I do this? (in...
by robK123 Explorer in Splunk Search 01-02-2013
0 2
0
2
pramodkumar
Hi Team, Am facing one issue, my requriement is to continously monitor the file and want to pick only the latest rec...
by pramodkumar Path Finder in Splunk Search 01-02-2013
0 3
0
3
sumanth_isac
Dear all, I am not able to remove old log files from my search. I tried all possibilities. I tried 1. ./splunk sto...
by sumanth_isac Path Finder in Splunk Search 01-01-2013
0 11
0
11
wellsajs
Hi, Has any one been able to work out howto incorporate the exclusion of public holidays in searches. I am trying t...
by wellsajs Explorer in Splunk Search 01-01-2013
0 3
0
3
xli_splunk
We need to know the env variables used to construct home path.
by xli_splunk Splunk Employee Splunk Employee in Splunk Search 12-31-2012
0 1
0
1
yap
I've encountered with this finding at Packetstorm website. May I know whether Splunk already verified and acknowledge...
by yap Explorer in Splunk Search 12-31-2012
0 2
0
2
jmaschle
i have several years of daily event data in a sqlserver table i would like to stack and chart and get some good stats...
by jmaschle New Member in Splunk Search 12-31-2012
0 6
0
6
Splunk_U
Can you please help me out to merge these two search strings index=os sourcetype=vmstat | multikv fields memUsedPc...
by Splunk_U Path Finder in Splunk Search 12-31-2012
0 5
0
5
pramodkumar
Hi Team, I have successfully indexed the data but it is not getting dispalyed in Search, dont know which settings i ...
by pramodkumar Path Finder in Splunk Search 12-31-2012
2 5
2
5
smolcj
hi, i want to change the fontsize of a single result table in application.css. i did a homework and i tried .Si...
by smolcj Builder in Splunk Search 12-31-2012
1 6
1
6
Aakanksha
Is it possible to display weekly as well as daily data on the same chart? Eg. Three weeks data with sub-scale of 7 da...
by Aakanksha Path Finder in Splunk Search 12-30-2012
0 3
0
3
Volto
I have a search that gives me the event counts for each host every hour and compares that count against a running ave...
by Volto Path Finder in Splunk Search 12-29-2012
0 1
0
1
a212830
Hi, I want to create a report on syslog messages received from the same file, which come from different types of dev...
by a212830 Champion in Splunk Search 12-28-2012
0 1
0
1
chablist
I'm trying to output the reliability for a channel over a time period. My sample log file looks like this: channel...
by chablist New Member in Splunk Search 12-28-2012
0 3
0
3
msmapper
Hi all, I would like to create a search that would only look at a certain minute or few seconds on the half hour ove...
by msmapper Path Finder in Splunk Search 12-28-2012
0 3
0
3
pjc
I'm fairly new to Splunk queries, so apologies if this is overly simplistic. I have a query looking at apache logs i...
by pjc Engager in Splunk Search 12-28-2012
1 4
1
4
xvxt006
Hi, i am using the below search query to get uri commands from the access logs. But result includes page resources as...
by xvxt006 Contributor in Splunk Search 12-28-2012
0 3
0
3
thiliphk
How do we determine the need for increasing diskspace on /Splunkidx. Do we have any formula ?
by thiliphk New Member in Splunk Search 12-28-2012
0 1
0
1
robK123
I have this search: (index=infrastructure-os OR index=main) sudo "incorrect password attempt*" |rex field=_raw "sudo...
by robK123 Explorer in Splunk Search 12-28-2012
0 4
0
4
sriva6
Hi, I have application logs which read something like this Blah bla blah File Descriptor: 1234 Blah bla blah File De...
by sriva6 New Member in Splunk Search 12-28-2012
0 4
0
4
splunk_learner
Hi, I want search query to read my index name and sourcetype name from config file.So that if there is any change in ...
by splunk_learner Explorer in Splunk Search 12-28-2012
0 3
0
3
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors