Discussions
Thread Info | |||||
---|---|---|---|---|---|
Sorry i am a noob to regex and splunk regex especially.
Regex to extarct all that is between the two single quotes...
by
r999
Path Finder
in
Splunk Search
09-01-2012
|
0
|
1
| |||
I have a transaction that crosses multiple applications. I have a eventguid that I use with the transaction command t...
by
Jeremiah
Motivator
in
Splunk Search
08-31-2012
|
1
|
1
| |||
Hi there,
I have a log that prefaces each message with either "Sending data on connection" or "Received data on co...
by
branfarm
Explorer
in
Splunk Search
08-31-2012
|
0
|
3
| |||
I have entries in my log which can have the same username but can have multiple machine_types. For example, user "jac...
by
HXCaine
Path Finder
in
Splunk Search
08-31-2012
|
0
|
1
| |||
Hi. We recently upgraded from a 4.2 installation to 4.3.3 and a report that includes the _time field (which used to c...
by
Sqig
Path Finder
in
Splunk Search
08-31-2012
|
2
|
3
| |||
Imagine I have the following data:
msg uid AB_test1 AB_test2
click 1 A A
reqst ...
by
mikesherov
Engager
in
Splunk Search
08-31-2012
|
1
|
2
| |||
Hi,
I want to show next 100 events after a first occurence of particular string. eg:Iam searching a string id:9045...
by
john
Communicator
in
Splunk Search
08-30-2012
|
0
|
2
| |||
Hi all,
Another question... I have two extracted fields: "MB" and "site".
I wish to do the following, over a pe...
by
aaronnicoli
Path Finder
in
Splunk Search
08-30-2012
|
0
|
3
| |||
I'm able to pull the events fine with the config below, but the GUIDs aren't being expanded. I've tried evt_resolve_a...
by
hughkelley
Path Finder
in
Splunk Search
04-08-2011
|
2
|
6
| |||
Okay so,
I have a field, "basedomain". This contains a huge list of data such as:
google.com
facebook.com
googl...
by
aaronnicoli
Path Finder
in
Splunk Search
08-30-2012
|
1
|
5
| |||
Hi .
I have a scheduled search which runs for every 5 min . How do i save these results in a csv file ? when using...
by
rakesh_498115
Motivator
in
Splunk Search
08-30-2012
|
0
|
2
| |||
I have a field called 'err_msg' this field contains a long line which consists of the error as well as the file name ...
by
tb5821
Communicator
in
Splunk Search
08-30-2012
|
0
|
2
| |||
Hi,
I have written a query which gives me the list of durations of all the transactions.Now i need to calucalte th...
by
rakesh_498115
Motivator
in
Splunk Search
08-29-2012
|
0
|
6
| |||
I was wondering if someone can help me with something I am trying to do. I have two extract fields called metricvalue...
by
numetheus
Engager
in
Splunk Search
08-29-2012
|
1
|
1
| |||
Is there a way to take a query, run it in the background, save the results to a file, and then reference that file in...
by
DTERM
Contributor
in
Splunk Search
08-28-2012
|
0
|
4
| |||
Running Splunk 4.2.3 on CentOS 5.3 x64 to capture syslog data sourced from network devices. I needed to enable DNS re...
by
johnnybravo
Explorer
in
Splunk Search
10-08-2011
|
0
|
2
| |||
I am looking to include the indexTime in my output file and then append that that field to an existing 'CreateTimeSta...
by
efelder0
Communicator
in
Splunk Search
05-30-2012
|
0
|
2
| |||
Hi,
Is it possible for Splunk to show ALL days on the x-axis for a timechart? I have a search which returns data f...
by
paulf
Explorer
in
Splunk Search
08-29-2012
|
0
|
3
| |||
I am testing out replacing LogLogic with Splunk. Right now, we have forwarded the LogLogic messages to a splunk forwa...
by
a212830
Champion
in
Splunk Search
08-22-2012
|
0
|
6
| |||
I am building a small visual app to assist cyber-security analysts.
They have an automated process to identify "SO...
by
sdwilkerson
Contributor
in
Splunk Search
06-07-2012
|
1
|
5
| |||
I have loaded logs and can do the following search:
index=cms_cc_logs error
This returns 239 events.
If I d...
by
AccentureQBETA
Path Finder
in
Splunk Search
08-28-2012
|
0
|
3
| |||
I need stats on transactions (WAN outages) over a given period - 1 day, for instance - to be grouped by hour.
Howe...
by
nobillgates
Engager
in
Splunk Search
08-28-2012
|
1
|
1
| |||
Hi there,
I have taken the following regex from here...
http://splunk-base.splunk.com/answers/9736/revisiting-r...
by
aaronnicoli
Path Finder
in
Splunk Search
08-27-2012
|
0
|
5
| |||
I need to identify how many authorizations (active directory domain logins) per day on average we have per domain con...
by
Ellen
Splunk Employee
in
Splunk Search
08-28-2012
|
2
|
1
| |||
Splunk response time is quite slow when I use the lookup script presented below. The response time of the web service...
by
lpolo
Motivator
in
Splunk Search
08-24-2012
|
0
|
7
|