Splunk Search

Splunk Search
Community Activity
cphair
I would like to use k-means clustering on a field (k=2) and then discard the search results in the cluster with the s...
by cphair Builder in Splunk Search 10-08-2012
1 2
1
2
1234testtest
Hi - I want to display the cpu, mem statistics (avg, min, max) for a specified duration - last 4 hours, 24 hours etc....
by 1234testtest Path Finder in Splunk Search 10-08-2012
0 1
0
1
Guven
Dear all, I try to search for log-files in following time-range: Start-time: 12/25/2012:0:0:0 Finish-time: 12/26/20...
by Guven New Member in Splunk Search 10-08-2012
0 1
0
1
responsys_cm
The Linux audit daemon can track the execution of individual commands. Each part of the command is stored in a separ...
by responsys_cm Builder in Splunk Search 10-08-2012
0 1
0
1
splunkpoornima
I want to calculate the timedifference between the start and the Completion of the task which are in different lines....
by splunkpoornima Communicator in Splunk Search 10-08-2012
0 1
0
1
mha_it_network
Hi, The following is what we have. 1 x Forwarder(Heavy Forwarder)1 x Indexer1 x Search Head We are attempting to f...
by mha_it_network New Member in Splunk Search 10-08-2012
0 2
0
2
ma_anand1984
This is a followup question to http://splunk-base.splunk.com/answers/61123/how-can-i-search-in-logs-for-mutiple-vau...
by ma_anand1984 Contributor in Splunk Search 10-08-2012
1 1
1
1
strive
Hi, I am a newbie, just started working on splunk. I need your help. I received application configuration files and...
by strive Influencer in Splunk Search 10-08-2012
0 2
0
2
crazyeva
XXX | streamstats count | eval _time=count | sort _time | transaction maxspan=5s I found "tranaction" is still using...
by crazyeva Contributor in Splunk Search 10-08-2012
0 3
0
3
Takajian
I want to index log4j syslog from remote log4j server, but I noticed the data is not plain text, splunk can not index...
by Takajian Builder in Splunk Search 10-08-2012
0 1
0
1
mehal
Hello All, I need a help in indexing whole DIRECTORY to index data from files residing in directory. My directory is...
by mehal New Member in Splunk Search 10-08-2012
0 5
0
5
rturk
Hi Splunkers/Splunkettes, To begin, I'm sorry about the length of the question. Scenario I have a large amount of ...
by rturk Builder in Splunk Search 10-07-2012
0 1
0
1
dennywebb
i have logs coming in as CSV files, but sometimes junk data is truncated on the front by the system generating them, ...
by dennywebb Path Finder in Splunk Search 10-06-2012
1 6
1
6
aalborz
I'm trying to view Windows Logs. I installed the universal forwarder on the local Windows PC. I configured only for l...
by aalborz New Member in Splunk Search 10-05-2012
0 3
0
3
bjwarner
Hi there, I am trying to use splunk to understand the alerts that are coming out of our system. We get approx 35K a...
by bjwarner Engager in Splunk Search 10-05-2012
0 4
0
4
likesplunk
Hi All, Any inputs on the following requirement is appreciated. I need to know the count of request of typ...
by likesplunk New Member in Splunk Search 10-05-2012
0 8
0
8
lpolo
I have some information I need to extract from the source field but I cannot do it for all cases: Example: I have the...
by lpolo Motivator in Splunk Search 10-05-2012
0 2
0
2
frank_zhang
Hi, My indexer receives the following network traffic stats in which value 3 and 4 of sys_report_id field indicates ...
by frank_zhang Path Finder in Splunk Search 10-05-2012
0 2
0
2
NK_1
Using Splunk 4.1.7 [searchstring...] earliest=09/23/2012:09:00:00 latest=09/23/2012:10:00:00 AccountID | transaction...
by NK_1 Path Finder in Splunk Search 10-05-2012
0 2
0
2
hortonew
Is there a way to highlight a new entry that comes in through real-time search (change background/font color temporar...
by hortonew Builder in Splunk Search 10-05-2012
0 2
0
2
brettcave
Is it possible to create a transaction on an eval field after passing through stats? ... | stats sum(total) as total...
by brettcave Builder in Splunk Search 10-05-2012
0 3
0
3
dmrhodes101
Hi all I have the following in a log file that we're passing to Splunk: Log for 03/07/2012 06:47:43 The date is be...
by dmrhodes101 Explorer in Splunk Search 10-05-2012
0 8
0
8
kennmunklarsen
Why does Splunk put this in front af alle extractions: (?i) I can't find documentation for what it does
by kennmunklarsen New Member in Splunk Search 10-04-2012
0 1
0
1
V_at_Splunk
(The 2-dimension restriction is not mentioned in http://www.splunk.com/base/Documentation/latest/SearchReference/Char...
by V_at_Splunk Splunk Employee Splunk Employee in Splunk Search 10-04-2012
1 7
1
7
kore
Hi there, Hoping someone can point me in the right direction. I'm trying to parse greppable nmap (*.gnmap) outputs f...
by kore Explorer in Splunk Search 10-04-2012
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...