Splunk Search

Splunk Search
Community Activity
jevenson
I'm trying to get the top 10 uri's from our IIS logs, and get the average time taken on each of those. I can't quite ...
by jevenson Path Finder in Splunk Search 10-11-2012
0 2
0
2
lpolo
Hi, Any idea how to get the result set of the last sample without using head. Let's say we have a summary index with...
by lpolo Motivator in Splunk Search 10-11-2012
0 2
0
2
whod81
Is it possible to attach two searches to a single report? SEARCH ONE (daily report by host, time ranged -1d@d to @d)...
by whod81 Explorer in Splunk Search 10-11-2012
1 3
1
3
EStallcup
I'm having trouble getting a flash timeline to populate with the results of a saved query in a view I'm trying to mak...
by EStallcup Path Finder in Splunk Search 10-11-2012
0 2
0
2
watsm10
I've got a field named "User" which holds the names of all the users of our service. Some users have similar names an...
by watsm10 Communicator in Splunk Search 10-11-2012
1 2
1
2
Michael_Schyma1
Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: ...
by Michael_Schyma1 Contributor in Splunk Search 10-11-2012
0 2
0
2
efo
Hi, We have gotten quite a complex search request, which we are not sure if is possible at all. If the application l...
by efo Engager in Splunk Search 10-11-2012
0 6
0
6
chca
I need to determine peek bandwidth from IIS logs. The logs have both the amount of bytes sent and the time taken (in ...
by chca Path Finder in Splunk Search 10-11-2012
1 3
1
3
ranjyotiprakash
I am running two different searches to get the total number of successful Logins and Unsuccessful Logins. The searche...
by ranjyotiprakash Communicator in Splunk Search 10-10-2012
1 3
1
3
glasserd17
I'm trying to extract the "user.name" field from the XML below (in pastebin). However, I can't seem to write an spath...
by glasserd17 New Member in Splunk Search 10-10-2012
0 1
0
1
fere
Hi, I have the following search which returns the avg number of "EnterPlace" actions in a session (a transaction = a ...
by fere Path Finder in Splunk Search 10-10-2012
0 1
0
1
kjohnsonzenimax
I have inherited a fairly undocumented splunk deployment which looks as follows (splunk 4.3.2): Forwarders -> 2x Hea...
by kjohnsonzenimax Explorer in Splunk Search 10-10-2012
1 3
1
3
mznikkip
I am using ASP.NET with C# to call a search job in Splunk. When I run the search in Splunk, it returns results but th...
by mznikkip Engager in Splunk Search 10-10-2012
0 9
0
9
jangid
My logs are coming from different time zone, that is ahead 4.5 hrs. I know I can't specify the time zone in Universa...
by jangid Builder in Splunk Search 10-10-2012
0 1
0
1
mihelic
While performing a search for log messages that contain the string "URIBL_" I got a lot less hits than by grepping th...
by mihelic Path Finder in Splunk Search 10-10-2012
0 2
0
2
acidkewpie
I'm using this query to graph how many web requests are being logged per second: index="bigip_ltm" (event=HTTP_REQUE...
by acidkewpie Path Finder in Splunk Search 10-10-2012
0 2
0
2
disha
Right now I have my search like this my search..| stats list(EventID), list(Time), list(EventDescription) by CustID ...
by disha Contributor in Splunk Search 10-10-2012
2 8
2
8
guilhem
Hi everyone! I'm a new splunk user, and I have a quesion about chart formatting. Here is the results of a search I'v...
by guilhem Contributor in Splunk Search 10-10-2012
0 8
0
8
RKB1923
Hi, beginner here having problems trying to write a query. In my data, I have an event that records when an app is r...
by RKB1923 Engager in Splunk Search 10-09-2012
1 1
1
1
dasari
I am able to execute the below search command using rex and retrieve the output successfully index=xyz | rex field=_...
by dasari Engager in Splunk Search 10-09-2012
1 3
1
3
romantercero
Hi, I'm trying to extract the cluster name of my servers using the host name. So we have something like host=cluste...
by romantercero Path Finder in Splunk Search 10-09-2012
0 7
0
7
daniel333
Sorry, I don't use Splunk much so I am sure this is an easy search for you all. I am trying to get a complete list ...
by daniel333 Builder in Splunk Search 10-09-2012
0 1
0
1
adityapavan18
I have a event similiar to one below: Server Status - ServerName - RUNNING JMS Queue - ServerName : Module1!JMSServ...
by adityapavan18 Contributor in Splunk Search 10-09-2012
0 3
0
3
MHibbin
Hi Splunkbase, I was just wondering how I would go about highlighting a certain value in my table on a dashboard (e....
by MHibbin Influencer in Splunk Search 10-09-2012
3 9
3
9
splunkatl
In our logs I will get field values like err=0 err=1 . . . err=49 I am able to get the results when run search again...
by splunkatl Path Finder in Splunk Search 10-09-2012
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...