Splunk Search

Splunk Search
Community Activity
trangadmin
Hi guys, I am building a search where I want to report on location based on source IP address. For example within ou...
by trangadmin New Member in Splunk Search 10-08-2012
0 2
0
2
cphair
I would like to use k-means clustering on a field (k=2) and then discard the search results in the cluster with the s...
by cphair Builder in Splunk Search 10-08-2012
1 2
1
2
1234testtest
Hi - I want to display the cpu, mem statistics (avg, min, max) for a specified duration - last 4 hours, 24 hours etc....
by 1234testtest Path Finder in Splunk Search 10-08-2012
0 1
0
1
Guven
Dear all, I try to search for log-files in following time-range: Start-time: 12/25/2012:0:0:0 Finish-time: 12/26/20...
by Guven New Member in Splunk Search 10-08-2012
0 1
0
1
responsys_cm
The Linux audit daemon can track the execution of individual commands. Each part of the command is stored in a separ...
by responsys_cm Builder in Splunk Search 10-08-2012
0 1
0
1
splunkpoornima
I want to calculate the timedifference between the start and the Completion of the task which are in different lines....
by splunkpoornima Communicator in Splunk Search 10-08-2012
0 1
0
1
mha_it_network
Hi, The following is what we have. 1 x Forwarder(Heavy Forwarder)1 x Indexer1 x Search Head We are attempting to f...
by mha_it_network New Member in Splunk Search 10-08-2012
0 2
0
2
ma_anand1984
This is a followup question to http://splunk-base.splunk.com/answers/61123/how-can-i-search-in-logs-for-mutiple-vau...
by ma_anand1984 Contributor in Splunk Search 10-08-2012
1 1
1
1
strive
Hi, I am a newbie, just started working on splunk. I need your help. I received application configuration files and...
by strive Influencer in Splunk Search 10-08-2012
0 2
0
2
crazyeva
XXX | streamstats count | eval _time=count | sort _time | transaction maxspan=5s I found "tranaction" is still using...
by crazyeva Contributor in Splunk Search 10-08-2012
0 3
0
3
Takajian
I want to index log4j syslog from remote log4j server, but I noticed the data is not plain text, splunk can not index...
by Takajian Builder in Splunk Search 10-08-2012
0 1
0
1
mehal
Hello All, I need a help in indexing whole DIRECTORY to index data from files residing in directory. My directory is...
by mehal New Member in Splunk Search 10-08-2012
0 5
0
5
rturk
Hi Splunkers/Splunkettes, To begin, I'm sorry about the length of the question. Scenario I have a large amount of ...
by rturk Builder in Splunk Search 10-07-2012
0 1
0
1
dennywebb
i have logs coming in as CSV files, but sometimes junk data is truncated on the front by the system generating them, ...
by dennywebb Path Finder in Splunk Search 10-06-2012
1 6
1
6
aalborz
I'm trying to view Windows Logs. I installed the universal forwarder on the local Windows PC. I configured only for l...
by aalborz New Member in Splunk Search 10-05-2012
0 3
0
3
bjwarner
Hi there, I am trying to use splunk to understand the alerts that are coming out of our system. We get approx 35K a...
by bjwarner Engager in Splunk Search 10-05-2012
0 4
0
4
likesplunk
Hi All, Any inputs on the following requirement is appreciated. I need to know the count of request of typ...
by likesplunk New Member in Splunk Search 10-05-2012
0 8
0
8
lpolo
I have some information I need to extract from the source field but I cannot do it for all cases: Example: I have the...
by lpolo Motivator in Splunk Search 10-05-2012
0 2
0
2
frank_zhang
Hi, My indexer receives the following network traffic stats in which value 3 and 4 of sys_report_id field indicates ...
by frank_zhang Path Finder in Splunk Search 10-05-2012
0 2
0
2
NK_1
Using Splunk 4.1.7 [searchstring...] earliest=09/23/2012:09:00:00 latest=09/23/2012:10:00:00 AccountID | transaction...
by NK_1 Path Finder in Splunk Search 10-05-2012
0 2
0
2
hortonew
Is there a way to highlight a new entry that comes in through real-time search (change background/font color temporar...
by hortonew Builder in Splunk Search 10-05-2012
0 2
0
2
brettcave
Is it possible to create a transaction on an eval field after passing through stats? ... | stats sum(total) as total...
by brettcave Builder in Splunk Search 10-05-2012
0 3
0
3
dmrhodes101
Hi all I have the following in a log file that we're passing to Splunk: Log for 03/07/2012 06:47:43 The date is be...
by dmrhodes101 Explorer in Splunk Search 10-05-2012
0 8
0
8
kennmunklarsen
Why does Splunk put this in front af alle extractions: (?i) I can't find documentation for what it does
by kennmunklarsen New Member in Splunk Search 10-04-2012
0 1
0
1
V_at_Splunk
(The 2-dimension restriction is not mentioned in http://www.splunk.com/base/Documentation/latest/SearchReference/Char...
by V_at_Splunk Splunk Employee Splunk Employee in Splunk Search 10-04-2012
1 7
1
7
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...