Splunk Search

Splunk Search
Community Activity
xvxt006
Hi, I am brand new to splunk, sorry if i am asking very basic questions. i have data in the below format (I have put ...
by xvxt006 Contributor in Splunk Search 09-27-2012
0 5
0
5
timbCFCA
I'm putting together a search which needs to cross correlate two data sources as well as run a nested search in order...
by timbCFCA Path Finder in Splunk Search 09-27-2012
0 1
0
1
john
Hi, I am trying to create a chart on the basis of difference of two fields same time on the right side it should sho...
by john Communicator in Splunk Search 09-27-2012
0 3
0
3
ajaysingh3
8/27/12 10:24:04.000 AM server=Test and status=Up host=test1 8/27/12 10:24:04.000 AM server=test1 and status=Up host...
by ajaysingh3 Explorer in Splunk Search 09-27-2012
1 8
1
8
yhemaraj
I am rookie here. I have a log of type "2e 00000008 M 2050 nodemgr 09/10/21 20:01:11.860361 NODEMGR: Successfully ...
by yhemaraj Engager in Splunk Search 09-26-2012
0 1
0
1
asingla
I have a subsearch which is returning two fields and I am succesfully able to use that in the outer search for the eq...
by asingla Communicator in Splunk Search 09-26-2012
1 6
1
6
dominiquevocat
I have a script which collects the ldap stats of a series of ldap hosts and forward the values to splunk. Now natura...
by SplunkTrust SplunkTrust in Splunk Search 09-26-2012
1 8
1
8
sysprg1
I have transactions being logged to Splunk, but I get multiple messages per transaction. We are in the middle tier an...
by sysprg1 Explorer in Splunk Search 09-26-2012
0 2
0
2
auntyem
I asked a few weeks ago how to get the total duration of my search timeframe and was told to use addinfo. Got it work...
by auntyem Explorer in Splunk Search 09-25-2012
0 1
0
1
gnovak
I've been going around in circles on this all day and at this point figured I would post my question here: sourcetyp...
by gnovak Builder in Splunk Search 09-25-2012
0 3
0
3
chrismorris
How do I get timeColumnName to read as "July"? It needs to be dynamic. Keying off of the eval or something similar....
by chrismorris Explorer in Splunk Search 09-25-2012
2 1
2
1
ajaykulkarni
Hi All, I am using Microsoft's Log Parser tool with which I can query my IIS logs. Now I have a query to select diff...
by ajaykulkarni Engager in Splunk Search 09-25-2012
0 2
0
2
kjycls
application.js value = Splunk.util.getParameter("name"); localStorage.setItem("name",value); I saved parameter val...
by kjycls Engager in Splunk Search 09-24-2012
0 3
0
3
danurag
Hi I have a batch file that executes a sqlserver query using sqlcmd. The contents of the batch file are: sqlcmd -i ...
by danurag Explorer in Splunk Search 09-24-2012
1 7
1
7
acontarciego
Hello, I have records that look like this: 2012-09-24T18:31:38: ^^ AAA ^^ BBB ^^ CCC ^^^ DDD ^^^ EEE The records ge...
by acontarciego Explorer in Splunk Search 09-24-2012
0 1
0
1
kogane
I'm trying to come up with a query that shows me the earliest (oldest) event in each index on every server that I hav...
by kogane Path Finder in Splunk Search 09-24-2012
0 1
0
1
DTERM
The following search works fine in the Splunk search: index=mydata | rex "\s+IP\s+(?\d+.\d+.\d+.\d+).(?\S+)\s+>\s+(...
by DTERM Contributor in Splunk Search 09-24-2012
0 2
0
2
sachinkum
Hi, Due to some issue the splunk server is not searching any data and getting bellow error. even I am not able to tel...
by sachinkum New Member in Splunk Search 09-24-2012
0 1
0
1
john
Hi , I am trying to track who all using splunk and ip address of there system.I found this query index=_audit action...
by john Communicator in Splunk Search 09-24-2012
0 8
0
8
tskimball
I have a dedicated index for syslogs that I would like to add a 'static field' to: MonFunc=sysmsgs ### Add to all ...
by tskimball New Member in Splunk Search 09-21-2012
0 5
0
5
the_wolverine
I'm using events from 2 sourcetypes to determine whether a transaction is complete. Quite simply, if there are 2 eve...
by the_wolverine Champion in Splunk Search 09-21-2012
0 6
0
6
tadb
We have several applications that we monitor and have written dashboards for. We would like to have one lookup table ...
by tadb New Member in Splunk Search 09-21-2012
0 6
0
6
john
Hi, User want to see 100 events after a particular event or String eg Id=987. I have used transaction for that.But a...
by john Communicator in Splunk Search 09-21-2012
0 2
0
2
cpowell
I have two different sources that I need to find and return all matching instances of a field. Unfortunately, the fie...
by cpowell New Member in Splunk Search 09-21-2012
0 3
0
3
pkeller
If I have a lookup table formatted like this: lookup_host,os host1,linux host2,linux host3,sunos And say I'm sen...
by pkeller Contributor in Splunk Search 09-21-2012
1 6
1
6
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors