Splunk Search

Splunk Search
Community Activity
kogane
I'm trying to come up with a query that shows me the earliest (oldest) event in each index on every server that I hav...
by kogane Path Finder in Splunk Search 09-24-2012
0 1
0
1
DTERM
The following search works fine in the Splunk search: index=mydata | rex "\s+IP\s+(?\d+.\d+.\d+.\d+).(?\S+)\s+>\s+(...
by DTERM Contributor in Splunk Search 09-24-2012
0 2
0
2
sachinkum
Hi, Due to some issue the splunk server is not searching any data and getting bellow error. even I am not able to tel...
by sachinkum New Member in Splunk Search 09-24-2012
0 1
0
1
john
Hi , I am trying to track who all using splunk and ip address of there system.I found this query index=_audit action...
by john Communicator in Splunk Search 09-24-2012
0 8
0
8
tskimball
I have a dedicated index for syslogs that I would like to add a 'static field' to: MonFunc=sysmsgs ### Add to all ...
by tskimball New Member in Splunk Search 09-21-2012
0 5
0
5
the_wolverine
I'm using events from 2 sourcetypes to determine whether a transaction is complete. Quite simply, if there are 2 eve...
by the_wolverine Champion in Splunk Search 09-21-2012
0 6
0
6
tadb
We have several applications that we monitor and have written dashboards for. We would like to have one lookup table ...
by tadb New Member in Splunk Search 09-21-2012
0 6
0
6
john
Hi, User want to see 100 events after a particular event or String eg Id=987. I have used transaction for that.But a...
by john Communicator in Splunk Search 09-21-2012
0 2
0
2
cpowell
I have two different sources that I need to find and return all matching instances of a field. Unfortunately, the fie...
by cpowell New Member in Splunk Search 09-21-2012
0 3
0
3
pkeller
If I have a lookup table formatted like this: lookup_host,os host1,linux host2,linux host3,sunos And say I'm sen...
by pkeller Contributor in Splunk Search 09-21-2012
1 6
1
6
atelesca
Hello, I have the following output of a script: fcs1 0 0 0 1 0 1 0 1 1 1 fcs2 0 0 0 1 1 1 0 0 0 0 fcs3 0 0 0 1 1 1 1...
by atelesca Explorer in Splunk Search 09-21-2012
1 5
1
5
iKate
Can one make contents of all views that are used in application? It really makes sence to have such information on th...
by iKate Builder in Splunk Search 09-21-2012
0 3
0
3
crazyeva
I want to append two (or more) search results by event number search1: # _raw 1 a 2 b 3 c search2: # _raw 1...
by crazyeva Contributor in Splunk Search 09-21-2012
0 2
0
2
paulf
Hi, I am collecting some disk performance stats via a Splunk Forwarder from a Windows Server. I am now trying to gr...
by paulf Explorer in Splunk Search 09-20-2012
0 3
0
3
coleman07
I have the following search string which I use to create a line chart: ....| timechart span=1d sum(kb) by series T...
by coleman07 Path Finder in Splunk Search 09-20-2012
0 3
0
3
sonicZ
I am currently matching a list of "bad ips" with a search such as this index=someindex NOT uri="/dot_clear.gif" [| i...
by sonicZ Contributor in Splunk Search 09-20-2012
0 3
0
3
pbunce1
We have the following events (dots represent other events for clarity) and would like to extract on a per process bas...
by pbunce1 Explorer in Splunk Search 09-20-2012
1 1
1
1
Andrew_Banman
Hi there folks, I am building a custom alerts dashboard based on a search that returns a table (see demo screen belo...
by Andrew_Banman Explorer in Splunk Search 09-20-2012
0 5
0
5
jtm7x2
We have our dnsdebuglog turned on and I want to create a summary search of # of events in descending order. Results ...
by jtm7x2 Explorer in Splunk Search 09-20-2012
0 1
0
1
jameshgibson
I am using a transaction to get the start/end/duration of jobs. This gives me back about 200 events. Something like: ...
by jameshgibson Path Finder in Splunk Search 09-20-2012
2 4
2
4
Lucas_K
I have a search that outputs a table similar to the following. Month starting count 1-Sep-11 21424533 1-Oct-11 ...
by Lucas_K Motivator in Splunk Search 09-19-2012
0 4
0
4
ninadmnaik
I want to extract exception, key and message from a raw event in our logs. The event looks like: EXCEPTION - : Type...
by ninadmnaik Explorer in Splunk Search 09-19-2012
0 1
0
1
wj
May I know if there is any size limit of the csv file when performing a lookup? I'm doing a lookup to a csv with aro...
by wj Engager in Splunk Search 09-19-2012
0 4
0
4
tpowell12
I have a Windows event below. This regex, (?ms)^\s+User Name:\s+(?\S+), is used to extract the value from the User Na...
by tpowell12 Explorer in Splunk Search 09-19-2012
0 7
0
7
Jason
I have a need to count up both failures and successes on a chart, split them by something, and then compare these val...
by Jason Motivator in Splunk Search 09-19-2012
4 3
4
3
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors