Splunk Search

Splunk Search
Community Activity
john
Hi, User want to see 100 events after a particular event or String eg Id=987. I have used transaction for that.But a...
by john Communicator in Splunk Search 09-21-2012
0 2
0
2
cpowell
I have two different sources that I need to find and return all matching instances of a field. Unfortunately, the fie...
by cpowell New Member in Splunk Search 09-21-2012
0 3
0
3
pkeller
If I have a lookup table formatted like this: lookup_host,os host1,linux host2,linux host3,sunos And say I'm sen...
by pkeller Contributor in Splunk Search 09-21-2012
1 6
1
6
atelesca
Hello, I have the following output of a script: fcs1 0 0 0 1 0 1 0 1 1 1 fcs2 0 0 0 1 1 1 0 0 0 0 fcs3 0 0 0 1 1 1 1...
by atelesca Explorer in Splunk Search 09-21-2012
1 5
1
5
iKate
Can one make contents of all views that are used in application? It really makes sence to have such information on th...
by iKate Builder in Splunk Search 09-21-2012
0 3
0
3
crazyeva
I want to append two (or more) search results by event number search1: # _raw 1 a 2 b 3 c search2: # _raw 1...
by crazyeva Contributor in Splunk Search 09-21-2012
0 2
0
2
paulf
Hi, I am collecting some disk performance stats via a Splunk Forwarder from a Windows Server. I am now trying to gr...
by paulf Explorer in Splunk Search 09-20-2012
0 3
0
3
coleman07
I have the following search string which I use to create a line chart: ....| timechart span=1d sum(kb) by series T...
by coleman07 Path Finder in Splunk Search 09-20-2012
0 3
0
3
sonicZ
I am currently matching a list of "bad ips" with a search such as this index=someindex NOT uri="/dot_clear.gif" [| i...
by sonicZ Contributor in Splunk Search 09-20-2012
0 3
0
3
pbunce1
We have the following events (dots represent other events for clarity) and would like to extract on a per process bas...
by pbunce1 Explorer in Splunk Search 09-20-2012
1 1
1
1
Andrew_Banman
Hi there folks, I am building a custom alerts dashboard based on a search that returns a table (see demo screen belo...
by Andrew_Banman Explorer in Splunk Search 09-20-2012
0 5
0
5
jtm7x2
We have our dnsdebuglog turned on and I want to create a summary search of # of events in descending order. Results ...
by jtm7x2 Explorer in Splunk Search 09-20-2012
0 1
0
1
jameshgibson
I am using a transaction to get the start/end/duration of jobs. This gives me back about 200 events. Something like: ...
by jameshgibson Path Finder in Splunk Search 09-20-2012
2 4
2
4
Lucas_K
I have a search that outputs a table similar to the following. Month starting count 1-Sep-11 21424533 1-Oct-11 ...
by Lucas_K Motivator in Splunk Search 09-19-2012
0 4
0
4
ninadmnaik
I want to extract exception, key and message from a raw event in our logs. The event looks like: EXCEPTION - : Type...
by ninadmnaik Explorer in Splunk Search 09-19-2012
0 1
0
1
wj
May I know if there is any size limit of the csv file when performing a lookup? I'm doing a lookup to a csv with aro...
by wj Engager in Splunk Search 09-19-2012
0 4
0
4
tpowell12
I have a Windows event below. This regex, (?ms)^\s+User Name:\s+(?\S+), is used to extract the value from the User Na...
by tpowell12 Explorer in Splunk Search 09-19-2012
0 7
0
7
Jason
I have a need to count up both failures and successes on a chart, split them by something, and then compare these val...
by Jason Motivator in Splunk Search 09-19-2012
4 3
4
3
RVDowning
In the following abbreviated search, is there anyway to have drilldown work properly when using an addtotals or when ...
by RVDowning Contributor in Splunk Search 09-19-2012
1 5
1
5
kkao00
Hi, I run a real time query in splunk search during load testing, and it comes out like this: http://picpaste.com/p...
by kkao00 Engager in Splunk Search 09-19-2012
0 4
0
4
dspracklen
It doesn't matter if the answer is in CSS or Advanced XML or both. I'm not even certain Advanced XML has access to pr...
by dspracklen Path Finder in Splunk Search 09-19-2012
1 4
1
4
lauj
Hi, I'm new to splunk and kinda stuck, so any help would be greatly appreciated. What I'm trying to do is take the ...
by lauj Observer in Splunk Search 09-18-2012
0 1
0
1
wrangler2x
I created a search that is part of a view called dhcp-MAC-lookup. When you pull up this view you are prompted to ent...
by wrangler2x Motivator in Splunk Search 09-18-2012
3 8
3
8
a212830
Hi, I noticed a whole bunch of these in my S.O.S. Not sure what they mean - the filesystems are fine. Is somebody ru...
by a212830 Champion in Splunk Search 09-18-2012
2 4
2
4
paul_hignutt
I have a customer that we did an extended PoC for on an old small server (3 months+). That customer purchased Splunk>...
by paul_hignutt Engager in Splunk Search 09-18-2012
1 1
1
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...