| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        Hi all, 
  Another question... I have two extracted fields: "MB" and "site". 
  I wish to do the following, over a pe...
        
       
         
           by 
           
                
                    
                        aaronnicoli
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-30-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I'm able to pull the events fine with the config below, but the GUIDs aren't being expanded. I've tried evt_resolve_a...
        
       
         
           by 
           
                
                    
                        hughkelley
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-08-2011
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Okay so, 
  I have a field, "basedomain". This contains a huge list of data such as: 
  google.com
facebook.com
googl...
        
       
         
           by 
           
                
                    
                        aaronnicoli
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-30-2012
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Hi . 
  I have a scheduled search which runs for every 5 min . How do i save these results in a csv file ? when using...
        
       
         
           by 
           
                
                    
                        rakesh_498115
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               08-30-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have a field called 'err_msg' this field contains a long line which consists of the error as well as the file name ...
        
       
         
           by 
           
                
                    
                        tb5821
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-30-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi, 
  I have written a query which gives me the list of durations of all the transactions.Now i need to calucalte th...
        
       
         
           by 
           
                
                    
                        rakesh_498115
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               08-29-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I was wondering if someone can help me with something I am trying to do. I have two extract fields called metricvalue...
        
       
         
           by 
           
                
                    
                        numetheus
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               08-29-2012
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Is there a way to take a query, run it in the background, save the results to a file, and then reference that file in...
        
       
         
           by 
           
                
                    
                        DTERM
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-28-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Running Splunk 4.2.3 on CentOS 5.3 x64 to capture syslog data sourced from network devices. I needed to enable DNS re...
        
       
         
           by 
           
                
                    
                        johnnybravo
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-08-2011
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I am looking to include the indexTime in my output file and then append that that field to an existing 'CreateTimeSta...
        
       
         
           by 
           
                
                    
                        efelder0
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               05-30-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Hi, 
  Is it possible for Splunk to show ALL days on the x-axis for a timechart? I have a search which returns data f...
        
       
         
           by 
           
                
                    
                        paulf
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-29-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I am testing out replacing LogLogic with Splunk. Right now, we have forwarded the LogLogic messages to a splunk forwa...
        
       
         
           by 
           
                
                    
                        a212830
                    
                
           
             
             
               Champion
             
           
           in
           Splunk Search
           
           
              
               08-22-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I am building a small visual app to assist cyber-security analysts. 
  They have an automated process to identify "SO...
        
       
         
           by 
           
                
                    
                        sdwilkerson
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               06-07-2012
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I have loaded logs and can do the following search: 
  index=cms_cc_logs error
 
  This returns 239 events. 
  If I d...
        
       
         
           by 
           
                
                    
                        AccentureQBETA
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-28-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I need stats on transactions (WAN outages) over a given period - 1 day, for instance - to be grouped by hour. 
  Howe...
        
       
         
           by 
           
                
                    
                        nobillgates
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               08-28-2012
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi there, 
  I have taken the following regex from here... 
  http://splunk-base.splunk.com/answers/9736/revisiting-r...
        
       
         
           by 
           
                
                    
                        aaronnicoli
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-27-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I need to identify how many authorizations (active directory domain logins) per day on average we have per domain con...
        
       
         
           by 
           
                
                    
                        Ellen
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               08-28-2012
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Splunk response time is quite slow when I use the lookup script presented below. The response time of the web service...
        
       
         
           by 
           
                
                    
                        lpolo
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               08-24-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        Hey Guys, Here are a few examples of the logs that we have. I am having trouble grabbing from the last bracket ] to t...
        
       
         
           by 
           
                
                    
                        Michael_Schyma1
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-28-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I forgot my user id and password
        
       
         
           by 
           
                
                    
                        tmfu3hn3
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-28-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi all, I am trying to do the following search: 
  sourcetype=squid 192.168.1.20 | stats sum(bytes_in) as bytes by sr...
        
       
         
           by 
           
                
                    
                        dondky
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-24-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Right now we have a lot of devices reporting syslogs into splunk. I'd really like to be able to search them by hostna...
        
       
         
           by 
           
                
                    
                        yumology
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               04-22-2011
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I'm trying to learn some regex and I was hoping to get the host name from the path when entering a new data source, b...
        
       
         
           by 
           
                
                    
                        skaboy71
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-29-2011
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        hi,  
  it is possible to do a real time search for today?  for the saved searches or reports, we can actually do a @...
        
       
         
           by 
           
                
                    
                        EricksonOng
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               04-24-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hi, 
  I am new to Splunk. I have an environement with devices sending Syslogs and some ESX hosts. I would like check...
        
       
         
           by 
           
                
                    
                        indikaw
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-21-2012
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 |