Splunk Search

Splunk Search
Community Activity
RVDowning
I need to perform a search that extracts user ids from unformatted log lines where the user id would be extracted by ...
by RVDowning Contributor in Splunk Search 08-16-2012
1 2
1
2
fresned
Hi, My log contains entries as shown below: 5:12:08.100 PM | activateServerlocked | tid:2552 | serverI...
by fresned Path Finder in Splunk Search 08-16-2012
1 4
1
4
paulyreid
Hi I have a CSV input file that has some null values. I'm using fillnull value=NULL to make these appear in the sear...
by paulyreid New Member in Splunk Search 08-16-2012
0 1
0
1
jangid
Whats wrong in my xml? <fieldset autoRun="true"> <input type="time" searchWhenChanged="true"> <d...
by jangid Builder in Splunk Search 08-16-2012
1 2
1
2
aniketb
Hi, I have a daily error report for failed login. Its very easy one: 'user not found | append [search \"invalid pas...
by aniketb Path Finder in Splunk Search 08-16-2012
1 1
1
1
zachvida
This plus the rest of the script work as expected !/usr/bin/env python import splunk.Intersplunk I need to use th...
by zachvida Path Finder in Splunk Search 08-16-2012
0 1
0
1
Jochen_1987
I have 2 questions: Is it possible to aggregate some values of a field into one value?? For example I have in the fie...
by Jochen_1987 Explorer in Splunk Search 08-16-2012
0 3
0
3
tuxford
Hello Lets say you timechart with span=1h and within that hour you have 10000 requests that you need to calculate th...
by tuxford Path Finder in Splunk Search 08-16-2012
0 3
0
3
jangid
How Do I display default search app in my app? http://mjserver:8000/en-US/app/search/dashboard_live Within my app I...
by jangid Builder in Splunk Search 08-16-2012
0 1
0
1
atelesca
Hello, I would like to know if it is possible to save a chart as an image. I read on one answer that there should be ...
by atelesca Explorer in Splunk Search 08-16-2012
1 1
1
1
mark
Hi, I assume this has been asked several times before, but I haven’t found a good discussion on it… What are the ho...
by mark Path Finder in Splunk Search 08-15-2012
1 1
1
1
mark
Hi, We have a distributed environment with 2 search heads in a pool (for LB and HA) running v4.3.0 (upgrading shortl...
by mark Path Finder in Splunk Search 08-15-2012
1 1
1
1
egrignon
Hello Splunk Users I m trying to get an average response time per IP for a few sites I m monitoring. | stats value...
by egrignon Explorer in Splunk Search 08-15-2012
0 2
0
2
j666gak
Hello, I am having issues when Splunk is reading an XML file. I need Splunk to know that a transaction starts with ...
by j666gak Communicator in Splunk Search 08-15-2012
0 5
0
5
Genti
So reading the documentation on http://www.splunk.com/base/Documentation/latest/Developer/RESTSearch#Search_ID it see...
by Genti Splunk Employee Splunk Employee in Splunk Search 08-15-2012
0 2
0
2
jangid
How to display a chart with raw data e.g. mysearch | table MyCount | timechart MyCount or mysearch | table MyCount ...
by jangid Builder in Splunk Search 08-15-2012
1 2
1
2
nirt
Hi, I have created a timechart of 2 time ranges: index="XXXX" host="XXXX" earliest=-0w@w latest=+1w@w XXXX | eval Re...
by nirt Path Finder in Splunk Search 08-15-2012
0 3
0
3
rblalock
I have too many machines (almost 500) logging to a single index. I want to create a new index (which I know how to d...
by rblalock New Member in Splunk Search 08-15-2012
0 3
0
3
imosquera
I had a query that was working perfectly until recently where it started cutting off the last 4 days of data just for...
by imosquera Explorer in Splunk Search 08-15-2012
0 1
0
1
cburr2012
Hello Splunkers, I've seen a few questions and one blog post about this topic. Goal: Look at the trend of one user...
by cburr2012 Path Finder in Splunk Search 08-15-2012
1 2
1
2
m_hunger
Hi, I am trying to extract an ID from a search and append the results using the extracted ID. Example: Search: host...
by m_hunger New Member in Splunk Search 08-15-2012
0 4
0
4
MrWh1t3
So i'm curious, I installed the Windows rsyslog agent on a windows box because I like the idea of being able to use S...
by MrWh1t3 Path Finder in Splunk Search 08-15-2012
0 4
0
4
jiseruk
The Explore Data button is disabled in my project. I uploaded a CSV file with data, but I can't explote it. It says "...
by jiseruk New Member in Splunk Search 08-15-2012
0 2
0
2
AccentureQBETA
I have the following search: index="cms_test_1" [|inputlookup Stacked_Worse12.csv | rename FullURL as cs_uri | field...
by AccentureQBETA Path Finder in Splunk Search 08-15-2012
0 2
0
2
stucky101
Gurus I just started playing with splunk and after reading the alert howto it looks like a real-time/rolling window a...
by stucky101 Engager in Splunk Search 08-14-2012
0 8
0
8
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...