Splunk Search

Splunk Search
Community Activity
j666gak
Hello, I am having issues when Splunk is reading an XML file. I need Splunk to know that a transaction starts with ...
by j666gak Communicator in Splunk Search 08-15-2012
0 5
0
5
Genti
So reading the documentation on http://www.splunk.com/base/Documentation/latest/Developer/RESTSearch#Search_ID it see...
by Genti Splunk Employee Splunk Employee in Splunk Search 08-15-2012
0 2
0
2
jangid
How to display a chart with raw data e.g. mysearch | table MyCount | timechart MyCount or mysearch | table MyCount ...
by jangid Builder in Splunk Search 08-15-2012
1 2
1
2
nirt
Hi, I have created a timechart of 2 time ranges: index="XXXX" host="XXXX" earliest=-0w@w latest=+1w@w XXXX | eval Re...
by nirt Path Finder in Splunk Search 08-15-2012
0 3
0
3
rblalock
I have too many machines (almost 500) logging to a single index. I want to create a new index (which I know how to d...
by rblalock New Member in Splunk Search 08-15-2012
0 3
0
3
imosquera
I had a query that was working perfectly until recently where it started cutting off the last 4 days of data just for...
by imosquera Explorer in Splunk Search 08-15-2012
0 1
0
1
cburr2012
Hello Splunkers, I've seen a few questions and one blog post about this topic. Goal: Look at the trend of one user...
by cburr2012 Path Finder in Splunk Search 08-15-2012
1 2
1
2
m_hunger
Hi, I am trying to extract an ID from a search and append the results using the extracted ID. Example: Search: host...
by m_hunger New Member in Splunk Search 08-15-2012
0 4
0
4
MrWh1t3
So i'm curious, I installed the Windows rsyslog agent on a windows box because I like the idea of being able to use S...
by MrWh1t3 Path Finder in Splunk Search 08-15-2012
0 4
0
4
jiseruk
The Explore Data button is disabled in my project. I uploaded a CSV file with data, but I can't explote it. It says "...
by jiseruk New Member in Splunk Search 08-15-2012
0 2
0
2
AccentureQBETA
I have the following search: index="cms_test_1" [|inputlookup Stacked_Worse12.csv | rename FullURL as cs_uri | field...
by AccentureQBETA Path Finder in Splunk Search 08-15-2012
0 2
0
2
stucky101
Gurus I just started playing with splunk and after reading the alert howto it looks like a real-time/rolling window a...
by stucky101 Engager in Splunk Search 08-14-2012
0 8
0
8
qodeninja
I'd like to get a list of sessions each with their page views and session durations like this: Session12324 | Sessio...
by qodeninja Explorer in Splunk Search 08-14-2012
1 5
1
5
gnovak
I have a search where I am trying to take the totals and turn them into a percentage. sourcetype="EPPWEB" source="/o...
by gnovak Builder in Splunk Search 08-14-2012
0 8
0
8
nielsenr
So here's my problem, I'm using splunk to index some server logs. I am using the splunk javasdk to do a search and ge...
by nielsenr New Member in Splunk Search 08-14-2012
0 2
0
2
Michael_Schyma1
How do i remove the first line from event type when importing a log file into our enviornment? I thought it would be ...
by Michael_Schyma1 Contributor in Splunk Search 08-14-2012
0 3
0
3
jangid
my search is based on the eventtype="someevents" and now I want to extract field and I want to restrict my fields ext...
by jangid Builder in Splunk Search 08-14-2012
1 4
1
4
hharvey
I need to create a field extraction that extracts the first 20 characters ONLY from an error log; I've got the regex ...
by hharvey Explorer in Splunk Search 08-14-2012
0 3
0
3
tstanley
I want to end up with a filed called mapi_err that contains a MAPI error string. I am looking at the third line in a ...
by tstanley Engager in Splunk Search 08-14-2012
1 2
1
2
socteam
Hi Guys, Can we use Splunk for configuration management? I know that splunk can be used for integrity checking of fi...
by socteam New Member in Splunk Search 08-14-2012
0 1
0
1
glitchcowboy
I've got a script that checks various settings on every host and returns data to the indexer via universal forwarder....
by glitchcowboy Path Finder in Splunk Search 08-13-2012
0 3
0
3
alnapp
Hi, Sure I'm missing something obvious, but: Raw data has field "SourceName" which is looks like this: api.internal....
by alnapp Engager in Splunk Search 08-13-2012
0 1
0
1
DamianS
Hi all, I have 2 different log file types, 1 of which I currently need to add fields in search time and the other al...
by DamianS Explorer in Splunk Search 08-13-2012
0 4
0
4
brettcave
It would be great if "eval" could do multiple evaluations in a single command, in a similar way that "stats" can: st...
by brettcave Builder in Splunk Search 08-13-2012
4 2
4
2
jangid
What is the difference between REPORT- and FIELD-?
by jangid Builder in Splunk Search 08-13-2012
3 8
3
8
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...