| rex field=_raw "Message=A user account was.*(?<accaction>.+?)\." 07/19/2012 11:32:19 AM LogName=Security SourceName... by Michael_Schyma1 Contributor in Splunk Search 07-19-2012 0 3 | 0 | 3 | ||
| I have data like this: [2011-04-23T23:59:54-05:00] bannerid=1210 action=view [2011-04-23T23:59:55-05:00] bannerid=12... by opticsplanet Path Finder in Splunk Search 07-19-2012 0 5 | 0 | 5 | ||
| Hi In the support program page: http://www.splunk.com/view/support-programs/SP-CAAACC8 what does "Live Product R... by melonman Motivator in Splunk Search 07-18-2012 1 1 | 1 | 1 | ||
| I have a configuration working perfectly in development in an environment with a single Splunk instance. This is the... by dbryan Path Finder in Splunk Search 07-18-2012 0 2 | 0 | 2 | ||
| Hi all, I'm currently trying to get the case() function working so that for each .csv file I have (which has informa... by Paxxxman Explorer in Splunk Search 07-18-2012 1 4 | 1 | 4 | ||
| I am new to Splunk logging and I have a host name and source that I would like to create an alert for. I want to crea... by rmccaffery New Member in Splunk Search 07-18-2012 0 1 | 0 | 1 | ||
| Now i select two fields A and B , it default set A as x-axis and B as y-axis. But now i want set B as x-axis and A as... by lihongyan_84 Explorer in Splunk Search 07-18-2012 1 3 | 1 | 3 | ||
| I have a custom command that takes in the input from a search command and I would like to make available in that comm... by radu_groupon New Member in Splunk Search 07-18-2012 0 1 | 0 | 1 | ||
| We are looking to create a multi field rex command to capture the following: 1. Firstname Lastname 2. OrgUnit I am... by zindain24 Path Finder in Splunk Search 07-18-2012 0 1 | 0 | 1 | ||
| Hi, Are there any limitations in amount of alias fields or is it a bug in 4.3.2 that fields are randomly aliased? I ... by jagresz Explorer in Splunk Search 07-18-2012 1 1 | 1 | 1 | ||
| Hello everyone. I want to track in real-time the time since the last event occurred. When I do this currently the ti... by matthewcanty Communicator in Splunk Search 07-18-2012 2 2 | 2 | 2 | ||
| I'm trying to add several lines of XML to a multi-valued field. The data looks like: <EXPLT> <REF><... by responsys_cm Builder in Splunk Search 07-18-2012 0 1 | 0 | 1 | ||
| Hi,I'm also confusing about the retention policy. I want to keep some indexes for 90 days. Now I'm doing some test,wh... by jichen Explorer in Splunk Search 07-17-2012 0 4 | 0 | 4 | ||
| I need to extract fields from a set of results with inconsistent formatting. I think this would be easy for a regex p... by beaunewcomb Communicator in Splunk Search 07-17-2012 0 6 | 0 | 6 | ||
| Hi, I've a search where I need to know the time boundaries of the search and use it to further filter results of the ... by dadi Path Finder in Splunk Search 07-17-2012 1 2 | 1 | 2 | ||
| index="Server" (CategoryString="Account Management" OR TaskCategory="Security Group Management" ) (Message="Security ... by Michael_Schyma1 Contributor in Splunk Search 07-17-2012 0 10 | 0 | 10 | ||
| Hello, I currently have a search that runs to show me the last time all my hosts checked in with Splunk. However, I... by kholleran Communicator in Splunk Search 07-17-2012 0 1 | 0 | 1 | ||
| I am trying to calculate a weighted concurrency across 3 different event types. Each of these event types has a sing... by myandow Path Finder in Splunk Search 07-17-2012 0 1 | 0 | 1 | ||
| I'm currently loading some localized CSV-files into Splunk which contains numbers formatted in a localized format (co... by martindalum Engager in Splunk Search 07-17-2012 3 1 | 3 | 1 | ||
| Hi, Does anyone know if it is possible to do a realtime search with an offset? The data that comes in has a delay of... by Stefan_van_de_R Explorer in Splunk Search 07-17-2012 0 2 | 0 | 2 | ||
| Hi All, I am currently trying to perform some monitoring, and am having a bit of trouble with the Splunk search engi... by iTUBS New Member in Splunk Search 07-17-2012 0 1 | 0 | 1 | ||
| index=hig `sourcetype="MainframeApps" |stats sum(count)|top limit=0 app_id app_name | fields + count, total_count, ... by Michael_Schyma1 Contributor in Splunk Search 07-17-2012 0 3 | 0 | 3 | ||
| Hello, I am trying to pull out some information from a syslog. We don't have the money to purchase a Defense Center f... by MrWh1t3 Path Finder in Splunk Search 07-16-2012 1 3 | 1 | 3 | ||
| Splunk is not removing commented out fields beginning with a "#" in indexed IIS logs. Any assistance would be greatly... by lspringer Path Finder in Splunk Search 07-16-2012 0 5 | 0 | 5 | ||
| I have a field defined in a transform. The field appears to work fine in a chart, whatever, but to put it in a field ... by mmattek Path Finder in Splunk Search 07-16-2012 0 4 | 0 | 4 |