Thread Info | |||||
---|---|---|---|---|---|
I'm dealing with a stream of monitoring data with good and bad events, but no text to distinguish them apart. Good vs...
by
Jason
Motivator
in
Splunk Search
10-11-2011
|
0
|
5
| |||
I have spent some time reading through the UI examples App and have attempted to duplicate a basic drill down action ...
by
jerrad
Path Finder
in
Splunk Search
10-11-2011
|
0
|
4
| |||
This is my search...
index=webproxy
| regex user=".+a"
| top 100 user
| eval user_name=substr(user,1,5)
I ha...
by
mcbradford
Contributor
in
Splunk Search
10-11-2011
|
1
|
1
| |||
Is it possible to dynamically calculate the RHS of a search comparison?
I'm looking to use Splunk to do latency me...
by
esp
New Member
in
Splunk Search
09-16-2010
|
0
|
5
| |||
I have a extremely slow search and I cannot understand why it is so. I'd appreciate any pointers.
Hardware is not ...
by
erga00
Path Finder
in
Splunk Search
10-10-2011
|
1
|
1
| |||
I have configured a dashboard with 28 boxes which change from green to red depending on the parameters of the saved s...
by
itsomana
Path Finder
in
Splunk Search
10-10-2011
|
0
|
1
| |||
Hi all,
I have two searches here, which are nearly the same (5 Events more at one of them). Is it somehow possible...
by
Katsche
Path Finder
in
Splunk Search
10-10-2011
|
0
|
6
| |||
I've been tinkering with a custom search command that uses win32com.client. When I try to invoke my search command I ...
by
Marinus
Communicator
in
Splunk Search
09-26-2011
|
1
|
3
| |||
I am a complete splunk newbie and I'm trying to find information on how powerful the searches and reports can be. Let...
by
motzgogh
Engager
in
Splunk Search
10-10-2011
|
0
|
1
| |||
I've got a splunk query like the following:
...| timechart span=10m max(CurrentAnonymousUsers) by ComputerName
...
by
dang
Path Finder
in
Splunk Search
10-07-2011
|
2
|
1
| |||
I'm trying to put into practice what I saw in Michael Wilde's Regex video with regards to making rex searches persist...
by
jlixfeld
Path Finder
in
Splunk Search
10-06-2011
|
0
|
8
| |||
I tried to use subsearch to find the 2nd last synchronization event by using the following:
synchronization [searc...
by
myli12
Path Finder
in
Splunk Search
10-07-2011
|
1
|
1
| |||
My results are like...
src_ip src_geo count
55.89.12.11 US 25
I want the result ...
by
mcbradford
Contributor
in
Splunk Search
10-07-2011
|
1
|
3
| |||
Why can't use subsearch in case command?
index="01_firewall" sourcetype="01_firewall" [search index=webping | rena...
by
ilove275
Path Finder
in
Splunk Search
10-06-2011
|
5
|
4
| |||
Hi,
I've a simple query as shown below to display the column chart over time.
MY_QUERY:
index=my_index sourcety...
by
freephoneid
Path Finder
in
Splunk Search
10-04-2011
|
1
|
1
| |||
I've following data in my summary index by time which runs in time range -1d@d to @d every day @ midnight:
09-01-1...
by
freephoneid
Path Finder
in
Splunk Search
10-06-2011
|
0
|
1
| |||
Hey everyone, I am working on an issue right now and I'm running into a problem with my understanding of how splunk w...
by
msarro
Builder
in
Splunk Search
08-25-2011
|
3
|
4
| |||
I am wondering if we can change a search on a dashboard based upon the time range selected.
EG: I have a hidden se...
by
jdunlea_splunk
Splunk Employee
in
Splunk Search
10-05-2011
|
1
|
2
| |||
Hi,
Currently, I'm getting number of users logged in last 24 hrs as below...
index=myindex sourcetype="my_log" ...
by
freephoneid
Path Finder
in
Splunk Search
10-04-2011
|
0
|
5
| |||
Trying to click on an item in the legend and have a new search come up based on item clicked.
Here is my current w...
by
talbot7
Path Finder
in
Splunk Search
10-04-2011
|
0
|
1
| |||
I am using Exchange 2007 SP3 and it appears that my logs are flowing to the Splunk Instance. Some of the searches and...
by
donwant
Explorer
in
Splunk Search
09-27-2011
|
0
|
1
| |||
Hi, all.
I was asked to get Exchange logs from an Exchange 2010 cluster going to Splunk. I've installed a forwarde...
by
tgiles
Path Finder
in
Splunk Search
09-02-2011
|
1
|
2
| |||
I have a vendor log file that has numeric codes for the field names (i.e. E-1, E-710, etc). The vendor also provides ...
by
cgl
Explorer
in
Splunk Search
10-03-2011
|
2
|
6
| |||
I want to extract two adjacent events, i.e., the first one with keyword "synchronization" and the event immediately f...
by
myli12
Path Finder
in
Splunk Search
10-04-2011
|
0
|
1
| |||
I trying to rename sourcetype for this regex but won't work but when i remove the rename = httpd-access its work?
...
by
catty
Engager
in
Splunk Search
10-03-2011
|
0
|
2
|