Splunk Search

Splunk Search
Community Activity
Michael_Schyma1
rex field=_raw "Message=A user account was.*(?<accaction>.+?)\." 07/19/2012 11:32:19 AM LogName=Security SourceName...
by Michael_Schyma1 Contributor in Splunk Search 07-19-2012
0 3
0
3
opticsplanet
I have data like this: [2011-04-23T23:59:54-05:00] bannerid=1210 action=view [2011-04-23T23:59:55-05:00] bannerid=12...
by opticsplanet Path Finder in Splunk Search 07-19-2012
0 5
0
5
melonman
Hi In the support program page: http://www.splunk.com/view/support-programs/SP-CAAACC8 what does "Live Product R...
by melonman Motivator in Splunk Search 07-18-2012
1 1
1
1
dbryan
I have a configuration working perfectly in development in an environment with a single Splunk instance. This is the...
by dbryan Path Finder in Splunk Search 07-18-2012
0 2
0
2
Paxxxman
Hi all, I'm currently trying to get the case() function working so that for each .csv file I have (which has informa...
by Paxxxman Explorer in Splunk Search 07-18-2012
1 4
1
4
rmccaffery
I am new to Splunk logging and I have a host name and source that I would like to create an alert for. I want to crea...
by rmccaffery New Member in Splunk Search 07-18-2012
0 1
0
1
lihongyan_84
Now i select two fields A and B , it default set A as x-axis and B as y-axis. But now i want set B as x-axis and A as...
by lihongyan_84 Explorer in Splunk Search 07-18-2012
1 3
1
3
radu_groupon
I have a custom command that takes in the input from a search command and I would like to make available in that comm...
by radu_groupon New Member in Splunk Search 07-18-2012
0 1
0
1
zindain24
We are looking to create a multi field rex command to capture the following: 1. Firstname Lastname 2. OrgUnit I am...
by zindain24 Path Finder in Splunk Search 07-18-2012
0 1
0
1
jagresz
Hi, Are there any limitations in amount of alias fields or is it a bug in 4.3.2 that fields are randomly aliased? I ...
by jagresz Explorer in Splunk Search 07-18-2012
1 1
1
1
matthewcanty
Hello everyone. I want to track in real-time the time since the last event occurred. When I do this currently the ti...
by matthewcanty Communicator in Splunk Search 07-18-2012
2 2
2
2
responsys_cm
I'm trying to add several lines of XML to a multi-valued field. The data looks like: <EXPLT> <REF><...
by responsys_cm Builder in Splunk Search 07-18-2012
0 1
0
1
jichen
Hi,I'm also confusing about the retention policy. I want to keep some indexes for 90 days. Now I'm doing some test,wh...
by jichen Explorer in Splunk Search 07-17-2012
0 4
0
4
beaunewcomb
I need to extract fields from a set of results with inconsistent formatting. I think this would be easy for a regex p...
by beaunewcomb Communicator in Splunk Search 07-17-2012
0 6
0
6
dadi
Hi, I've a search where I need to know the time boundaries of the search and use it to further filter results of the ...
by dadi Path Finder in Splunk Search 07-17-2012
1 2
1
2
Michael_Schyma1
index="Server" (CategoryString="Account Management" OR TaskCategory="Security Group Management" ) (Message="Security ...
by Michael_Schyma1 Contributor in Splunk Search 07-17-2012
0 10
0
10
kholleran
Hello, I currently have a search that runs to show me the last time all my hosts checked in with Splunk. However, I...
by kholleran Communicator in Splunk Search 07-17-2012
0 1
0
1
myandow
I am trying to calculate a weighted concurrency across 3 different event types. Each of these event types has a sing...
by myandow Path Finder in Splunk Search 07-17-2012
0 1
0
1
martindalum
I'm currently loading some localized CSV-files into Splunk which contains numbers formatted in a localized format (co...
by martindalum Engager in Splunk Search 07-17-2012
3 1
3
1
Stefan_van_de_R
Hi, Does anyone know if it is possible to do a realtime search with an offset? The data that comes in has a delay of...
by Stefan_van_de_R Explorer in Splunk Search 07-17-2012
0 2
0
2
iTUBS
Hi All, I am currently trying to perform some monitoring, and am having a bit of trouble with the Splunk search engi...
by iTUBS New Member in Splunk Search 07-17-2012
0 1
0
1
Michael_Schyma1
index=hig `sourcetype="MainframeApps" |stats sum(count)|top limit=0 app_id app_name | fields + count, total_count, ...
by Michael_Schyma1 Contributor in Splunk Search 07-17-2012
0 3
0
3
MrWh1t3
Hello, I am trying to pull out some information from a syslog. We don't have the money to purchase a Defense Center f...
by MrWh1t3 Path Finder in Splunk Search 07-16-2012
1 3
1
3
lspringer
Splunk is not removing commented out fields beginning with a "#" in indexed IIS logs. Any assistance would be greatly...
by lspringer Path Finder in Splunk Search 07-16-2012
0 5
0
5
mmattek
I have a field defined in a transform. The field appears to work fine in a chart, whatever, but to put it in a field ...
by mmattek Path Finder in Splunk Search 07-16-2012
0 4
0
4
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...
Top Solution Authors