Splunk Search

Splunk Search
Community Activity
talbot7
We have two environments, prod1 and prod2. At any given point in time one is production and the other is staging. W...
by talbot7 Path Finder in Splunk Search 07-26-2012
1 9
1
9
wang
I have a timechart that plots response time by source: index=myidx duration | timechart avg(duration) by source Beca...
by wang Path Finder in Splunk Search 07-26-2012
0 3
0
3
shangshin
Hi, Our web server is fronted by a load balancer with 3 different VIPs I am using the search string below to see the...
by shangshin Builder in Splunk Search 07-26-2012
0 2
0
2
Michael_Schyma1
New Policy: Success Failure + + Logon/Logoff + - Object Access + - Privilege Use + + ...
by Michael_Schyma1 Contributor in Splunk Search 07-26-2012
0 8
0
8
jambajuice
Assume I have an event with the following field: Name="Microsoft Office Outlook MUI (English) 2007" Assume I have a...
by jambajuice Communicator in Splunk Search 07-26-2012
1 4
1
4
Michael_Schyma1
Here is the raw data: 07/26/2012 08:03:39 AM LogName=System SourceName=USER32 EventCode=1073 EventType=2 Type=Warnin...
by Michael_Schyma1 Contributor in Splunk Search 07-26-2012
0 5
0
5
NeonFlash
I want to list all the file names in a log file in Splunk whose name ends with, "_bn.txt" Let's say the field name i...
by NeonFlash Explorer in Splunk Search 07-26-2012
0 3
0
3
Srw12
I am having a SimpleResultsTable which allows to collect all information what I need. Whereas, I would like to chan...
by Srw12 Explorer in Splunk Search 07-26-2012
0 3
0
3
dbryan
I'm developing an app that will run on in an distributed environment in production, with a search head, an indexer an...
by dbryan Path Finder in Splunk Search 07-25-2012
1 1
1
1
sonicZ
We have a NFS mount on a EMC NS 480 and about enable dedup to see if we can reduce the size of a cold storage mount p...
by sonicZ Contributor in Splunk Search 07-25-2012
0 2
0
2
splunk_gs
i have a field called "Status" which contains "fresh" or "stale" which is distinct via host I want to do a distinct c...
by splunk_gs Explorer in Splunk Search 07-25-2012
0 1
0
1
gnovak
I want to move my defaultdb from one indexer to another. The data will be put in an index called "OLD" on the new in...
by gnovak Builder in Splunk Search 07-25-2012
0 1
0
1
tpowell12
I have a search for failed login attempts and am running a count based on EventCodes per host. ("EventCode=4625" OR...
by tpowell12 Explorer in Splunk Search 07-25-2012
0 6
0
6
hjs123
Hi. I want to collect for the ms-sql data. but, the following error occurs. I do not know the cause. What's wrong ? ...
by hjs123 New Member in Splunk Search 07-25-2012
0 1
0
1
krussell101
I would desperately like to use this application but it has out-smarted me. Is there a video or some other sort of t...
by krussell101 Path Finder in Splunk Search 07-25-2012
0 4
0
4
splunker_123
Hi I've a question regarding the log file sent by forwarders to indexers Assume , a log file called abc.log is inde...
by splunker_123 Path Finder in Splunk Search 07-25-2012
0 3
0
3
cburr2012
Hello, After some time spent Googling/Splunking yesterday, I could not find a unique solution to my problem. Goal:...
by cburr2012 Path Finder in Splunk Search 07-25-2012
2 6
2
6
dadi
hi guys, I want to use eventstats->perc function. This function is form perc*10(x) in order to get the 10 percentile ...
by dadi Path Finder in Splunk Search 07-25-2012
0 1
0
1
crazyeva
Such as "* | transaction field" (field=1,2,3,4,5,6) means exactly the same field will be found But i want something l...
by crazyeva Contributor in Splunk Search 07-25-2012
0 10
0
10
bumbumndb
My data same : Jul 24 19:49:59 mydomain.com httpd[9058]: [error] [client 10.254.53.13] Directory index forbidden by...
by bumbumndb New Member in Splunk Search 07-25-2012
0 4
0
4
trilogy
Splunk was shut down for a few weeks on my server, and now I am missing events from my log files for the time it was ...
by trilogy New Member in Splunk Search 07-24-2012
0 4
0
4
Michael_Schyma1
07/20/2012 05:19:38 AM LogName=Security SourceName=Microsoft Windows security auditing. EventCode=4726 EventType=0 Ty...
by Michael_Schyma1 Contributor in Splunk Search 07-24-2012
0 12
0
12
arjangoos
I want to create a timechart line graph based on: total kb per source over time. Now I have: index="_internal" sourc...
by arjangoos Path Finder in Splunk Search 07-24-2012
0 3
0
3
hartfoml
I am using timechart to build a graph for the last 7 days. the chart by default uses _time as the format for the Gra...
by hartfoml Motivator in Splunk Search 07-24-2012
0 1
0
1
angelo82
Good Morning I'm looking for collect in Splunk Search all nights event logs between 08:00 PM and 07:00 AM i've done ...
by angelo82 Explorer in Splunk Search 07-24-2012
0 2
0
2
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...