Splunk Search

Splunk Search
Community Activity
rturk
Greetings Splunkers! I posed this question in the IRC channel, but thought I'd put it in here as well just in case a...
by rturk Builder in Splunk Search 07-11-2012
0 11
0
11
rakesh_498115
Hi, I need to calucalte the time difference between two events in splunk..using the transaction command ....how can ...
by rakesh_498115 Motivator in Splunk Search 07-11-2012
0 1
0
1
mzammit
Hi, I'm trying to implement a search which raises alerts based on events with unique, but as of yet unknown keys wit...
by mzammit New Member in Splunk Search 07-11-2012
0 1
0
1
josknigh
Is it possible to use the rex command to do a dynamic key=value extraction where they key is a also a regular express...
by josknigh Engager in Splunk Search 07-10-2012
1 1
1
1
kbantoft
I've got data coming in, looking like: Jul 10 21:29:33 74.117.145.130 sdpd[3899]: [sdpd.INFO]: ext_host_stat is 173....
by kbantoft Engager in Splunk Search 07-10-2012
0 1
0
1
klaurean
I have been trying to make a new field using IFX by making a search and selecting "extract fields" and then inputting...
by klaurean Engager in Splunk Search 07-10-2012
0 3
0
3
asingla
I am using a join search command. What I noticed is that join only takes one row from the sub search result for the j...
by asingla Communicator in Splunk Search 07-10-2012
0 1
0
1
marywill
I want to use the outlier function but am having trouble identifying the sources as outlier, this is what I have so f...
by marywill Engager in Splunk Search 07-10-2012
0 1
0
1
benjiminhugh
I came across a very strange problem: I have a transformation field: [record] FORMAT = event_type::Record_DVR dvr_sta...
by benjiminhugh Explorer in Splunk Search 07-10-2012
0 1
0
1
mship
Splunk server is running 4.3.2, installed UF 4.3.2 on winXP embedded client and was getting the following error "Mes...
by mship Path Finder in Splunk Search 07-10-2012
0 1
0
1
karthik7411
hi, i have already uploaded a csv lookup file to the splunk indexer. Now i want to add more entries to the csv file. ...
by karthik7411 New Member in Splunk Search 07-10-2012
0 1
0
1
asarolkar
When I execute this search, I get all events from organization : Barclays that contains records for 2012. index="lo...
by asarolkar Builder in Splunk Search 07-10-2012
0 4
0
4
rroberts
Not sure of the cause of this error? # (2013, 'Lost connection to MySQL server during query') Have verified UID and P...
by rroberts Splunk Employee Splunk Employee in Splunk Search 07-10-2012
0 2
0
2
Michael_Schyma1
sourcetype="MFApps" | addtotals fieldname=sum |top limit=1 sum | fields + count | rename count AS "Number of Events...
by Michael_Schyma1 Contributor in Splunk Search 07-10-2012
0 1
0
1
cphair
I have the feeling this should be easy, but I can't figure it out. I want to determine a host's percent uptime over ...
by cphair Builder in Splunk Search 07-10-2012
0 4
0
4
Michael_Schyma1
Is there a way to use the top function that will list all of the fields (like setting it equal to infinity) that I am...
by Michael_Schyma1 Contributor in Splunk Search 07-10-2012
0 1
0
1
splunk_zen
How can I correctly get a (time, causes, count) collums search from the following input data example? EXECUTION_...
by splunk_zen Builder in Splunk Search 07-10-2012
0 13
0
13
dbryan
Hello, I'm trying to build a Python custom search command. The command is run after a transaction, and adds values c...
by dbryan Path Finder in Splunk Search 07-09-2012
1 2
1
2
asarolkar
I have log that looks like this: 2012-02-23 09:25:21 VShellSSH2 sftp 108660 172.59.56.8 62386 NESTLE - C:\SFTP\NESTL...
by asarolkar Builder in Splunk Search 07-09-2012
1 1
1
1
adoshi
I would like to get an average of a any given value for a time range say 7:00 PM to 8:00 PM over last 30 days. Would...
by adoshi Explorer in Splunk Search 07-09-2012
0 2
0
2
mataharry
in 4.1.6 On the UI, I can run a search with a sub search in the condition. index="_internal" source="log" OR [ searc...
by mataharry Communicator in Splunk Search 07-09-2012
1 2
1
2
jumper4000
We pull in all the security event logs using WMI. However, it's pulling in WAY too much data. Is there a way to limit...
by jumper4000 Explorer in Splunk Search 07-09-2012
0 1
0
1
sune43
How can I compute a frequency distribution chart? For example I want to take the time_taken from my IIS web-server ...
by sune43 Engager in Splunk Search 07-09-2012
0 1
0
1
subhadipc
I wanted to see a detailed analysis of IIS logs in W3C (which is being fed to Splunk). I could not get all the availa...
by subhadipc Explorer in Splunk Search 07-07-2012
0 1
0
1
kjetil
Hi. I have a Checkpoint firewall managed by my WAN provider, and would like to be able to do more with the logs than...
by kjetil New Member in Splunk Search 07-06-2012
0 6
0
6
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...