Splunk Search

Splunk Search
Community Activity
yoeljacobsen
I'm looking for an efficient way to retrieve the single most recent event from each of about 2000 sources. It seems ...
by yoeljacobsen Explorer in Splunk Search 07-12-2012
2 9
2
9
KarunK
Hi All, I am trying to extract the timestamps from the log file name (source) and then find how many logs are produc...
by KarunK Contributor in Splunk Search 07-12-2012
1 3
1
3
cheeseng
I am doing a internal audit for splunk log, the query is following index="_audit" action = edit_user NOT "search" |...
by cheeseng New Member in Splunk Search 07-12-2012
0 1
0
1
hortone
I am collecting syslogs from the network (UDP 514) and they are all coming in as sourcetype=syslog. I did not see a c...
by hortone New Member in Splunk Search 07-11-2012
0 1
0
1
bshamsian
I am having problems with an extracted field not showing in the search results. I am indexing a log file that among ...
by bshamsian Path Finder in Splunk Search 07-11-2012
0 1
0
1
Anthony_Hou
Hi, We have an issue about receiving email tells "The search that you sent to the background has completed" We recei...
by Anthony_Hou Path Finder in Splunk Search 07-11-2012
0 2
0
2
bojanz
I'm having a field that is being specifically indexed (and not extracted during search time). The following configura...
by bojanz Communicator in Splunk Search 07-11-2012
0 7
0
7
splunk_zen
From the latest docs, this is the simplest prerequisite to build a bubble chart, "1. A single series structure that ...
by splunk_zen Builder in Splunk Search 07-11-2012
1 6
1
6
jangid
What is the best option for field extraction? my log file contain some data separated with # and I want to convert t...
by jangid Builder in Splunk Search 07-11-2012
0 8
0
8
paulf
Hi, Is it possible to perform a more than 1x lookup on a number of fields? I have 2x IP fields, one is a source ip a...
by paulf Explorer in Splunk Search 07-11-2012
1 2
1
2
rturk
Greetings Splunkers! I posed this question in the IRC channel, but thought I'd put it in here as well just in case a...
by rturk Builder in Splunk Search 07-11-2012
0 11
0
11
rakesh_498115
Hi, I need to calucalte the time difference between two events in splunk..using the transaction command ....how can ...
by rakesh_498115 Motivator in Splunk Search 07-11-2012
0 1
0
1
mzammit
Hi, I'm trying to implement a search which raises alerts based on events with unique, but as of yet unknown keys wit...
by mzammit New Member in Splunk Search 07-11-2012
0 1
0
1
josknigh
Is it possible to use the rex command to do a dynamic key=value extraction where they key is a also a regular express...
by josknigh Engager in Splunk Search 07-10-2012
1 1
1
1
kbantoft
I've got data coming in, looking like: Jul 10 21:29:33 74.117.145.130 sdpd[3899]: [sdpd.INFO]: ext_host_stat is 173....
by kbantoft Engager in Splunk Search 07-10-2012
0 1
0
1
klaurean
I have been trying to make a new field using IFX by making a search and selecting "extract fields" and then inputting...
by klaurean Engager in Splunk Search 07-10-2012
0 3
0
3
asingla
I am using a join search command. What I noticed is that join only takes one row from the sub search result for the j...
by asingla Communicator in Splunk Search 07-10-2012
0 1
0
1
marywill
I want to use the outlier function but am having trouble identifying the sources as outlier, this is what I have so f...
by marywill Engager in Splunk Search 07-10-2012
0 1
0
1
benjiminhugh
I came across a very strange problem: I have a transformation field: [record] FORMAT = event_type::Record_DVR dvr_sta...
by benjiminhugh Explorer in Splunk Search 07-10-2012
0 1
0
1
mship
Splunk server is running 4.3.2, installed UF 4.3.2 on winXP embedded client and was getting the following error "Mes...
by mship Path Finder in Splunk Search 07-10-2012
0 1
0
1
karthik7411
hi, i have already uploaded a csv lookup file to the splunk indexer. Now i want to add more entries to the csv file. ...
by karthik7411 New Member in Splunk Search 07-10-2012
0 1
0
1
asarolkar
When I execute this search, I get all events from organization : Barclays that contains records for 2012. index="lo...
by asarolkar Builder in Splunk Search 07-10-2012
0 4
0
4
rroberts
Not sure of the cause of this error? # (2013, 'Lost connection to MySQL server during query') Have verified UID and P...
by rroberts Splunk Employee Splunk Employee in Splunk Search 07-10-2012
0 2
0
2
Michael_Schyma1
sourcetype="MFApps" | addtotals fieldname=sum |top limit=1 sum | fields + count | rename count AS "Number of Events...
by Michael_Schyma1 Contributor in Splunk Search 07-10-2012
0 1
0
1
cphair
I have the feeling this should be easy, but I can't figure it out. I want to determine a host's percent uptime over ...
by cphair Builder in Splunk Search 07-10-2012
0 4
0
4
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Solution Authors