Splunk Search

Splunk Search
Community Activity
chicodeme
Splunk runs as root so it has access to monitor anything on the system without managing those permissions. I ran thi...
by chicodeme Communicator in Splunk Search 07-06-2012
1 3
1
3
kjetil
Hi. I've just started with Splunk and need help setting up file input. The log files looks like the below. A header ...
by kjetil New Member in Splunk Search 07-06-2012
0 1
0
1
Michael_Schyma1
I am trying to get a running total for the number of events field. I can not get a column that adds up every 'number ...
by Michael_Schyma1 Contributor in Splunk Search 07-05-2012
0 13
0
13
terryloar
I get the following error: "Error in 'inputlookup' command: This command must be the first command of a search." F...
by terryloar Path Finder in Splunk Search 07-05-2012
1 1
1
1
gregwilliams
I have a universal forwarder pulling in a log file from a linux server. It has been working just fine up until the o...
by gregwilliams Path Finder in Splunk Search 07-05-2012
0 6
0
6
jangid
How to create a field from _raw field? my _raw field have some common pattern e.g. I0703 15:07:20.627351 3108 logg...
by jangid Builder in Splunk Search 07-05-2012
0 6
0
6
DTERM
This is a sample snippet from a very large log file: lastOccurrence=2012/07/05 13:56:14|firstOccurrence=2012/06/18 1...
by DTERM Contributor in Splunk Search 07-05-2012
0 1
0
1
jangid
I want to extract processid from my log and here is query eventtype=statustrace | regex _raw="^[IEWF]" | rex field=_...
by jangid Builder in Splunk Search 07-05-2012
0 5
0
5
LauraBre
hello, I have this following log in Splunk: RS:D2T,PAN:1/1,Req:fr18126,User:a169805,TKN:g00e29dfd883effecba,H:W6008...
by LauraBre Communicator in Splunk Search 07-05-2012
0 2
0
2
Yarsa
Hi this is a simple case query I ran on splunk ... | eval country=case(country="US","USA",country="CA","CA","rest") ...
by Yarsa Path Finder in Splunk Search 07-05-2012
0 1
0
1
dungpv
Hi Everyone, I have one question. I have excuted searching and created alert data in splunk. I saw alert on tab alert...
by dungpv Explorer in Splunk Search 07-04-2012
0 4
0
4
msamant
We have installed Splunk recently and forwarding our Cisco FW logs through syslog. We have also installed the Splunk ...
by msamant New Member in Splunk Search 07-04-2012
0 6
0
6
iKate
Hello Let's say there are several Excel tables and it is needed to make graphs using its data in Splunk dashboard. H...
by iKate Builder in Splunk Search 07-04-2012
0 3
0
3
joshhenderson
Hi, What I'm attempting to do is monitor a specific set of processes on a machine. For this, I am obtaining data fro...
by joshhenderson Explorer in Splunk Search 07-03-2012
1 2
1
2
atreece
I have a set of events that are generated with locations in the form of xloc and yloc. (z, or height, is irrelevant) ...
by atreece Path Finder in Splunk Search 07-03-2012
0 1
0
1
queme
I am looking to pull all domains from dns logs and get a count of how many unique sub-domains that were requested of ...
by queme Explorer in Splunk Search 07-03-2012
0 5
0
5
asarolkar
I am trying to filter out events whenever the "healthcheck" url below appears. 2012-07-02 15:29:52,190 DEBUG [http-0...
by asarolkar Builder in Splunk Search 07-03-2012
0 7
0
7
gloudou
Hello, I would like to know if it's possible with Splunk to know the connection time of each user by day or month fo...
by gloudou Engager in Splunk Search 07-03-2012
0 3
0
3
klaurean
Hey everyone! I just started using Splunk and am having trouble finding a way to have a line graph with 3 separate li...
by klaurean Engager in Splunk Search 07-02-2012
0 2
0
2
asarolkar
We have a certain logfile (tied to sourcetype: syslog) inbound from a forwarder which has THIS line in it: 2012-07-...
by asarolkar Builder in Splunk Search 07-02-2012
1 2
1
2
responsys_cm
I have a table with the following fields: table qualys_id,exploit_cve_id,exploit_name,exploit_source,exploit_url Do...
by responsys_cm Builder in Splunk Search 07-02-2012
0 1
0
1
timmy13
I am just using some test data that I generated to try to get lookups to work. First, my log (completely manually ge...
by timmy13 Communicator in Splunk Search 07-02-2012
0 4
0
4
responsys_cm
I would like to use a field in my event data for the _time field. It looks like: <LAST_UPDATE><![CDATA[2012-06-14T2...
by responsys_cm Builder in Splunk Search 07-01-2012
0 3
0
3
rakesh_498115
Hi.. I have a created a simple form which consists of a textbox to take the search key input to perform the search.I...
by rakesh_498115 Motivator in Splunk Search 07-01-2012
0 3
0
3
responsys_cm
I have a field in some of our events called "action". I have blacklisted IPs that we've seen a number of attacks fro...
by responsys_cm Builder in Splunk Search 06-29-2012
0 1
0
1
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...