Splunk Search

Splunk Search
Community Activity
Michael_Schyma1
rex field=_raw "Message=A user account was.*(?<accaction>.+?)\." 07/19/2012 11:32:19 AM LogName=Security SourceName...
by Michael_Schyma1 Contributor in Splunk Search 07-19-2012
0 3
0
3
opticsplanet
I have data like this: [2011-04-23T23:59:54-05:00] bannerid=1210 action=view [2011-04-23T23:59:55-05:00] bannerid=12...
by opticsplanet Path Finder in Splunk Search 07-19-2012
0 5
0
5
melonman
Hi In the support program page: http://www.splunk.com/view/support-programs/SP-CAAACC8 what does "Live Product R...
by melonman Motivator in Splunk Search 07-18-2012
1 1
1
1
dbryan
I have a configuration working perfectly in development in an environment with a single Splunk instance. This is the...
by dbryan Path Finder in Splunk Search 07-18-2012
0 2
0
2
Paxxxman
Hi all, I'm currently trying to get the case() function working so that for each .csv file I have (which has informa...
by Paxxxman Explorer in Splunk Search 07-18-2012
1 4
1
4
rmccaffery
I am new to Splunk logging and I have a host name and source that I would like to create an alert for. I want to crea...
by rmccaffery New Member in Splunk Search 07-18-2012
0 1
0
1
lihongyan_84
Now i select two fields A and B , it default set A as x-axis and B as y-axis. But now i want set B as x-axis and A as...
by lihongyan_84 Explorer in Splunk Search 07-18-2012
1 3
1
3
radu_groupon
I have a custom command that takes in the input from a search command and I would like to make available in that comm...
by radu_groupon New Member in Splunk Search 07-18-2012
0 1
0
1
zindain24
We are looking to create a multi field rex command to capture the following: 1. Firstname Lastname 2. OrgUnit I am...
by zindain24 Path Finder in Splunk Search 07-18-2012
0 1
0
1
jagresz
Hi, Are there any limitations in amount of alias fields or is it a bug in 4.3.2 that fields are randomly aliased? I ...
by jagresz Explorer in Splunk Search 07-18-2012
1 1
1
1
matthewcanty
Hello everyone. I want to track in real-time the time since the last event occurred. When I do this currently the ti...
by matthewcanty Communicator in Splunk Search 07-18-2012
2 2
2
2
responsys_cm
I'm trying to add several lines of XML to a multi-valued field. The data looks like: <EXPLT> <REF><...
by responsys_cm Builder in Splunk Search 07-18-2012
0 1
0
1
jichen
Hi,I'm also confusing about the retention policy. I want to keep some indexes for 90 days. Now I'm doing some test,wh...
by jichen Explorer in Splunk Search 07-17-2012
0 4
0
4
beaunewcomb
I need to extract fields from a set of results with inconsistent formatting. I think this would be easy for a regex p...
by beaunewcomb Communicator in Splunk Search 07-17-2012
0 6
0
6
dadi
Hi, I've a search where I need to know the time boundaries of the search and use it to further filter results of the ...
by dadi Path Finder in Splunk Search 07-17-2012
1 2
1
2
Michael_Schyma1
index="Server" (CategoryString="Account Management" OR TaskCategory="Security Group Management" ) (Message="Security ...
by Michael_Schyma1 Contributor in Splunk Search 07-17-2012
0 10
0
10
kholleran
Hello, I currently have a search that runs to show me the last time all my hosts checked in with Splunk. However, I...
by kholleran Communicator in Splunk Search 07-17-2012
0 1
0
1
myandow
I am trying to calculate a weighted concurrency across 3 different event types. Each of these event types has a sing...
by myandow Path Finder in Splunk Search 07-17-2012
0 1
0
1
martindalum
I'm currently loading some localized CSV-files into Splunk which contains numbers formatted in a localized format (co...
by martindalum Engager in Splunk Search 07-17-2012
3 1
3
1
Stefan_van_de_R
Hi, Does anyone know if it is possible to do a realtime search with an offset? The data that comes in has a delay of...
by Stefan_van_de_R Explorer in Splunk Search 07-17-2012
0 2
0
2
iTUBS
Hi All, I am currently trying to perform some monitoring, and am having a bit of trouble with the Splunk search engi...
by iTUBS New Member in Splunk Search 07-17-2012
0 1
0
1
Michael_Schyma1
index=hig `sourcetype="MainframeApps" |stats sum(count)|top limit=0 app_id app_name | fields + count, total_count, ...
by Michael_Schyma1 Contributor in Splunk Search 07-17-2012
0 3
0
3
MrWh1t3
Hello, I am trying to pull out some information from a syslog. We don't have the money to purchase a Defense Center f...
by MrWh1t3 Path Finder in Splunk Search 07-16-2012
1 3
1
3
lspringer
Splunk is not removing commented out fields beginning with a "#" in indexed IIS logs. Any assistance would be greatly...
by lspringer Path Finder in Splunk Search 07-16-2012
0 5
0
5
mmattek
I have a field defined in a transform. The field appears to work fine in a chart, whatever, but to put it in a field ...
by mmattek Path Finder in Splunk Search 07-16-2012
0 4
0
4
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors