Splunk Search

Splunk Search
Community Activity
yoeljacobsen
I'm looking for an efficient way to retrieve the single most recent event from each of about 2000 sources. It seems ...
by yoeljacobsen Explorer in Splunk Search 07-12-2012
2 9
2
9
KarunK
Hi All, I am trying to extract the timestamps from the log file name (source) and then find how many logs are produc...
by KarunK Contributor in Splunk Search 07-12-2012
1 3
1
3
cheeseng
I am doing a internal audit for splunk log, the query is following index="_audit" action = edit_user NOT "search" |...
by cheeseng New Member in Splunk Search 07-12-2012
0 1
0
1
hortone
I am collecting syslogs from the network (UDP 514) and they are all coming in as sourcetype=syslog. I did not see a c...
by hortone New Member in Splunk Search 07-11-2012
0 1
0
1
bshamsian
I am having problems with an extracted field not showing in the search results. I am indexing a log file that among ...
by bshamsian Path Finder in Splunk Search 07-11-2012
0 1
0
1
Anthony_Hou
Hi, We have an issue about receiving email tells "The search that you sent to the background has completed" We recei...
by Anthony_Hou Path Finder in Splunk Search 07-11-2012
0 2
0
2
bojanz
I'm having a field that is being specifically indexed (and not extracted during search time). The following configura...
by bojanz Communicator in Splunk Search 07-11-2012
0 7
0
7
splunk_zen
From the latest docs, this is the simplest prerequisite to build a bubble chart, "1. A single series structure that ...
by splunk_zen Builder in Splunk Search 07-11-2012
1 6
1
6
jangid
What is the best option for field extraction? my log file contain some data separated with # and I want to convert t...
by jangid Builder in Splunk Search 07-11-2012
0 8
0
8
paulf
Hi, Is it possible to perform a more than 1x lookup on a number of fields? I have 2x IP fields, one is a source ip a...
by paulf Explorer in Splunk Search 07-11-2012
1 2
1
2
rturk
Greetings Splunkers! I posed this question in the IRC channel, but thought I'd put it in here as well just in case a...
by rturk Builder in Splunk Search 07-11-2012
0 11
0
11
rakesh_498115
Hi, I need to calucalte the time difference between two events in splunk..using the transaction command ....how can ...
by rakesh_498115 Motivator in Splunk Search 07-11-2012
0 1
0
1
mzammit
Hi, I'm trying to implement a search which raises alerts based on events with unique, but as of yet unknown keys wit...
by mzammit New Member in Splunk Search 07-11-2012
0 1
0
1
josknigh
Is it possible to use the rex command to do a dynamic key=value extraction where they key is a also a regular express...
by josknigh Engager in Splunk Search 07-10-2012
1 1
1
1
kbantoft
I've got data coming in, looking like: Jul 10 21:29:33 74.117.145.130 sdpd[3899]: [sdpd.INFO]: ext_host_stat is 173....
by kbantoft Engager in Splunk Search 07-10-2012
0 1
0
1
klaurean
I have been trying to make a new field using IFX by making a search and selecting "extract fields" and then inputting...
by klaurean Engager in Splunk Search 07-10-2012
0 3
0
3
asingla
I am using a join search command. What I noticed is that join only takes one row from the sub search result for the j...
by asingla Communicator in Splunk Search 07-10-2012
0 1
0
1
marywill
I want to use the outlier function but am having trouble identifying the sources as outlier, this is what I have so f...
by marywill Engager in Splunk Search 07-10-2012
0 1
0
1
benjiminhugh
I came across a very strange problem: I have a transformation field: [record] FORMAT = event_type::Record_DVR dvr_sta...
by benjiminhugh Explorer in Splunk Search 07-10-2012
0 1
0
1
mship
Splunk server is running 4.3.2, installed UF 4.3.2 on winXP embedded client and was getting the following error "Mes...
by mship Path Finder in Splunk Search 07-10-2012
0 1
0
1
karthik7411
hi, i have already uploaded a csv lookup file to the splunk indexer. Now i want to add more entries to the csv file. ...
by karthik7411 New Member in Splunk Search 07-10-2012
0 1
0
1
asarolkar
When I execute this search, I get all events from organization : Barclays that contains records for 2012. index="lo...
by asarolkar Builder in Splunk Search 07-10-2012
0 4
0
4
rroberts
Not sure of the cause of this error? # (2013, 'Lost connection to MySQL server during query') Have verified UID and P...
by rroberts Splunk Employee Splunk Employee in Splunk Search 07-10-2012
0 2
0
2
Michael_Schyma1
sourcetype="MFApps" | addtotals fieldname=sum |top limit=1 sum | fields + count | rename count AS "Number of Events...
by Michael_Schyma1 Contributor in Splunk Search 07-10-2012
0 1
0
1
cphair
I have the feeling this should be easy, but I can't figure it out. I want to determine a host's percent uptime over ...
by cphair Builder in Splunk Search 07-10-2012
0 4
0
4
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...