Splunk Search

Splunk Search
Community Activity
Dark_Ichigo
http://docs.splunk.com/Documentation/Splunk/4.2.4/User/RealtimeSearch#Real-time_backfill Realtime backfill, how is t...
by Dark_Ichigo Builder in Splunk Search 06-01-2012
0 1
0
1
mcwomble
I have the following search which displays amounts of records by month (X-axis). index="billing" suspededrecords |...
by mcwomble Path Finder in Splunk Search 05-31-2012
2 4
2
4
aarcro
So I want use bucket to group my data by weeks that start on Mondays if I change my query to use earliest=-1w@w1 late...
by aarcro Explorer in Splunk Search 05-31-2012
0 4
0
4
andrewsmiley
Once a week when Symantec runs a full scan our quota gets blown out of the water. Is there a way to filter these eve...
by andrewsmiley Engager in Splunk Search 05-31-2012
1 2
1
2
gehogan3
Is it possible to chain together two searches? Basically, need to grab the IP address from my webserver logs (if it ...
by gehogan3 Explorer in Splunk Search 05-31-2012
0 1
0
1
rakesh_498115
Hi , I have been using the stats avg(duration) as Avg_Duration in my query.But while displayin the Avg_Duration i am...
by rakesh_498115 Motivator in Splunk Search 05-31-2012
0 5
0
5
Jordan_Brough
Is it possible to apply a search-time field extraction to all inputs? Our log files (across multiple hosts, sources ...
by Jordan_Brough Path Finder in Splunk Search 05-30-2012
0 3
0
3
timbCFCA
I have multiple key value pairs in a line like so: summary=" Policy Rule modified" summary=" Policy Rule number 2 mod...
by timbCFCA Path Finder in Splunk Search 05-30-2012
1 3
1
3
neilsussman
I'm fairly new to Splunk search strings so hopefully someone can help. I'm trying to create a three column search: ...
by neilsussman Explorer in Splunk Search 05-30-2012
2 3
2
3
dturner83
Hello, I have an application sending logs to the windows event log with a lognamename of ErrorLogs. The error log l...
by dturner83 Path Finder in Splunk Search 05-30-2012
1 4
1
4
myli12
I constructed transactions with "startswith" and "endswith" and I am trying to identify those incomplete transactions...
by myli12 Path Finder in Splunk Search 05-30-2012
1 3
1
3
rakesh_498115
I Have Two sourcetypes defined . i need to write a query integrating the two sourcetypes and should get a single resu...
by rakesh_498115 Motivator in Splunk Search 05-30-2012
0 1
0
1
Norling
Hi all! I have two searches that I want to display in the same search and pipe them out in a time-chart Both search...
by Norling Explorer in Splunk Search 05-30-2012
0 2
0
2
responsys_cm
I have a lookup table that contains details about Nessus plugins -- the Nessus ID, Plugin Name, Risk Factor, and a fe...
by responsys_cm Builder in Splunk Search 05-30-2012
0 1
0
1
zloc
Hi there, This should be a pretty simple question. I have looked around for a while. We have a web log we are trying...
by zloc Engager in Splunk Search 05-29-2012
0 2
0
2
jevenson
This may be confusing, so I'll try to explain it as best as I can. I've got a search that looks for servers that get ...
by jevenson Path Finder in Splunk Search 05-29-2012
0 1
0
1
nelsonb
I'm unable to get this search to output anything except the _time of the first search: |set diff [ search index="col...
by nelsonb Explorer in Splunk Search 05-29-2012
0 5
0
5
jedatt01
I have a chart that I want to drilldown on and display another graph based on the drilldown results in a popup window...
by jedatt01 Builder in Splunk Search 05-29-2012
1 3
1
3
a212830
Hi, I'm a relative newbie (power noob?) who is having issues with extracting fields from a multi-line event. A sampl...
by a212830 Champion in Splunk Search 05-29-2012
0 4
0
4
tmarlette
I am attempting to look for the top 10 offenders of a specific event type, and get their IP address. That I can do no...
by tmarlette Motivator in Splunk Search 05-29-2012
0 4
0
4
jangid
What is the difference between Choose a Data Type and Choose a Data Source. I want to monitor only directories that ...
by jangid Builder in Splunk Search 05-29-2012
0 3
0
3
stwong
Hi all, I'm a newbie to Splunk. I tried to index all apache log files in the same directory as a single source so th...
by stwong Communicator in Splunk Search 05-28-2012
0 3
0
3
zucler
Hi guys, As I understand, dedup command will filter the complete set of results and remove any duplicate fields. Wh...
by zucler Explorer in Splunk Search 05-28-2012
0 3
0
3
sjjohns
So I am brand new to Splunk. I just finished setting up a Ubuntu server for indexing and have got all my forwarders w...
by sjjohns New Member in Splunk Search 05-28-2012
0 1
0
1
hello_world15
I have events like this: Desc_1=eth1 Desc_50=vlan.10 Desc_123=vlan.20 .... the key is in Descr_* format and I want t...
by hello_world15 Engager in Splunk Search 05-28-2012
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Solution Authors