Splunk Search

Splunk Search
Community Activity
lpolo
Splunk support the statistical function "mode(X)". According to the Splunk documentation this function returns the mo...
by lpolo Motivator in Splunk Search 06-01-2012
0 3
0
3
mseffrin
In the manual we have: sourcetype=access_* action=purchase [search sourcetype=access_* action=purchase | top limit=...
by mseffrin Engager in Splunk Search 06-01-2012
0 1
0
1
Dark_Ichigo
http://docs.splunk.com/Documentation/Splunk/4.2.4/User/RealtimeSearch#Real-time_backfill Realtime backfill, how is t...
by Dark_Ichigo Builder in Splunk Search 06-01-2012
0 1
0
1
mcwomble
I have the following search which displays amounts of records by month (X-axis). index="billing" suspededrecords |...
by mcwomble Path Finder in Splunk Search 05-31-2012
2 4
2
4
aarcro
So I want use bucket to group my data by weeks that start on Mondays if I change my query to use earliest=-1w@w1 late...
by aarcro Explorer in Splunk Search 05-31-2012
0 4
0
4
andrewsmiley
Once a week when Symantec runs a full scan our quota gets blown out of the water. Is there a way to filter these eve...
by andrewsmiley Engager in Splunk Search 05-31-2012
1 2
1
2
gehogan3
Is it possible to chain together two searches? Basically, need to grab the IP address from my webserver logs (if it ...
by gehogan3 Explorer in Splunk Search 05-31-2012
0 1
0
1
rakesh_498115
Hi , I have been using the stats avg(duration) as Avg_Duration in my query.But while displayin the Avg_Duration i am...
by rakesh_498115 Motivator in Splunk Search 05-31-2012
0 5
0
5
Jordan_Brough
Is it possible to apply a search-time field extraction to all inputs? Our log files (across multiple hosts, sources ...
by Jordan_Brough Path Finder in Splunk Search 05-30-2012
0 3
0
3
timbCFCA
I have multiple key value pairs in a line like so: summary=" Policy Rule modified" summary=" Policy Rule number 2 mod...
by timbCFCA Path Finder in Splunk Search 05-30-2012
1 3
1
3
neilsussman
I'm fairly new to Splunk search strings so hopefully someone can help. I'm trying to create a three column search: ...
by neilsussman Explorer in Splunk Search 05-30-2012
2 3
2
3
dturner83
Hello, I have an application sending logs to the windows event log with a lognamename of ErrorLogs. The error log l...
by dturner83 Path Finder in Splunk Search 05-30-2012
1 4
1
4
myli12
I constructed transactions with "startswith" and "endswith" and I am trying to identify those incomplete transactions...
by myli12 Path Finder in Splunk Search 05-30-2012
1 3
1
3
rakesh_498115
I Have Two sourcetypes defined . i need to write a query integrating the two sourcetypes and should get a single resu...
by rakesh_498115 Motivator in Splunk Search 05-30-2012
0 1
0
1
Norling
Hi all! I have two searches that I want to display in the same search and pipe them out in a time-chart Both search...
by Norling Explorer in Splunk Search 05-30-2012
0 2
0
2
responsys_cm
I have a lookup table that contains details about Nessus plugins -- the Nessus ID, Plugin Name, Risk Factor, and a fe...
by responsys_cm Builder in Splunk Search 05-30-2012
0 1
0
1
zloc
Hi there, This should be a pretty simple question. I have looked around for a while. We have a web log we are trying...
by zloc Engager in Splunk Search 05-29-2012
0 2
0
2
jevenson
This may be confusing, so I'll try to explain it as best as I can. I've got a search that looks for servers that get ...
by jevenson Path Finder in Splunk Search 05-29-2012
0 1
0
1
nelsonb
I'm unable to get this search to output anything except the _time of the first search: |set diff [ search index="col...
by nelsonb Explorer in Splunk Search 05-29-2012
0 5
0
5
jedatt01
I have a chart that I want to drilldown on and display another graph based on the drilldown results in a popup window...
by jedatt01 Builder in Splunk Search 05-29-2012
1 3
1
3
a212830
Hi, I'm a relative newbie (power noob?) who is having issues with extracting fields from a multi-line event. A sampl...
by a212830 Champion in Splunk Search 05-29-2012
0 4
0
4
tmarlette
I am attempting to look for the top 10 offenders of a specific event type, and get their IP address. That I can do no...
by tmarlette Motivator in Splunk Search 05-29-2012
0 4
0
4
jangid
What is the difference between Choose a Data Type and Choose a Data Source. I want to monitor only directories that ...
by jangid Builder in Splunk Search 05-29-2012
0 3
0
3
stwong
Hi all, I'm a newbie to Splunk. I tried to index all apache log files in the same directory as a single source so th...
by stwong Communicator in Splunk Search 05-28-2012
0 3
0
3
zucler
Hi guys, As I understand, dedup command will filter the complete set of results and remove any duplicate fields. Wh...
by zucler Explorer in Splunk Search 05-28-2012
0 3
0
3
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...