Splunk Search

Splunk Search
Community Activity
Yarsa
Hi, Let's say "user X" visited my site on these dates: 2/3/2012 2/4/2012 2/5/2012 10/5/2012 11/5/2012 How can I coun...
by Yarsa Path Finder in Splunk Search 05-17-2012
1 4
1
4
emckinlay
My log files are stored in nested folders of the following form: 1_1_2012 ..... 08_45_10_12 .......... l...
by emckinlay New Member in Splunk Search 05-16-2012
0 3
0
3
dang
I'm writing a search that is comparing the count of an event versus what happned one and two weeks ago. My search lo...
by dang Path Finder in Splunk Search 05-16-2012
1 2
1
2
sou128
I have a simple join search as follow, index=portal bam="audit" event="userLogout" | stats median(secSessDur) as med...
by sou128 Explorer in Splunk Search 05-16-2012
1 1
1
1
mcbradford
I want to create a time chart (line) based on the count of events for the past 24 hours, and one week earlier same da...
by mcbradford Contributor in Splunk Search 05-16-2012
0 1
0
1
kunadkat
I am plotting reponse time data using the following search sourcetype="jboss" TOTAL SEARCH TIME CAREWEB AND NOT PMR ...
by kunadkat Explorer in Splunk Search 05-16-2012
0 3
0
3
Yarsa
Hi, is it possible to manipulate the events of a query with a transaction after using stats/table/eval/where? the eve...
by Yarsa Path Finder in Splunk Search 05-16-2012
1 1
1
1
arturo
Folks : I have a customer using numbers in "spanish" standard (a number in the US Standard like 1,000,000.25 is rep...
by arturo Explorer in Splunk Search 05-16-2012
1 6
1
6
LauraBre
Hello, This is my search : tag::source="TokenizerWatchdogSplunk" Service_Type="*" | eval series=case(Service_Type="...
by LauraBre Communicator in Splunk Search 05-16-2012
0 3
0
3
adityapavan18
Hi I am using following query to get my results in tabular format: source="/splunkInput/MARTINI/EMLC/*" E2E_ID="sa...
by adityapavan18 Contributor in Splunk Search 05-16-2012
0 2
0
2
MHibbin
Hey All, I was wondering if someone could shed light on this error... [SimpleResultsTable module] Input is not prop...
by MHibbin Influencer in Splunk Search 05-16-2012
0 2
0
2
a356115
I have the following multiple events: date=08/07/11 time=14:58:29 app=surveyStartCall ct=1 q1=8 q2=5 q3=5 q4=5 date...
by a356115 New Member in Splunk Search 05-15-2012
0 9
0
9
htaylor
When searching for email addresses in our sendmail logs, it helps to see the full transaction by using the queue id (...
by htaylor New Member in Splunk Search 05-15-2012
0 3
0
3
shangshin
Hi, I installed splunk on 2 servers, e.g. abc and xyz and I am able to access it from http://abc:8000/ and http://x...
by shangshin Builder in Splunk Search 05-15-2012
0 4
0
4
scottjreynolds
We have a logfile that logs the following two lines per logical unit of work completed by the application server. In...
by scottjreynolds Engager in Splunk Search 05-15-2012
1 2
1
2
epreece
Hi all, I have two searches that provide useful data points. One shows failures, one successes. I would like to furt...
by epreece Engager in Splunk Search 05-14-2012
0 2
0
2
lalbsah
I have below log format and I want to get value of getTaskHistoryList(in this case it is 33 but this may get changed)...
by lalbsah Engager in Splunk Search 05-14-2012
1 1
1
1
Dark_Ichigo
I want to add a Field Extractor Regex in props.conf but not from _raw but from another field Example: rex Filed=tes...
by Dark_Ichigo Builder in Splunk Search 05-13-2012
1 2
1
2
balidani
Hello! When I run the following search it works perfectly: inc=* | head 2 However if the search is after a pipelin...
by balidani Explorer in Splunk Search 05-12-2012
0 2
0
2
Paolo_Prigione
Hi you, viewmakers! Has anybody had problems with the grouping param of the <row> element? It works on <dashboard> ...
by Paolo_Prigione Builder in Splunk Search 05-12-2012
0 1
0
1
andrewsmiley
I'm already extracting the byte size from the event using this: \s+bytes\s+(?\d+)\s Is there a way to do an inline F...
by andrewsmiley Engager in Splunk Search 05-11-2012
0 1
0
1
caffein
When using the outlier function will it remove the whole log entry from the set of values to process, or does it just...
by caffein Path Finder in Splunk Search 05-11-2012
0 2
0
2
p_splunk
Hi, i want to accumulate a field per user (and time). so lets say the users are distinguishable by the field user and...
by p_splunk Engager in Splunk Search 05-11-2012
0 1
0
1
efelder0
Recently, I have made changes to my Splunk environment where I created new indexes and assigned multiple data sources...
by efelder0 Communicator in Splunk Search 05-11-2012
0 4
0
4
lautero
I had an IBM reporting program exporting CSV data with Splunk reading it correctly for a few hours. During this perio...
by lautero New Member in Splunk Search 05-11-2012
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...