Splunk Search

Splunk Search
Community Activity
1StopBloke
Hello, We use log4net for a bunch of our windows services and web applications. Currently I set the sourcetype for e...
by 1StopBloke Explorer in Splunk Search 04-29-2012
0 1
0
1
gpanicker
I am looking for a query to group a set of transactions with respect to their duration. The output should be like thi...
by gpanicker Explorer in Splunk Search 04-29-2012
0 4
0
4
sou128
currently my simpletresultstable is showing myDecimalfield1 | myNumfield1 | MyCalculatedField1 1234.56789 | 1 | 1234...
by sou128 Explorer in Splunk Search 04-29-2012
0 1
0
1
johandk
I'm running a search like this: index=summary splunk_server=local search_name=SOMESEARCH earliest=-1mon@mon latest=@...
by johandk Path Finder in Splunk Search 04-29-2012
0 3
0
3
bmaupin
I want to get the earliest time that an event was indexed in each of my indexes--not the time of the event itself, bu...
by bmaupin Explorer in Splunk Search 04-27-2012
4 4
4
4
a212830
Hi, I'm having issues with extracting a field from multi-line events. Two samples are below. I want to grab the valu...
by a212830 Champion in Splunk Search 04-27-2012
0 2
0
2
DTERM
I've created a saved search on an indexer. I set the permissions such that the search is available for all apps. I'...
by DTERM Contributor in Splunk Search 04-27-2012
0 1
0
1
fernandoandre
Hi I'm indexing a file which is being written by a syslog process (therefore I defined the sourcetype=syslog) and th...
by fernandoandre Communicator in Splunk Search 04-27-2012
0 5
0
5
singhg
Hi, I am trging to find the first time the event ID 4656 was indexed for particular server. the below search gives ...
by singhg Explorer in Splunk Search 04-27-2012
0 3
0
3
nebel
Hi there, I have a network with Windows and Linux Systems mixed. It is not possible to seperate them or create IP r...
by nebel Communicator in Splunk Search 04-27-2012
0 2
0
2
rahul_matharu
How can we save a job or search after creating it. I further need to create an alert out of the job. I understand ho...
by rahul_matharu New Member in Splunk Search 04-26-2012
0 1
0
1
john
I want to display search result value in a readonly textbox.Iam using advanced Xml.Please help
by john Communicator in Splunk Search 04-26-2012
0 4
0
4
attgjh1
Hi, ive asked my qn below after my event logs shown: Example logs: part of event A: ... ... (other details of even...
by attgjh1 Communicator in Splunk Search 04-26-2012
0 4
0
4
tachu
I would like to be able to have a predefined variable or constant to run queries with by example source="syslog" log...
by tachu Explorer in Splunk Search 04-26-2012
1 2
1
2
kml_uvce
I upgraded Splunk version 4.2.4 to Splunk 4.3 in linux (using .rpm file) but in my IPAD it looks like the graphs are ...
by kml_uvce Builder in Splunk Search 04-26-2012
1 9
1
9
a212830
Hi, I want to query on eventtype, and my query is returning items that I don't want. My search is: source="/var/opt...
by a212830 Champion in Splunk Search 04-26-2012
0 3
0
3
Brian_Osburn
I have a field in my Apache logs that's defined as "MicroSeconds". This is the response time in microseconds for a s...
by Brian_Osburn Builder in Splunk Search 04-26-2012
0 4
0
4
manikdham
I want to customize splunk search app such that particular users have access to a particular index. at login one shou...
by manikdham Path Finder in Splunk Search 04-26-2012
0 2
0
2
MasterOogway
I have an "error-string" and need to alert when I find it not only in the first 10 minute check; not only in the seco...
by MasterOogway Communicator in Splunk Search 04-26-2012
0 3
0
3
matthewcanty
I want to take a totals field. And display the rate on a chart. For example: Total = 0, 1, 2, 3, 4, 5, 6, 7, 9, 10 ...
by matthewcanty Communicator in Splunk Search 04-26-2012
1 2
1
2
lim23
Hello, I am trying to extract the mac address from the following snmp trap. The mac address is embedded in the Hex-...
by lim23 New Member in Splunk Search 04-26-2012
0 5
0
5
mlevenson
Been poking around and trying to figure out how to pull up how much data has been sent from a specific host. For exa...
by mlevenson Explorer in Splunk Search 04-25-2012
0 1
0
1
jspears
I'm trying to check for hosts that were sending data last week and now are not, or newly added hosts. I don't think ...
by jspears Communicator in Splunk Search 04-25-2012
1 3
1
3
mayler
First, thanks for taking the time to look at this. Hopefully I'll be able to provide all the information you need to ...
by mayler Path Finder in Splunk Search 04-25-2012
0 7
0
7
mlevenson
Trying to create a report for avg CPU usage and failing. current search is splunk_server=red counter="% Processo...
by mlevenson Explorer in Splunk Search 04-25-2012
0 3
0
3
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors