Thread Info | |||||
---|---|---|---|---|---|
<Product>
<ProductName>(\w+)</ProductName>
<ProductName>(\w+)</ProductName>
<ProductName>(\w+)</ProductName>
</Pro...
by
tven
Explorer
in
Splunk Search
04-12-2012
|
0
|
1
| |||
I have a rex that returns a series of 5-8 digit IDs:
SEARCH "rex field=_raw "2012-\d\d-\d\d,\d,(?
\d{1,8})...
by
rachelneal
Path Finder
in
Splunk Search
04-12-2012
|
1
|
3
| |||
I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 ...
by
subhadipc
Explorer
in
Splunk Search
04-12-2012
|
1
|
1
| |||
I am trying to report the number of unique logged in users (field=USERNAME) in a timespan=1h and since i only want un...
by
dominiquevocat
SplunkTrust
in
Splunk Search
04-12-2012
|
0
|
2
| |||
Hello
I have two searches: Search A: BGP_NEIGHBOR_STATE_CHANGED source="udp:514" AND ("Established to Idle" OR "E...
by
C4r7m4n
Path Finder
in
Splunk Search
04-11-2012
|
0
|
6
| |||
I would like to associate the "ip" field with every log line, i.e.
Current source log format:
1227.125106.091263 ip...
by
NK_1
Path Finder
in
Splunk Search
07-15-2011
|
0
|
2
| |||
What does the regex in my question's title above mean?
Source: Search Language Quick Reference Card (on top of pag...
by
boris
Path Finder
in
Splunk Search
04-11-2012
|
0
|
1
| |||
I'm trying to return a field based upon a search and within that search extract a variable to search for in another s...
by
gregwilliams
Path Finder
in
Splunk Search
04-11-2012
|
0
|
5
| |||
I am trying to get the number of denied connections from squid proxy logs from a Cisco Ironport web security applianc...
by
lmyoung
Engager
in
Splunk Search
04-11-2012
|
1
|
1
| |||
Hopufully a quick one but I'm looking to search and extract anything between two these fields anyone know how?
by
tb582
Explorer
in
Splunk Search
04-09-2012
|
0
|
18
| |||
Is there a way to show the status of search jobs while the search is in progress. I have a dashboard with multiple se...
by
Sriram
Communicator
in
Splunk Search
03-31-2012
|
0
|
8
| |||
First time posting! --using splunk 4.2.4--
I noticed similar questions on here that were either unanswered or didn...
by
sberg
Explorer
in
Splunk Search
04-09-2012
|
0
|
5
| |||
I'm trying to add search servers to my search head. I'm using the following command:
./splunk add search-server -h...
by
kevinsikora
Explorer
in
Splunk Search
04-10-2012
|
1
|
3
| |||
Hey everyone. Is anyone using Nagios to monitor their splunk instance? I've seen that there was a check_splunk plugin...
by
msarro
Builder
in
Splunk Search
09-09-2011
|
1
|
2
| |||
I have a lookup on sourcetype=vipservices csv file has values like so
jurhash, jurhasfriendlyname somehashvalue, s...
by
sonicZ
Contributor
in
Splunk Search
04-09-2012
|
0
|
3
| |||
I'm using a transaction to group events within 30 minutes of one another. What I want to do after that is "undo" one ...
by
acdevlin
Communicator
in
Splunk Search
08-05-2011
|
2
|
6
| |||
I'm using
transaction ... | search duration>x
to eliminate some noise, but then I want to break the events bac...
by
vbumgarner
Contributor
in
Splunk Search
03-22-2011
|
6
|
3
| |||
It is best to demonstrate with an example:
Example of data:
And expected tesult table:
by
Print
Explorer
in
Splunk Search
04-10-2012
|
1
|
10
| |||
I am extracting a date/time stamp out of some XML; however, I need to strip out the time from the string.
i.e. - 3...
by
efelder0
Communicator
in
Splunk Search
04-05-2012
|
0
|
5
| |||
All of the Event's in Splunk have MAL,WM,W32,Troj,CXmal,JS,or Vir in their name. Is there a way to separate all of th...
by
antifreke
Path Finder
in
Splunk Search
04-10-2012
|
0
|
3
| |||
I am trying to reformat a date field in Splunk. I have a field called "last_updated_date" and its value is 2012-04-03...
by
efelder0
Communicator
in
Splunk Search
04-09-2012
|
2
|
5
| |||
All fields from a lookup.csv file appear as available search fields except the date field.
Here is how I defined t...
by
boris
Path Finder
in
Splunk Search
04-06-2012
|
0
|
3
| |||
I have a problem creating new search time field extractions using the Splunk's REST API and the Java SDK.
This is ...
by
misteryuku
Communicator
in
Splunk Search
04-08-2012
|
0
|
1
| |||
I have created a new field extraction on props.conf via Splunk REST API
I have a raw message that looks like this....
by
misteryuku
Communicator
in
Splunk Search
04-08-2012
|
0
|
1
| |||
I have a search using transaction and the startswith/endswith but I don't know how to call the Task_time field in the...
by
tb582
Explorer
in
Splunk Search
04-06-2012
|
0
|
13
|