Splunk Search

Splunk Search
Community Activity
sonicZ
I have a lookup on sourcetype=vipservices csv file has values like so jurhash, jurhasfriendlyname somehashvalue, som...
by sonicZ Contributor in Splunk Search 04-10-2012
0 3
0
3
acdevlin
I'm using a transaction to group events within 30 minutes of one another. What I want to do after that is "undo" one ...
by acdevlin Communicator in Splunk Search 04-10-2012
2 6
2
6
vbumgarner
I'm using transaction ... | search duration>x to eliminate some noise, but then I want to break the events back ou...
by vbumgarner Contributor in Splunk Search 04-10-2012
6 3
6
3
Print
It is best to demonstrate with an example: Example of data: And expected tesult table:
by Print Explorer in Splunk Search 04-10-2012
1 10
1
10
efelder0
I am extracting a date/time stamp out of some XML; however, I need to strip out the time from the string. i.e. - 3/7...
by efelder0 Communicator in Splunk Search 04-10-2012
0 5
0
5
antifreke
All of the Event's in Splunk have MAL,WM,W32,Troj,CXmal,JS,or Vir in their name. Is there a way to separate all of th...
by antifreke Path Finder in Splunk Search 04-10-2012
0 3
0
3
efelder0
I am trying to reformat a date field in Splunk. I have a field called "last_updated_date" and its value is 2012-04-03...
by efelder0 Communicator in Splunk Search 04-09-2012
2 5
2
5
boris
All fields from a lookup.csv file appear as available search fields except the date field. Here is how I defined the...
by boris Path Finder in Splunk Search 04-09-2012
0 3
0
3
misteryuku
I have a problem creating new search time field extractions using the Splunk's REST API and the Java SDK. This is th...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
misteryuku
I have created a new field extraction on props.conf via Splunk REST API I have a raw message that looks like this. f...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
tb582
I have a search using transaction and the startswith/endswith but I don't know how to call the Task_time field in the...
by tb582 Explorer in Splunk Search 04-08-2012
0 13
0
13
michaeljlancast
I have a timechart that shows me the daily throughput for a log source per indexer. I'm trying to find a way to add ...
by michaeljlancast Explorer in Splunk Search 04-08-2012
1 3
1
3
tb582
I'm looking to find everything that has the string "Task Failed". I want splunk to get the task_id and then use all t...
by tb582 Explorer in Splunk Search 04-08-2012
0 4
0
4
tb5821
new to splunk so go easy on me I can currently run two different searches and get the the results I'm looking for bu...
by tb5821 Communicator in Splunk Search 04-07-2012
0 5
0
5
hmahendrakumar
I am looking for a search that will list the concurrent searches(jobs) running that were running on the machine for a...
by hmahendrakumar Path Finder in Splunk Search 04-06-2012
6 4
6
4
chris
Hi I have defined a field for different types of events, the field is recognized in all the events I want to see it....
by chris Motivator in Splunk Search 04-06-2012
1 3
1
3
nebel
Hi, is it possible to merge two or more event results in one? The events are from the same field. Reason : I have a...
by nebel Communicator in Splunk Search 04-06-2012
0 2
0
2
mjones414
Trying to compare the results of a lookup table to a field I'm creating by using mvindex and I can get it to join and...
by mjones414 Contributor in Splunk Search 04-06-2012
1 1
1
1
mikefoti
My ultimate goal is to create a regex expression that can be used use to extract fields from any record made up comma...
by mikefoti Communicator in Splunk Search 04-05-2012
0 3
0
3
talbot7
Trying to show the top 10 busiest guest VM's in mu environment. Each guest VM is reporting its network status in the ...
by talbot7 Path Finder in Splunk Search 04-05-2012
0 1
0
1
Glenn
I know how to exclude certain days from your search results: http://splunk-base.splunk.com/answers/1367/how-do-you-ex...
by Glenn Builder in Splunk Search 04-05-2012
0 5
0
5
gowen
How can I filter events based on two things being true in transforms.conf? Specifically, let's say that I want to fi...
by gowen Path Finder in Splunk Search 04-05-2012
0 4
0
4
ifsuser
Hi im trying to extract domain usernames from my juniper log files using regex however depending on the log message t...
by ifsuser New Member in Splunk Search 04-05-2012
0 6
0
6
jsb22
Essentailly I'm trying to create a form that uses a wildcard by default so users can just hit search on page load and...
by jsb22 Path Finder in Splunk Search 04-05-2012
0 6
0
6
andrzejwasilews
Why it is not possible to install PDF printing in Splunk server on Windows host? We have licensed Splunk and we had ...
by andrzejwasilews Explorer in Splunk Search 04-05-2012
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...