Splunk Search

Splunk Search
Community Activity
NK_1
I would like to associate the "ip" field with every log line, i.e. Current source log format: 1227.125106.091263 ip...
by NK_1 Path Finder in Splunk Search 04-11-2012
0 2
0
2
boris
What does the regex in my question's title above mean? Source: Search Language Quick Reference Card (on top of page ...
by boris Path Finder in Splunk Search 04-11-2012
0 1
0
1
gregwilliams
I'm trying to return a field based upon a search and within that search extract a variable to search for in another s...
by gregwilliams Path Finder in Splunk Search 04-11-2012
0 5
0
5
lmyoung
I am trying to get the number of denied connections from squid proxy logs from a Cisco Ironport web security applianc...
by lmyoung Engager in Splunk Search 04-11-2012
1 1
1
1
tb582
Hopufully a quick one but I'm looking to search and extract anything between two these fields anyone know how?
by tb582 Explorer in Splunk Search 04-11-2012
0 18
0
18
Sriram
Is there a way to show the status of search jobs while the search is in progress. I have a dashboard with multiple se...
by Sriram Communicator in Splunk Search 04-10-2012
0 8
0
8
sberg
First time posting! --using splunk 4.2.4-- I noticed similar questions on here that were either unanswered or didn't...
by sberg Explorer in Splunk Search 04-10-2012
0 5
0
5
kevinsikora
I'm trying to add search servers to my search head. I'm using the following command: ./splunk add search-server -hos...
by kevinsikora Explorer in Splunk Search 04-10-2012
1 3
1
3
msarro
Hey everyone. Is anyone using Nagios to monitor their splunk instance? I've seen that there was a check_splunk plugin...
by msarro Builder in Splunk Search 04-10-2012
1 2
1
2
sonicZ
I have a lookup on sourcetype=vipservices csv file has values like so jurhash, jurhasfriendlyname somehashvalue, som...
by sonicZ Contributor in Splunk Search 04-10-2012
0 3
0
3
acdevlin
I'm using a transaction to group events within 30 minutes of one another. What I want to do after that is "undo" one ...
by acdevlin Communicator in Splunk Search 04-10-2012
2 6
2
6
vbumgarner
I'm using transaction ... | search duration>x to eliminate some noise, but then I want to break the events back ou...
by vbumgarner Contributor in Splunk Search 04-10-2012
6 3
6
3
Print
It is best to demonstrate with an example: Example of data: And expected tesult table:
by Print Explorer in Splunk Search 04-10-2012
1 10
1
10
efelder0
I am extracting a date/time stamp out of some XML; however, I need to strip out the time from the string. i.e. - 3/7...
by efelder0 Communicator in Splunk Search 04-10-2012
0 5
0
5
antifreke
All of the Event's in Splunk have MAL,WM,W32,Troj,CXmal,JS,or Vir in their name. Is there a way to separate all of th...
by antifreke Path Finder in Splunk Search 04-10-2012
0 3
0
3
efelder0
I am trying to reformat a date field in Splunk. I have a field called "last_updated_date" and its value is 2012-04-03...
by efelder0 Communicator in Splunk Search 04-09-2012
2 5
2
5
boris
All fields from a lookup.csv file appear as available search fields except the date field. Here is how I defined the...
by boris Path Finder in Splunk Search 04-09-2012
0 3
0
3
misteryuku
I have a problem creating new search time field extractions using the Splunk's REST API and the Java SDK. This is th...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
misteryuku
I have created a new field extraction on props.conf via Splunk REST API I have a raw message that looks like this. f...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
tb582
I have a search using transaction and the startswith/endswith but I don't know how to call the Task_time field in the...
by tb582 Explorer in Splunk Search 04-08-2012
0 13
0
13
michaeljlancast
I have a timechart that shows me the daily throughput for a log source per indexer. I'm trying to find a way to add ...
by michaeljlancast Explorer in Splunk Search 04-08-2012
1 3
1
3
tb582
I'm looking to find everything that has the string "Task Failed". I want splunk to get the task_id and then use all t...
by tb582 Explorer in Splunk Search 04-08-2012
0 4
0
4
tb5821
new to splunk so go easy on me I can currently run two different searches and get the the results I'm looking for bu...
by tb5821 Communicator in Splunk Search 04-07-2012
0 5
0
5
hmahendrakumar
I am looking for a search that will list the concurrent searches(jobs) running that were running on the machine for a...
by hmahendrakumar Path Finder in Splunk Search 04-06-2012
6 4
6
4
chris
Hi I have defined a field for different types of events, the field is recognized in all the events I want to see it....
by chris Motivator in Splunk Search 04-06-2012
1 3
1
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...