Splunk Search

Splunk Search
Community Activity
bmaupin
I want to get the earliest time that an event was indexed in each of my indexes--not the time of the event itself, bu...
by bmaupin Explorer in Splunk Search 04-27-2012
4 4
4
4
a212830
Hi, I'm having issues with extracting a field from multi-line events. Two samples are below. I want to grab the valu...
by a212830 Champion in Splunk Search 04-27-2012
0 2
0
2
DTERM
I've created a saved search on an indexer. I set the permissions such that the search is available for all apps. I'...
by DTERM Contributor in Splunk Search 04-27-2012
0 1
0
1
fernandoandre
Hi I'm indexing a file which is being written by a syslog process (therefore I defined the sourcetype=syslog) and th...
by fernandoandre Communicator in Splunk Search 04-27-2012
0 5
0
5
singhg
Hi, I am trging to find the first time the event ID 4656 was indexed for particular server. the below search gives ...
by singhg Explorer in Splunk Search 04-27-2012
0 3
0
3
nebel
Hi there, I have a network with Windows and Linux Systems mixed. It is not possible to seperate them or create IP r...
by nebel Communicator in Splunk Search 04-27-2012
0 2
0
2
rahul_matharu
How can we save a job or search after creating it. I further need to create an alert out of the job. I understand ho...
by rahul_matharu New Member in Splunk Search 04-26-2012
0 1
0
1
john
I want to display search result value in a readonly textbox.Iam using advanced Xml.Please help
by john Communicator in Splunk Search 04-26-2012
0 4
0
4
attgjh1
Hi, ive asked my qn below after my event logs shown: Example logs: part of event A: ... ... (other details of even...
by attgjh1 Communicator in Splunk Search 04-26-2012
0 4
0
4
tachu
I would like to be able to have a predefined variable or constant to run queries with by example source="syslog" log...
by tachu Explorer in Splunk Search 04-26-2012
1 2
1
2
kml_uvce
I upgraded Splunk version 4.2.4 to Splunk 4.3 in linux (using .rpm file) but in my IPAD it looks like the graphs are ...
by kml_uvce Builder in Splunk Search 04-26-2012
1 9
1
9
a212830
Hi, I want to query on eventtype, and my query is returning items that I don't want. My search is: source="/var/opt...
by a212830 Champion in Splunk Search 04-26-2012
0 3
0
3
Brian_Osburn
I have a field in my Apache logs that's defined as "MicroSeconds". This is the response time in microseconds for a s...
by Brian_Osburn Builder in Splunk Search 04-26-2012
0 4
0
4
manikdham
I want to customize splunk search app such that particular users have access to a particular index. at login one shou...
by manikdham Path Finder in Splunk Search 04-26-2012
0 2
0
2
MasterOogway
I have an "error-string" and need to alert when I find it not only in the first 10 minute check; not only in the seco...
by MasterOogway Communicator in Splunk Search 04-26-2012
0 3
0
3
matthewcanty
I want to take a totals field. And display the rate on a chart. For example: Total = 0, 1, 2, 3, 4, 5, 6, 7, 9, 10 ...
by matthewcanty Communicator in Splunk Search 04-26-2012
1 2
1
2
lim23
Hello, I am trying to extract the mac address from the following snmp trap. The mac address is embedded in the Hex-...
by lim23 New Member in Splunk Search 04-26-2012
0 5
0
5
mlevenson
Been poking around and trying to figure out how to pull up how much data has been sent from a specific host. For exa...
by mlevenson Explorer in Splunk Search 04-25-2012
0 1
0
1
jspears
I'm trying to check for hosts that were sending data last week and now are not, or newly added hosts. I don't think ...
by jspears Communicator in Splunk Search 04-25-2012
1 3
1
3
mayler
First, thanks for taking the time to look at this. Hopefully I'll be able to provide all the information you need to ...
by mayler Path Finder in Splunk Search 04-25-2012
0 7
0
7
mlevenson
Trying to create a report for avg CPU usage and failing. current search is splunk_server=red counter="% Processo...
by mlevenson Explorer in Splunk Search 04-25-2012
0 3
0
3
Flynt
I have a text file that I cannot index, I KNOW it's text, I can vi the file with :set list and there are no hidden ch...
by Flynt Splunk Employee Splunk Employee in Splunk Search 04-25-2012
0 1
0
1
efelder0
Is there a way (Splunk feature or search cmd) to export a list of files that were indexed and then create a report?
by efelder0 Communicator in Splunk Search 04-25-2012
1 3
1
3
jspears
How does one get at fields in _internal that are prefixed with an underscore, e.g. _tcp_KBps ? It seems that Splunk ...
by jspears Communicator in Splunk Search 04-25-2012
1 2
1
2
curtgran
Hi, I'm hoping this is trivial but I've searched and can't really find the answer. I'm searching TCP connections an...
by curtgran Explorer in Splunk Search 04-24-2012
1 2
1
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...