Splunk Search

Splunk Search
Community Activity
bermudabob
Hi, Novice to Splunk, I've indexed some data and now want to perform some reports on it. My main requirement is that...
by bermudabob Explorer in Splunk Search 04-16-2012
0 7
0
7
Jason
So, I was running ... | sistats count by host, source, sourcetype, field1, field2 and saving it to a summary index. ...
by Jason Motivator in Splunk Search 04-16-2012
2 4
2
4
C4r7m4n
Hello I have this search: earliest=-7d@d latest=@d source="/var/log/snmptrapfmt.log" (timeout_url="*.GE" OR timeo...
by C4r7m4n Path Finder in Splunk Search 04-16-2012
0 2
0
2
zuberpalekar
Sample data that I am querying on 2012/04/16 10:36:10.290 2012/04/16 10:35:16.333 2980023 811863 jac-datafileupl...
by zuberpalekar Engager in Splunk Search 04-16-2012
0 1
0
1
sideview
I have an interesting situation where I want to be able to display a little summary table, showing a few statistics ...
by SplunkTrust SplunkTrust in Splunk Search 04-14-2012
0 2
0
2
subhadipc
I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 ...
by subhadipc Explorer in Splunk Search 04-13-2012
0 3
0
3
mikefoti
The query below displays accurate values for Requests, Accepted, Rejected and %Accepted. | stats count(eval(nps_pac...
by mikefoti Communicator in Splunk Search 04-13-2012
0 10
0
10
anssntaco
When running a timechart over the last 7 days, using span=10m, the timechart will only display roughly the first 3.5...
by anssntaco Path Finder in Splunk Search 04-13-2012
0 1
0
1
nebel
Hi Splunkers, I need the result from first search in another search. First search: sourcetype=win_server | multikv ...
by nebel Communicator in Splunk Search 04-13-2012
0 3
0
3
jgauthier
Ugh! I hate having to ask for query help, but I'm close.. but not close enough. Basically, I have two sets of data....
by jgauthier Contributor in Splunk Search 04-13-2012
0 8
0
8
C4r7m4n
Hello, Does anybody know how to write a search that find events occur at least one per day and these events count as...
by C4r7m4n Path Finder in Splunk Search 04-12-2012
1 9
1
9
ironhalo
We had an event on our splunk server, and there's a gap in some of the logs. The logs are continually written to on ...
by ironhalo Explorer in Splunk Search 04-12-2012
0 1
0
1
tven
<Product> <ProductName>(\w+)</ProductName> <ProductName>(\w+)</ProductName> <ProductName>(\w+)</ProductName> </Pro...
by tven Explorer in Splunk Search 04-12-2012
0 1
0
1
rachelneal
I have a rex that returns a series of 5-8 digit IDs: SEARCH "rex field=_raw "2012-\d\d-\d\d,\d,(?\d{1,8})"" RESULT ...
by rachelneal Path Finder in Splunk Search 04-12-2012
1 3
1
3
subhadipc
I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 ...
by subhadipc Explorer in Splunk Search 04-12-2012
1 1
1
1
dominiquevocat
I am trying to report the number of unique logged in users (field=USERNAME) in a timespan=1h and since i only want un...
by SplunkTrust SplunkTrust in Splunk Search 04-12-2012
0 2
0
2
C4r7m4n
Hello I have two searches: Search A: BGP_NEIGHBOR_STATE_CHANGED source="udp:514" AND ("Established to Idle" OR "Est...
by C4r7m4n Path Finder in Splunk Search 04-12-2012
0 6
0
6
NK_1
I would like to associate the "ip" field with every log line, i.e. Current source log format: 1227.125106.091263 ip...
by NK_1 Path Finder in Splunk Search 04-11-2012
0 2
0
2
boris
What does the regex in my question's title above mean? Source: Search Language Quick Reference Card (on top of page ...
by boris Path Finder in Splunk Search 04-11-2012
0 1
0
1
gregwilliams
I'm trying to return a field based upon a search and within that search extract a variable to search for in another s...
by gregwilliams Path Finder in Splunk Search 04-11-2012
0 5
0
5
lmyoung
I am trying to get the number of denied connections from squid proxy logs from a Cisco Ironport web security applianc...
by lmyoung Engager in Splunk Search 04-11-2012
1 1
1
1
tb582
Hopufully a quick one but I'm looking to search and extract anything between two these fields anyone know how?
by tb582 Explorer in Splunk Search 04-11-2012
0 18
0
18
Sriram
Is there a way to show the status of search jobs while the search is in progress. I have a dashboard with multiple se...
by Sriram Communicator in Splunk Search 04-10-2012
0 8
0
8
sberg
First time posting! --using splunk 4.2.4-- I noticed similar questions on here that were either unanswered or didn't...
by sberg Explorer in Splunk Search 04-10-2012
0 5
0
5
kevinsikora
I'm trying to add search servers to my search head. I'm using the following command: ./splunk add search-server -hos...
by kevinsikora Explorer in Splunk Search 04-10-2012
1 3
1
3
Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...