Splunk Search

Splunk Search
Community Activity
ironhalo
We had an event on our splunk server, and there's a gap in some of the logs. The logs are continually written to on ...
by ironhalo Explorer in Splunk Search 04-12-2012
0 1
0
1
tven
<Product> <ProductName>(\w+)</ProductName> <ProductName>(\w+)</ProductName> <ProductName>(\w+)</ProductName> </Pro...
by tven Explorer in Splunk Search 04-12-2012
0 1
0
1
rachelneal
I have a rex that returns a series of 5-8 digit IDs: SEARCH "rex field=_raw "2012-\d\d-\d\d,\d,(?\d{1,8})"" RESULT ...
by rachelneal Path Finder in Splunk Search 04-12-2012
1 3
1
3
subhadipc
I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 ...
by subhadipc Explorer in Splunk Search 04-12-2012
1 1
1
1
dominiquevocat
I am trying to report the number of unique logged in users (field=USERNAME) in a timespan=1h and since i only want un...
by SplunkTrust SplunkTrust in Splunk Search 04-12-2012
0 2
0
2
C4r7m4n
Hello I have two searches: Search A: BGP_NEIGHBOR_STATE_CHANGED source="udp:514" AND ("Established to Idle" OR "Est...
by C4r7m4n Path Finder in Splunk Search 04-12-2012
0 6
0
6
NK_1
I would like to associate the "ip" field with every log line, i.e. Current source log format: 1227.125106.091263 ip...
by NK_1 Path Finder in Splunk Search 04-11-2012
0 2
0
2
boris
What does the regex in my question's title above mean? Source: Search Language Quick Reference Card (on top of page ...
by boris Path Finder in Splunk Search 04-11-2012
0 1
0
1
gregwilliams
I'm trying to return a field based upon a search and within that search extract a variable to search for in another s...
by gregwilliams Path Finder in Splunk Search 04-11-2012
0 5
0
5
lmyoung
I am trying to get the number of denied connections from squid proxy logs from a Cisco Ironport web security applianc...
by lmyoung Engager in Splunk Search 04-11-2012
1 1
1
1
tb582
Hopufully a quick one but I'm looking to search and extract anything between two these fields anyone know how?
by tb582 Explorer in Splunk Search 04-11-2012
0 18
0
18
Sriram
Is there a way to show the status of search jobs while the search is in progress. I have a dashboard with multiple se...
by Sriram Communicator in Splunk Search 04-10-2012
0 8
0
8
sberg
First time posting! --using splunk 4.2.4-- I noticed similar questions on here that were either unanswered or didn't...
by sberg Explorer in Splunk Search 04-10-2012
0 5
0
5
kevinsikora
I'm trying to add search servers to my search head. I'm using the following command: ./splunk add search-server -hos...
by kevinsikora Explorer in Splunk Search 04-10-2012
1 3
1
3
msarro
Hey everyone. Is anyone using Nagios to monitor their splunk instance? I've seen that there was a check_splunk plugin...
by msarro Builder in Splunk Search 04-10-2012
1 2
1
2
sonicZ
I have a lookup on sourcetype=vipservices csv file has values like so jurhash, jurhasfriendlyname somehashvalue, som...
by sonicZ Contributor in Splunk Search 04-10-2012
0 3
0
3
acdevlin
I'm using a transaction to group events within 30 minutes of one another. What I want to do after that is "undo" one ...
by acdevlin Communicator in Splunk Search 04-10-2012
2 6
2
6
vbumgarner
I'm using transaction ... | search duration>x to eliminate some noise, but then I want to break the events back ou...
by vbumgarner Contributor in Splunk Search 04-10-2012
6 3
6
3
Print
It is best to demonstrate with an example: Example of data: And expected tesult table:
by Print Explorer in Splunk Search 04-10-2012
1 10
1
10
efelder0
I am extracting a date/time stamp out of some XML; however, I need to strip out the time from the string. i.e. - 3/7...
by efelder0 Communicator in Splunk Search 04-10-2012
0 5
0
5
antifreke
All of the Event's in Splunk have MAL,WM,W32,Troj,CXmal,JS,or Vir in their name. Is there a way to separate all of th...
by antifreke Path Finder in Splunk Search 04-10-2012
0 3
0
3
efelder0
I am trying to reformat a date field in Splunk. I have a field called "last_updated_date" and its value is 2012-04-03...
by efelder0 Communicator in Splunk Search 04-09-2012
2 5
2
5
boris
All fields from a lookup.csv file appear as available search fields except the date field. Here is how I defined the...
by boris Path Finder in Splunk Search 04-09-2012
0 3
0
3
misteryuku
I have a problem creating new search time field extractions using the Splunk's REST API and the Java SDK. This is th...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
misteryuku
I have created a new field extraction on props.conf via Splunk REST API I have a raw message that looks like this. f...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...