Splunk Search

Splunk Search
Community Activity
kevinsikora
I'm trying to add search servers to my search head. I'm using the following command: ./splunk add search-server -hos...
by kevinsikora Explorer in Splunk Search 04-10-2012
1 3
1
3
msarro
Hey everyone. Is anyone using Nagios to monitor their splunk instance? I've seen that there was a check_splunk plugin...
by msarro Builder in Splunk Search 04-10-2012
1 2
1
2
sonicZ
I have a lookup on sourcetype=vipservices csv file has values like so jurhash, jurhasfriendlyname somehashvalue, som...
by sonicZ Contributor in Splunk Search 04-10-2012
0 3
0
3
acdevlin
I'm using a transaction to group events within 30 minutes of one another. What I want to do after that is "undo" one ...
by acdevlin Communicator in Splunk Search 04-10-2012
2 6
2
6
vbumgarner
I'm using transaction ... | search duration>x to eliminate some noise, but then I want to break the events back ou...
by vbumgarner Contributor in Splunk Search 04-10-2012
6 3
6
3
Print
It is best to demonstrate with an example: Example of data: And expected tesult table:
by Print Explorer in Splunk Search 04-10-2012
1 10
1
10
efelder0
I am extracting a date/time stamp out of some XML; however, I need to strip out the time from the string. i.e. - 3/7...
by efelder0 Communicator in Splunk Search 04-10-2012
0 5
0
5
antifreke
All of the Event's in Splunk have MAL,WM,W32,Troj,CXmal,JS,or Vir in their name. Is there a way to separate all of th...
by antifreke Path Finder in Splunk Search 04-10-2012
0 3
0
3
efelder0
I am trying to reformat a date field in Splunk. I have a field called "last_updated_date" and its value is 2012-04-03...
by efelder0 Communicator in Splunk Search 04-09-2012
2 5
2
5
boris
All fields from a lookup.csv file appear as available search fields except the date field. Here is how I defined the...
by boris Path Finder in Splunk Search 04-09-2012
0 3
0
3
misteryuku
I have a problem creating new search time field extractions using the Splunk's REST API and the Java SDK. This is th...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
misteryuku
I have created a new field extraction on props.conf via Splunk REST API I have a raw message that looks like this. f...
by misteryuku Communicator in Splunk Search 04-08-2012
0 1
0
1
tb582
I have a search using transaction and the startswith/endswith but I don't know how to call the Task_time field in the...
by tb582 Explorer in Splunk Search 04-08-2012
0 13
0
13
michaeljlancast
I have a timechart that shows me the daily throughput for a log source per indexer. I'm trying to find a way to add ...
by michaeljlancast Explorer in Splunk Search 04-08-2012
1 3
1
3
tb582
I'm looking to find everything that has the string "Task Failed". I want splunk to get the task_id and then use all t...
by tb582 Explorer in Splunk Search 04-08-2012
0 4
0
4
tb5821
new to splunk so go easy on me I can currently run two different searches and get the the results I'm looking for bu...
by tb5821 Communicator in Splunk Search 04-07-2012
0 5
0
5
hmahendrakumar
I am looking for a search that will list the concurrent searches(jobs) running that were running on the machine for a...
by hmahendrakumar Path Finder in Splunk Search 04-06-2012
6 4
6
4
chris
Hi I have defined a field for different types of events, the field is recognized in all the events I want to see it....
by chris Motivator in Splunk Search 04-06-2012
1 3
1
3
nebel
Hi, is it possible to merge two or more event results in one? The events are from the same field. Reason : I have a...
by nebel Communicator in Splunk Search 04-06-2012
0 2
0
2
mjones414
Trying to compare the results of a lookup table to a field I'm creating by using mvindex and I can get it to join and...
by mjones414 Contributor in Splunk Search 04-06-2012
1 1
1
1
mikefoti
My ultimate goal is to create a regex expression that can be used use to extract fields from any record made up comma...
by mikefoti Communicator in Splunk Search 04-05-2012
0 3
0
3
talbot7
Trying to show the top 10 busiest guest VM's in mu environment. Each guest VM is reporting its network status in the ...
by talbot7 Path Finder in Splunk Search 04-05-2012
0 1
0
1
Glenn
I know how to exclude certain days from your search results: http://splunk-base.splunk.com/answers/1367/how-do-you-ex...
by Glenn Builder in Splunk Search 04-05-2012
0 5
0
5
gowen
How can I filter events based on two things being true in transforms.conf? Specifically, let's say that I want to fi...
by gowen Path Finder in Splunk Search 04-05-2012
0 4
0
4
ifsuser
Hi im trying to extract domain usernames from my juniper log files using regex however depending on the log message t...
by ifsuser New Member in Splunk Search 04-05-2012
0 6
0
6
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...