Splunk Search

Splunk Search
Community Activity
Ellen
In 4.3 the search flashtime, sometimes the same query will return a full set of result rows in the events list but ot...
by Ellen Splunk Employee Splunk Employee in Splunk Search 03-28-2012
3 1
3
1
Rhuen
Hy, i dont know why, but since 5 days i become no more Event Logs from Client PC's (Windows XP). When i remote conn...
by Rhuen New Member in Splunk Search 03-28-2012
0 4
0
4
misteryuku
I inserted a search command in a splunk search app as follows : sourcetype="sexuality" | replace "Yan Yi" with jtyi i...
by misteryuku Communicator in Splunk Search 03-27-2012
0 5
0
5
hjwang
Dear all There is something strange that i can see the correct results of field extraction from manually search but ...
by hjwang Contributor in Splunk Search 03-27-2012
0 1
0
1
misteryuku
For the search app, I want to modify a field called "partner" (new field added when data is sent to Splunk in receive...
by misteryuku Communicator in Splunk Search 03-27-2012
0 1
0
1
esweeney
Time savings? Cost savings? New product offering? New business opportunity? New customers? Promotions? Once you under...
by esweeney Splunk Employee Splunk Employee in Splunk Search 03-27-2012
9 3
9
3
esweeney
How do I register for .conf2012: The 3rd Annual Splunk's Users' Conference?
by esweeney Splunk Employee Splunk Employee in Splunk Search 03-27-2012
12 5
12
5
jconger
I'm trying to get CPU statistics for servers that have a variable number of CPUs. Below are some fictitious events i...
by jconger Splunk Employee Splunk Employee in Splunk Search 03-27-2012
0 1
0
1
Ayn
Whenever a backslash is used in questions/answers/comments on splunk-base, another backslash will be added. For ins...
by Legend in Splunk Search 03-27-2012
7 2
7
2
misteryuku
Since fields in Splunk are generally not set at index-time, except for a few key values like source, sourcetype, _raw...
by misteryuku Communicator in Splunk Search 03-27-2012
0 4
0
4
conner9
I am trying to extract the hostname from the name of the file selected as input. For input setup I have the followin...
by conner9 Path Finder in Splunk Search 03-27-2012
0 2
0
2
gofrolist
Hello, I need to anonimize data in search-time and count by message. Example. source log file contains: E 120327 ...
by gofrolist New Member in Splunk Search 03-27-2012
0 1
0
1
pborucki
Hello, I am new to Splunk and I ma trying to analyze my logfile and create graph for two avg fields by each present ...
by pborucki New Member in Splunk Search 03-27-2012
0 1
0
1
tyronetv
I am attempting to translate system response codes to natural language for business reasons. I have 7 codes that rela...
by tyronetv Communicator in Splunk Search 03-27-2012
0 1
0
1
misteryuku
I added events through Splunk's REST API and i added new fields to the new events that i added to Splunk. Then i sea...
by misteryuku Communicator in Splunk Search 03-26-2012
0 1
0
1
jroysdon
How can I export information from Websense? WCG as a Proxy running on RHEL5 and the rest running on a W2K8 server.
by jroysdon Engager in Splunk Search 03-26-2012
1 2
1
2
mlulmer
Current EVENT logs from estreamer client pulls the following example record: Tue Nov 1 23:59:59 2011 sensor_id=66 ...
by mlulmer Explorer in Splunk Search 03-26-2012
1 2
1
2
jewhite
I want to find clientip's (in apache access_combined logs) where more than one event occurred (e.g. status=200 file=F...
by jewhite Explorer in Splunk Search 03-26-2012
0 9
0
9
john
source="D:\SplunkLogs\status.log" |search data|rex field=_raw "control\s(?.*)" |stats values(myvalue)|where myvalue="...
by john Communicator in Splunk Search 03-26-2012
0 2
0
2
tonan
Hi Want to extract specific fields from a log file. Tried using rex but failed.. need help Want to extract matching ...
by tonan Explorer in Splunk Search 03-26-2012
0 3
0
3
diwa
I'm using the free version, Is there is a way to backup the syslog from the splunk ? Once the size limit exceed 500 M...
by diwa New Member in Splunk Search 03-26-2012
0 2
0
2
0cool
I'm looking for a way to dedup a given field for each instance of another field. More specifically: | eval warningIs...
by 0cool New Member in Splunk Search 03-24-2012
0 1
0
1
DrColombes
In Splunk 4.3 I want to do a join of an regex-extracted variable A (belonging to app/sourcetype a) with a variable B ...
by DrColombes New Member in Splunk Search 03-24-2012
0 1
0
1
Nicholas_Key
How does the 'optimized' splunk search string (without using JOIN) looks like for the following search string? SELEC...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 03-23-2012
0 1
0
1
wandi
bla xx bla Call Return: [20001TNSN NONONOONONO] bla y bla Call Return: [20001TNSN NONONOONONO] bla zzz bla Call Retur...
by wandi Explorer in Splunk Search 03-23-2012
0 3
0
3
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...