| How does the 'optimized' splunk search string (without using JOIN) looks like for the following search string? SELEC... by Nicholas_Key Splunk Employee 0 1 | 0 | 1 | ||
| bla xx bla Call Return: [20001TNSN NONONOONONO] bla y bla Call Return: [20001TNSN NONONOONONO] bla zzz bla Call Retur... by wandi Explorer in Splunk Search 03-23-2012 0 3 | 0 | 3 | ||
| Hi, I need to make a ranking of most common exception messages, from different services. I've been able to extract th... by hbazan Path Finder in Splunk Search 03-23-2012 0 3 | 0 | 3 | ||
| Hi I am creating a search for sendmail log on multiple mail servers to obtain time taken to relay between MTA and e... by melonman Motivator in Splunk Search 03-23-2012 1 1 | 1 | 1 | ||
| I set the key=value pairs into the body of the REST HTTP request directly using Java REST SDK API. Example : Reque... by misteryuku Communicator in Splunk Search 03-22-2012 0 1 | 0 | 1 | ||
| v4.3.1 linux so why piping top | top dont work? index=cisco_firewall | top error_code limit=5 | top src limit=10 ce... by cvajs Contributor in Splunk Search 03-22-2012 0 6 | 0 | 6 | ||
| So I've been asked to determine what the top 5 events are on our network from the traffic, which is simple enough, bu... by jam678 Explorer in Splunk Search 03-22-2012 0 6 | 0 | 6 | ||
| Hi I am trying to create a timechart report that displays both average of a numeric value of last 7 days and real ti... by melonman Motivator in Splunk Search 03-22-2012 0 1 | 0 | 1 | ||
| We are currently indexing data which contains predicted values for data into the future. I am having trouble working... by phoenixdigital Builder in Splunk Search 03-22-2012 0 2 | 0 | 2 | ||
| We're working with really long queries (with a lot of excludes) and we're looking for a solution to short the query a... by gfoligna0 Explorer in Splunk Search 03-22-2012 1 3 | 1 | 3 | ||
| v4.3.1 linux how do you create a search that mimics iteration like in bash for i in ls /root ;do ls -al $i > out.txt ... by cvajs Contributor in Splunk Search 03-22-2012 0 4 | 0 | 4 | ||
| can anyone provide me with a way to have Splunk convert an extracted field which is currently in milliseconds to HH:M... by tb5821 Communicator in Splunk Search 03-22-2012 0 1 | 0 | 1 | ||
| I have a dashboard that is displaying 3 charts and a table. In the 3 charts the legend mostly consists the source pa... by gnovak Builder in Splunk Search 03-22-2012 0 10 | 0 | 10 | ||
| I am new to splunk. Just 3 odd days at it. I have been using Lucene for indexing and searching raw data in forms of f... by wajihullahbaig Explorer in Splunk Search 03-22-2012 1 1 | 1 | 1 | ||
| I have the following search: stats count by jvm category host This returns a table with the headings count, jvm, hos... by SarahWKarvenz Path Finder in Splunk Search 03-21-2012 0 2 | 0 | 2 | ||
| Hi there, I am getting "The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration '... by derekleuridan New Member in Splunk Search 03-21-2012 0 1 | 0 | 1 | ||
| I am trying to create a table or timechart that tracks averages for an event from the 3rd Tuesday of every month to t... by grhick New Member in Splunk Search 03-21-2012 0 2 | 0 | 2 | ||
| I've been able to extract Postfix Queue ID's out of sourcetype="postfix_syslog" however often logs have multiple Queu... by thartmann Path Finder in Splunk Search 03-21-2012 2 4 | 2 | 4 | ||
| 0 | 2 | |||
| v4.3.1 linux so apparently Splunk will not execute nested functions. example | stats count,values(src),count(values... by cvajs Contributor in Splunk Search 03-20-2012 0 3 | 0 | 3 | ||
| I have files in a directory like this: /home/user/files/servername_01020304050607.log How can I get the servername o... by tiernan New Member in Splunk Search 03-20-2012 0 2 | 0 | 2 | ||
| Scenario: Project Splunk Deployment: 1 indexer with ~250 Windows forwarders, a few Linux, and various other switch... by rgcox1 Communicator in Splunk Search 03-20-2012 1 3 | 1 | 3 | ||
| From my list of field in Splunk, I have three fields with numeric values that I would like to add together and assign... by efelder0 Communicator in Splunk Search 03-20-2012 0 1 | 0 | 1 | ||
| We have multiple splunk servers accessed by two central search heads, and some of these splunk servers are spread out... by sonicZ Contributor in Splunk Search 03-20-2012 0 2 | 0 | 2 | ||
| I am trying to find a way to turn an IP address into CIDR format to group by reports. Ideally, I'd be able to do some... by jeff Contributor in Splunk Search 03-20-2012 0 3 | 0 | 3 |