Discussions
Thread Info | |||||
---|---|---|---|---|---|
I want to format nicely the fields or events at search time.
by example : US phone : 11122223333 to (111) 222-3333...
by
mataharry
Communicator
in
Splunk Search
12-21-2011
|
0
|
1
| |||
I'm trying to write a search that will compare values from different data inputs and return the highest value to use ...
by
achudnoff
Explorer
in
Splunk Search
12-20-2011
|
0
|
2
| |||
Is there a way to perform an eval when using an automatic lookup? I'm using user IDs in IIS logs to find a user's rea...
by
Bulluk
Path Finder
in
Splunk Search
12-15-2011
|
1
|
6
| |||
I'm trying to combine the results of a search and subsearch. They have overlapping fields but different result sets. ...
by
atornes
Path Finder
in
Splunk Search
12-15-2011
|
0
|
1
| |||
I am trying to assign a value to a Severity field when the sourcetype = "low" or "Med" or "high".
I.e. - IF source...
by
efelder0
Communicator
in
Splunk Search
12-20-2011
|
1
|
6
| |||
I add this to props.conf to detect shellscripts, but interesting enough this not only matches shell-scripts but also ...
by
flo_cognosec
Communicator
in
Splunk Search
12-16-2011
|
0
|
1
| |||
for example, i have the following 7 logs,
2011-DEC-17 slotid="Location-Maps-US-Sunnyvale" delta_msec="1487" seq="3...
by
xiaoyuew
Path Finder
in
Splunk Search
12-20-2011
|
0
|
1
| |||
Hi
Is there any way to write the search results (in table format) in to a lookup table
i.e... | table field1,fe...
by
adityapavan18
Contributor
in
Splunk Search
12-21-2011
|
1
|
1
| |||
I would like to calculate the total for the following sample. These are numbers but have comma.
122
3,871
17,896
...
by
rksubbu
Explorer
in
Splunk Search
12-19-2011
|
2
|
6
| |||
My logs contain a field "A", i need to calculate a new field "B" based on the SLOT, when A=a1 OR A=a2, THEN B=avg of...
by
xiaoyuew
Path Finder
in
Splunk Search
12-19-2011
|
0
|
2
| |||
Hello,
I'm having an issue with a regex i did. I want to create a new column with my regex where there's 2 values ...
by
rbw78
Communicator
in
Splunk Search
12-20-2011
|
0
|
3
| |||
Hi there!
I'm looking at this previous question here:
[http://splunk-base.splunk.com/answers/2602/can-splunk-fi...
by
gnovak
Builder
in
Splunk Search
12-19-2011
|
0
|
2
| |||
my field extractions are not working
tranforms.conf file is [tms_iisfields] FIELDS = "date","time","s-ip","cs-met...
by
kml_uvce
Builder
in
Splunk Search
12-19-2011
|
0
|
3
| |||
i have yet to get lookups to work correctly in an app.
The file is in the right place
/opt/splunk/etc/apps/my...
by
robgreen
Path Finder
in
Splunk Search
12-18-2011
|
0
|
3
| |||
I am trying to extract the fields from an Oracle 10g Audit trail. Below is a sample of the raw log :
Tue Feb 15 10...
by
JSapienza
Contributor
in
Splunk Search
03-08-2011
|
0
|
6
| |||
Hello, I have a source that contains events like these:
"MONEY LEFT: 1.000,00"
"MONEY LEFT: 000,00"
"MONEY LEFT: 3...
by
cafissimo
Communicator
in
Splunk Search
12-17-2010
|
0
|
3
| |||
Splunk's scrub command scrub data in queries/report. What are the steps to permanently remove certain logs from Splun...
by
qas
Engager
in
Splunk Search
04-13-2011
|
3
|
3
| |||
I'm getting this error message twice every 30 sec. 12-19-2011 12:15:27.539 -0500 ERROR AuthenticationManagerLDAP - Co...
by
wbfoxii
Communicator
in
Splunk Search
12-19-2011
|
1
|
3
| |||
I am trying to set my host name equal to part of the file name with a regex (regular expression) and I am a regex nov...
by
ianathompson
Explorer
in
Splunk Search
12-18-2011
|
0
|
1
| |||
Hello,
I have data in the form of a date,server,events triplet. The fields are correctly extracted and assigned.
...
by
wsw70
Communicator
in
Splunk Search
12-19-2011
|
0
|
2
| |||
Hi I have an index named pci and the location of this is /windows/pci/db i want move it(existing and new) in another ...
by
kml_uvce
Builder
in
Splunk Search
12-19-2011
|
0
|
1
| |||
Hi
I have a problem with the field extraction. I am trying to extract out and name a field containing the data "--...
by
the3nd4u
New Member
in
Splunk Search
12-17-2011
|
0
|
1
| |||
We have couple of credit card data in splunk and we need to remove those from the splunk. I am using the below query ...
by
npandith
Explorer
in
Splunk Search
12-17-2011
|
0
|
1
| |||
I am attempting to Index a file once from my Splunk server. The file contains a copy of syslog data.
The lines loo...
by
stefanlasiewski
Contributor
in
Splunk Search
12-13-2011
|
0
|
6
| |||
I'm trying to integrate information from this link http://splunk-base.splunk.com/answers/13482/plotting-trendlines-in...
by
DTERM
Contributor
in
Splunk Search
12-14-2011
|
0
|
3
|