Splunk Search

Splunk Search
Community Activity
jroysdon
How can I export information from Websense? WCG as a Proxy running on RHEL5 and the rest running on a W2K8 server.
by jroysdon Engager in Splunk Search 03-26-2012
1 2
1
2
mlulmer
Current EVENT logs from estreamer client pulls the following example record: Tue Nov 1 23:59:59 2011 sensor_id=66 ...
by mlulmer Explorer in Splunk Search 03-26-2012
1 2
1
2
jewhite
I want to find clientip's (in apache access_combined logs) where more than one event occurred (e.g. status=200 file=F...
by jewhite Explorer in Splunk Search 03-26-2012
0 9
0
9
john
source="D:\SplunkLogs\status.log" |search data|rex field=_raw "control\s(?.*)" |stats values(myvalue)|where myvalue="...
by john Communicator in Splunk Search 03-26-2012
0 2
0
2
tonan
Hi Want to extract specific fields from a log file. Tried using rex but failed.. need help Want to extract matching ...
by tonan Explorer in Splunk Search 03-26-2012
0 3
0
3
diwa
I'm using the free version, Is there is a way to backup the syslog from the splunk ? Once the size limit exceed 500 M...
by diwa New Member in Splunk Search 03-26-2012
0 2
0
2
0cool
I'm looking for a way to dedup a given field for each instance of another field. More specifically: | eval warningIs...
by 0cool New Member in Splunk Search 03-24-2012
0 1
0
1
DrColombes
In Splunk 4.3 I want to do a join of an regex-extracted variable A (belonging to app/sourcetype a) with a variable B ...
by DrColombes New Member in Splunk Search 03-24-2012
0 1
0
1
Nicholas_Key
How does the 'optimized' splunk search string (without using JOIN) looks like for the following search string? SELEC...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 03-23-2012
0 1
0
1
wandi
bla xx bla Call Return: [20001TNSN NONONOONONO] bla y bla Call Return: [20001TNSN NONONOONONO] bla zzz bla Call Retur...
by wandi Explorer in Splunk Search 03-23-2012
0 3
0
3
hbazan
Hi, I need to make a ranking of most common exception messages, from different services. I've been able to extract th...
by hbazan Path Finder in Splunk Search 03-23-2012
0 3
0
3
melonman
Hi I am creating a search for sendmail log on multiple mail servers to obtain time taken to relay between MTA and e...
by melonman Motivator in Splunk Search 03-23-2012
1 1
1
1
misteryuku
I set the key=value pairs into the body of the REST HTTP request directly using Java REST SDK API. Example : Reque...
by misteryuku Communicator in Splunk Search 03-22-2012
0 1
0
1
cvajs
v4.3.1 linux so why piping top | top dont work? index=cisco_firewall | top error_code limit=5 | top src limit=10 ce...
by cvajs Contributor in Splunk Search 03-22-2012
0 6
0
6
jam678
So I've been asked to determine what the top 5 events are on our network from the traffic, which is simple enough, bu...
by jam678 Explorer in Splunk Search 03-22-2012
0 6
0
6
melonman
Hi I am trying to create a timechart report that displays both average of a numeric value of last 7 days and real ti...
by melonman Motivator in Splunk Search 03-22-2012
0 1
0
1
phoenixdigital
We are currently indexing data which contains predicted values for data into the future. I am having trouble working...
by phoenixdigital Builder in Splunk Search 03-22-2012
0 2
0
2
gfoligna0
We're working with really long queries (with a lot of excludes) and we're looking for a solution to short the query a...
by gfoligna0 Explorer in Splunk Search 03-22-2012
1 3
1
3
cvajs
v4.3.1 linux how do you create a search that mimics iteration like in bash for i in ls /root ;do ls -al $i > out.txt ...
by cvajs Contributor in Splunk Search 03-22-2012
0 4
0
4
tb5821
can anyone provide me with a way to have Splunk convert an extracted field which is currently in milliseconds to HH:M...
by tb5821 Communicator in Splunk Search 03-22-2012
0 1
0
1
gnovak
I have a dashboard that is displaying 3 charts and a table. In the 3 charts the legend mostly consists the source pa...
by gnovak Builder in Splunk Search 03-22-2012
0 10
0
10
wajihullahbaig
I am new to splunk. Just 3 odd days at it. I have been using Lucene for indexing and searching raw data in forms of f...
by wajihullahbaig Explorer in Splunk Search 03-22-2012
1 1
1
1
SarahWKarvenz
I have the following search: stats count by jvm category host This returns a table with the headings count, jvm, hos...
by SarahWKarvenz Path Finder in Splunk Search 03-21-2012
0 2
0
2
derekleuridan
Hi there, I am getting "The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration '...
by derekleuridan New Member in Splunk Search 03-21-2012
0 1
0
1
grhick
I am trying to create a table or timechart that tracks averages for an event from the 3rd Tuesday of every month to t...
by grhick New Member in Splunk Search 03-21-2012
0 2
0
2
Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...