Thread Info | |||||
---|---|---|---|---|---|
Hey everyone, I am working on an issue right now and I'm running into a problem with my understanding of how splunk w...
by
msarro
Builder
in
Splunk Search
08-25-2011
|
3
|
4
| |||
I am wondering if we can change a search on a dashboard based upon the time range selected.
EG: I have a hidden se...
by
jdunlea_splunk
Splunk Employee
in
Splunk Search
10-05-2011
|
1
|
2
| |||
Hi,
Currently, I'm getting number of users logged in last 24 hrs as below...
index=myindex sourcetype="my_log" ...
by
freephoneid
Path Finder
in
Splunk Search
10-04-2011
|
0
|
5
| |||
Trying to click on an item in the legend and have a new search come up based on item clicked.
Here is my current w...
by
talbot7
Path Finder
in
Splunk Search
10-04-2011
|
0
|
1
| |||
I am using Exchange 2007 SP3 and it appears that my logs are flowing to the Splunk Instance. Some of the searches and...
by
donwant
Explorer
in
Splunk Search
09-27-2011
|
0
|
1
| |||
Hi, all.
I was asked to get Exchange logs from an Exchange 2010 cluster going to Splunk. I've installed a forwarde...
by
tgiles
Path Finder
in
Splunk Search
09-02-2011
|
1
|
2
| |||
I have a vendor log file that has numeric codes for the field names (i.e. E-1, E-710, etc). The vendor also provides ...
by
cgl
Explorer
in
Splunk Search
10-03-2011
|
2
|
6
| |||
I want to extract two adjacent events, i.e., the first one with keyword "synchronization" and the event immediately f...
by
myli12
Path Finder
in
Splunk Search
10-04-2011
|
0
|
1
| |||
I trying to rename sourcetype for this regex but won't work but when i remove the rename = httpd-access its work?
...
by
catty
Engager
in
Splunk Search
10-03-2011
|
0
|
2
| |||
Hi,
I have log messages like this:
1) ECMSELECT_SERVICE_RESPONSEReceived Tru2way Proxy Sync Response - selectSe...
by
anushamkrishna
New Member
in
Splunk Search
09-28-2011
|
0
|
1
| |||
I've clearly munged something in my transform:
# props.conf
[snmp-trap]
pulldown_type = true
maxDist = 3
TIME_FO...
by
jlixfeld
Path Finder
in
Splunk Search
10-03-2011
|
1
|
3
| |||
Hi,
Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact sa...
by
tgiles
Path Finder
in
Splunk Search
04-12-2011
|
0
|
3
| |||
I'm using the following search using Splunk 4.2.1:
sourcetype=somesourcetype (tag=Metric AND tag=ResponseTime) NOT...
by
johnboldt
Explorer
in
Splunk Search
09-30-2011
|
1
|
2
| |||
Hi,
I would like to know how exactly scheduled saved search works.
I've a saved search for which I gave the tim...
by
freephoneid
Path Finder
in
Splunk Search
09-30-2011
|
0
|
3
| |||
Hi,
I've below log lines in below format:
[2011-09-30 23:33:20:465 GMT+00:00][F3951B38F4DF45440927EDF522D5C9FF....
by
freephoneid
Path Finder
in
Splunk Search
10-02-2011
|
0
|
3
| |||
<module Search>
<search> search string </search>
<module resultTable>
<module Redirect autorun="true"> ...
by
joy76
Path Finder
in
Splunk Search
09-30-2011
|
0
|
1
| |||
When I search for: index=unix pool=general1 dom0stat42 | delta stolen_cpu_ticks as sct | eval abssct=abs(sct) | ti...
by
talbot7
Path Finder
in
Splunk Search
09-30-2011
|
1
|
2
| |||
Hi,
I want to find out how many users have blue colors & how many of them have red color for all unique users?
...
by
freephoneid
Path Finder
in
Splunk Search
09-30-2011
|
0
|
1
| |||
in the manual: http://docs.splunk.com/Documentation/Splunk/4.2.3/Deploy/Mounttheknowledgebundle#Use_mounted_bundles_w...
by
tpsplunk
Communicator
in
Splunk Search
09-14-2011
|
2
|
3
| |||
I am trying to write a query to return host, source, last updated. However, it appears as though the source and host ...
by
tmurray3
Path Finder
in
Splunk Search
09-30-2011
|
1
|
2
| |||
Sorry for the horrible title but I cannot think of a good, succinct description of the problem I am trying to solve (...
by
Wilcooley
Path Finder
in
Splunk Search
09-29-2011
|
1
|
1
| |||
My search looks like this:
index=webproxy | regex user=".+a" | top 100 user
results are j9999la
I want to ...
by
mcbradford
Contributor
in
Splunk Search
09-29-2011
|
0
|
3
| |||
Hi, I would to know if it is possible to use a part of the source events file path ie "foobar" from
/weblogs/123/h...
by
pl123
Path Finder
in
Splunk Search
01-19-2011
|
1
|
3
| |||
I'm trying to extract these values into a field called Data.
from sample 1: CMD(XYZ) Val(*12A)
In props.conf
...
by
remy06
Contributor
in
Splunk Search
09-30-2011
|
0
|
10
| |||
My set up is that I have splunk forwarders sending data to two load balanced indexers. I then have a search head that...
by
builder
Path Finder
in
Splunk Search
06-16-2011
|
2
|
6
|