Splunk Search

Splunk Search
Community Activity
ysdeos
Hi! Every time a user enters my system, I report his userId. I tried using the DIFF operation to find out which user...
by ysdeos New Member in Splunk Search 02-19-2012
0 1
0
1
EricPartington
I am using splunk to compare the output of routes from a list of firewalls. The output contains a listing of routes....
by EricPartington Communicator in Splunk Search 02-18-2012
0 1
0
1
dpadams
I've got a series of events with a timestamp and two numbers, like so: "2011-05-29 22:54:06",68,31 "2011-08-15 10:20...
by dpadams Communicator in Splunk Search 02-17-2012
0 7
0
7
geek238
Working with stat log events from DJB's dnscache. These look like: @400000004f3ebb59244cc72c stats 275245265 10318...
by geek238 Engager in Splunk Search 02-17-2012
0 3
0
3
Justin
I am trying to write a query that filters our users' network traffic. I would like the query to return information o...
by Justin Path Finder in Splunk Search 02-17-2012
0 3
0
3
Bulluk
Is it possible to recover events that I've filtered out in a search, ie (and I know this is a daft example but it's g...
by Bulluk Path Finder in Splunk Search 02-17-2012
0 11
0
11
arthiv1
Hi, I recently installed splunk on Windows. I was able to login into the Splunk webbased UI. ( http://l-156009194:8...
by arthiv1 Engager in Splunk Search 02-17-2012
0 5
0
5
peppersprayy
I will lay out the scenario, i work in security and I want to look for trending from our VPN users. I want to pass o...
by peppersprayy New Member in Splunk Search 02-17-2012
0 1
0
1
msarro
Hey everyone, I am just trying to figure out how to remove a specific listener via CLI. I can find the command to cre...
by msarro Builder in Splunk Search 02-16-2012
0 2
0
2
Simeon
I have a scripted input that takes in rpm -qa output and want to find out the difference in packages installed on two...
by Simeon Splunk Employee Splunk Employee in Splunk Search 02-16-2012
0 1
0
1
atreece
I am working on a game, and have been asked to create an interesting dashboard. My superiors want to know how long it...
by atreece Path Finder in Splunk Search 02-16-2012
0 8
0
8
greg
I'm trying to compose a search like this: sourcetype=A | eval param=ceil(SomeField) | join Name [search sourcetype=B...
by greg Communicator in Splunk Search 02-16-2012
0 2
0
2
mundus
It seems that non-admin users are only able to have three searches running simultaneously. Is there a way to increas...
by mundus Path Finder in Splunk Search 02-15-2012
0 1
0
1
steveirogers
I have seen several questions about restricting access to "Manager" but all of the answers seem to require coding Jav...
by steveirogers Communicator in Splunk Search 02-15-2012
0 6
0
6
jcbrendsel
I am wrapping numerically names fields in $...$ to force splunk to interpret them as field names. This works great i...
by jcbrendsel Path Finder in Splunk Search 02-15-2012
1 6
1
6
gerald_huddlest
iam trying to extarct the room name fromt eh string below but the automatioc filed extraction does not fined enough e...
by gerald_huddlest Path Finder in Splunk Search 02-15-2012
0 1
0
1
eFlea
I'm running Splunk v4.1.5, and I'm trying to specify a time range in my search so that I can find events within a cer...
by eFlea New Member in Splunk Search 02-15-2012
0 2
0
2
kml_uvce
I am trying to get restful service from splunk curl -k -u username:password -k https:///services/search/jobs -d sea...
by kml_uvce Builder in Splunk Search 02-15-2012
0 1
0
1
namanjoshi
Hi, I running Splunk 4.1.6 and I'm trying to create a role which allows the user to only have read access to the Sea...
by namanjoshi Explorer in Splunk Search 02-14-2012
0 5
0
5
zservati
I am trying to perform a search and using regx and parameter can summarize the result based on two fields which are f...
by zservati Explorer in Splunk Search 02-14-2012
0 1
0
1
subhadipc
I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example...
by subhadipc Explorer in Splunk Search 02-14-2012
0 4
0
4
ryanmims
I have just turned on compression and have over 100 GB of uncompressed data. How can I compress it and Splunk still b...
by ryanmims Explorer in Splunk Search 02-14-2012
0 3
0
3
mundus
I'm following the instructions for implementing a reverse DNS lookup at search time. I either get an error saying th...
by mundus Path Finder in Splunk Search 02-14-2012
0 1
0
1
kiersti
I have the start of a query but I can't get it to limit a look up by time. I need to use the converted field sent_ti...
by kiersti Engager in Splunk Search 02-14-2012
0 1
0
1
rcovert
I am trying to do something very simple but cannot figure it out. I am new to splunk and using the web intelligence ...
by rcovert Path Finder in Splunk Search 02-14-2012
0 2
0
2
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors