Thread Info | |||||
---|---|---|---|---|---|
Greetings, I'm new to splunk and even though I'm extremely impressed with what I have seen/managed to do so far I sti...
by
isrjo
Explorer
in
Splunk Search
11-21-2010
|
0
|
2
| |||
I'm still sifting through the 'realated questsions' proposed in "Ask a Question" (great feature btw), but I don't thi...
by
richard_whiffen
Explorer
in
Splunk Search
11-19-2010
|
0
|
2
| |||
I am trying to create a table (and then a report) of all exceptions/errors that occur for a given sourcetype.
The...
by
seanlon11
Path Finder
in
Splunk Search
11-18-2010
|
0
|
2
| |||
I have a set of data that has one event for ever second, with a field for the number of simultaneous phone calls goin...
by
David
Splunk Employee
in
Splunk Search
11-04-2010
|
1
|
2
| |||
I have syslog from a server sending me logs from /var/log/secure (ssh). But splunk can't seem to read out some stuff ...
by
fisk12
Path Finder
in
Splunk Search
11-14-2010
|
0
|
3
| |||
How to use rex in searchTemplate while form creation? When i try to use following search using rex, it gives me "Inva...
by
Anvita
Explorer
in
Splunk Search
11-19-2010
|
1
|
2
| |||
Hi,all
index=C (sourcetype=A earliest=-3d latest=-2d) OR earliest=-3d latest=now sourcetype=B |transaction keepevi...
by
grio
Engager
in
Splunk Search
11-19-2010
|
0
|
2
| |||
I'm trying to get a time prefix working for the following event:
00:13:11:ee:b7:5e~00:13:11:ee:b7:5d~123.net~123.n...
by
msarro
Builder
in
Splunk Search
11-18-2010
|
1
|
1
| |||
Hi ,
I have three sourcetype. It's a complicated question. I'll try my best to let you understand what I mean.
...
by
flora123
Path Finder
in
Splunk Search
11-18-2010
|
1
|
1
| |||
Hi,
I am trying to figure out how to achieve something and would appreciate any help from your experience.
I ha...
by
Eldad
Explorer
in
Splunk Search
11-18-2010
|
1
|
1
| |||
Hey everyone! I am working on files right now that contain numerous timestamps. The timestamps are presented in this ...
by
msarro
Builder
in
Splunk Search
11-17-2010
|
0
|
2
| |||
I need to calculate average response time (ELT) by service (SVC) if number of trx by service is >5 within the last 4 ...
by
JYTTEJ
Communicator
in
Splunk Search
10-21-2010
|
0
|
3
| |||
Hey,
I want to switch off what seems to be a default function in Splunk.
I am trying to drill down on the follo...
by
Ant1D
Motivator
in
Splunk Search
10-20-2010
|
0
|
2
| |||
Hi,
I'm working on a problem where Splunk is not displaying (sometimes) all indexed events.
The problematic ind...
by
bojanz
Communicator
in
Splunk Search
11-14-2010
|
0
|
2
| |||
I am trying to create a field that contains information about the type of host based on the host field. For example, ...
by
axsolis
Path Finder
in
Splunk Search
11-16-2010
|
1
|
4
| |||
I have log entries looking as follows:
Nov 16 08:37:47 psdkxt05 MID=xxx005I;XID=;SID=;UID=;STM=2010-11-16 08:37:47...
by
JYTTEJ
Communicator
in
Splunk Search
11-18-2010
|
0
|
2
| |||
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by
snowmizer
Communicator
in
Splunk Search
06-28-2010
|
2
|
5
| |||
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by
msarro
Builder
in
Splunk Search
11-15-2010
|
2
|
11
| |||
Couldn't see to find a question like this here, but maybe my search for it is no good.
What I'd like to do is have...
by
skippylou
Communicator
in
Splunk Search
11-17-2010
|
1
|
2
| |||
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by
Marinus
Communicator
in
Splunk Search
07-29-2010
|
4
|
5
| |||
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by
blurblebot
Communicator
in
Splunk Search
11-16-2010
|
1
|
3
| |||
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few t...
by
wmwilson01
Engager
in
Splunk Search
11-16-2010
|
2
|
2
| |||
I would like to find
All Users that have not logged in for 90 days ans active scheduled searches associated with ...
by
sanju005ind
Communicator
in
Splunk Search
11-02-2010
|
0
|
1
| |||
Hi,all
I want to use "substr" to get what I want.
A=1420014
... |eval A=if(substr(A, 1,2)="14",replace(A, "1...
by
flora123
Path Finder
in
Splunk Search
11-16-2010
|
1
|
2
| |||
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac.
I am ...
by
sanju005ind
Communicator
in
Splunk Search
11-12-2010
|
0
|
3
|