Splunk Search

Splunk Search
Community Activity
sdwilkerson
Hello, Does anyone know the frequency that the lea-loggrabber-splunk app's lea_loggrabber process should write to it...
by sdwilkerson Contributor in Splunk Search 02-24-2012
0 1
0
1
sethdill
The situation: A client produces a weekly magazine, in PDF format. There are 17 different versions of the zine each ...
by sethdill Engager in Splunk Search 02-24-2012
0 2
0
2
DFresh4130
So I'm currently searching my jboss access logs for all 500 errors with " 500 ". I get all the results, but then I'd...
by DFresh4130 Path Finder in Splunk Search 02-24-2012
0 1
0
1
greg
Hi! I have two sources A and В. Source A contains events in form of: Id1 StartTime1 EndTime1 Id2 StartTime2 EndTi...
by greg Communicator in Splunk Search 02-24-2012
1 6
1
6
gerald_huddlest
sure this is very similar to other questions but I have not been able to apply any of the suggestions successfully. ...
by gerald_huddlest Path Finder in Splunk Search 02-24-2012
1 1
1
1
orakanggo
How can I join two table in Splunk using query like this? select dialog.id, dialog.callId, dialogParty_dialog_id, at...
by orakanggo New Member in Splunk Search 02-24-2012
0 2
0
2
rbw78
Hello, Is there a solution to specify in my search to get only the logs with the last timestamp ? In fact, i have s...
by rbw78 Communicator in Splunk Search 02-24-2012
0 9
0
9
Dark_Ichigo
when writing a search to create a chart, We all then tend to integrate it into a dashboard as a report. My problem is...
by Dark_Ichigo Builder in Splunk Search 02-23-2012
0 1
0
1
BWRic
Hello, How can I put the chart shown on my search results page into a dashboard widget? I simply want to by able to...
by BWRic New Member in Splunk Search 02-23-2012
0 1
0
1
nate015
amMap works fine using a lookup, but what if the data already has the client_city, client_region, client_country, cli...
by nate015 Explorer in Splunk Search 02-23-2012
0 1
0
1
kml_uvce
I want to delete duplicate events means want only one event and other same event should be deleted.
by kml_uvce Builder in Splunk Search 02-23-2012
1 5
1
5
kml_uvce
My search showing alphabetic order in months(like chart is in this order (dec,feb,jan, nov) |eval month=strftime(s...
by kml_uvce Builder in Splunk Search 02-23-2012
0 4
0
4
SarahWKarvenz
I cannot seem to get my inputs.conf to accept the wildcard in the monitor string. This is my inputs.conf file: [defa...
by SarahWKarvenz Path Finder in Splunk Search 02-22-2012
1 1
1
1
jambajuice
Let's say I have a table that looks like the following: Date Host Port 1/1/2011 HostA 80 1/2/20...
by jambajuice Communicator in Splunk Search 02-22-2012
1 5
1
5
pstamati
Hello everybody. I´m having troubles managing logs that contains strings in spanish that has tilde (ó, á) characters,...
by pstamati Path Finder in Splunk Search 02-22-2012
2 7
2
7
jodros
We are sending anti-virus logs to Splunk. I am trying to create a search that would first, find logs indicating even...
by jodros Builder in Splunk Search 02-22-2012
0 11
0
11
kml_uvce
I have a field like in this format 2012-02-11 This field is in many events with diffrent year-month-day. I want to m...
by kml_uvce Builder in Splunk Search 02-22-2012
0 13
0
13
freephoneid
Hi, My log snippet is as shown below: productid=12 email=abc@gg.com productid=13 email=pqr@aa.com productid=14 emai...
by freephoneid Path Finder in Splunk Search 02-22-2012
0 2
0
2
howyagoin
Hi, I get the feeling that there's a better/faster way for me to do what I'm doing. I have a query such as this: i...
by howyagoin Contributor in Splunk Search 02-22-2012
0 2
0
2
KarunK
Hi ALL, I am using a transaction command to group two events together, "connect" and "disconnect". Both the events...
by KarunK Contributor in Splunk Search 02-21-2012
0 2
0
2
tsingara
I'm running a regular expression on a string which runs for 5 or more lines. The first few words on the first line he...
by tsingara Engager in Splunk Search 02-21-2012
0 1
0
1
DTERM
I'm getting some unexpected results when I run the following query for hosts: index=mydata | top host I expect to s...
by DTERM Contributor in Splunk Search 02-21-2012
1 7
1
7
Yarsa
Hi, I'm trying to create a report that does the same search for two different dates, the regular search uses a transa...
by Yarsa Path Finder in Splunk Search 02-21-2012
1 2
1
2
kml_uvce
I have a requirement in that i have events for diiffrent dates 28,489,BLR 3BC019-Web18,172.22.16.21, Mani Sundaram,7...
by kml_uvce Builder in Splunk Search 02-21-2012
0 2
0
2
KarunK
Hi, I have the following search string which works (sourcetype="cds_fms_access" x_event="*connect" x_status="200") ...
by KarunK Contributor in Splunk Search 02-21-2012
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...