Splunk Search

Splunk Search
Community Activity
eFlea
I'm running Splunk v4.1.5, and I'm trying to specify a time range in my search so that I can find events within a cer...
by eFlea New Member in Splunk Search 02-15-2012
0 2
0
2
kml_uvce
I am trying to get restful service from splunk curl -k -u username:password -k https:///services/search/jobs -d sea...
by kml_uvce Builder in Splunk Search 02-15-2012
0 1
0
1
namanjoshi
Hi, I running Splunk 4.1.6 and I'm trying to create a role which allows the user to only have read access to the Sea...
by namanjoshi Explorer in Splunk Search 02-14-2012
0 5
0
5
zservati
I am trying to perform a search and using regx and parameter can summarize the result based on two fields which are f...
by zservati Explorer in Splunk Search 02-14-2012
0 1
0
1
subhadipc
I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example...
by subhadipc Explorer in Splunk Search 02-14-2012
0 4
0
4
ryanmims
I have just turned on compression and have over 100 GB of uncompressed data. How can I compress it and Splunk still b...
by ryanmims Explorer in Splunk Search 02-14-2012
0 3
0
3
mundus
I'm following the instructions for implementing a reverse DNS lookup at search time. I either get an error saying th...
by mundus Path Finder in Splunk Search 02-14-2012
0 1
0
1
kiersti
I have the start of a query but I can't get it to limit a look up by time. I need to use the converted field sent_ti...
by kiersti Engager in Splunk Search 02-14-2012
0 1
0
1
rcovert
I am trying to do something very simple but cannot figure it out. I am new to splunk and using the web intelligence ...
by rcovert Path Finder in Splunk Search 02-14-2012
0 2
0
2
dwaddle
There is a similar question related to changing debug levels at runtime. But, what if I'm doing this on a Universal ...
by SplunkTrust SplunkTrust in Splunk Search 02-13-2012
3 3
3
3
jaoui
I am receiving logs that show me when a mac address appears on my network switch and when it is removed logs i recei...
by jaoui Path Finder in Splunk Search 02-13-2012
0 3
0
3
ssingh5
How can create a table containg date and time of oldest and most recent log per index in splunk ?
by ssingh5 Path Finder in Splunk Search 02-13-2012
0 1
0
1
willthames2
I can replicate this behaviour within a search head pool by Add a Lookup Table, and upload a CSV fileChange permissi...
by willthames2 Path Finder in Splunk Search 02-12-2012
1 2
1
2
astepanov
I need to find transactions that failed to complete. Transaction go across 4 systems, from front-end to back-end sys...
by astepanov Explorer in Splunk Search 02-11-2012
1 1
1
1
splunker_jim
Hi there, I have an computationally expensive query which is (manually) run on the main index. Instead of running it...
by splunker_jim Explorer in Splunk Search 02-10-2012
2 4
2
4
a212830
Hi, I'm trying to extract a field from a source, and when I test it, it appears to work, but in practice, it's grabb...
by a212830 Champion in Splunk Search 02-10-2012
0 8
0
8
subhadipc
I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example...
by subhadipc Explorer in Splunk Search 02-10-2012
0 1
0
1
gerald_huddlest
hi I have created an eventtype that looks for a certain event across 12 servers (cmchost). I created a dashboard show...
by gerald_huddlest Path Finder in Splunk Search 02-10-2012
0 4
0
4
lennyburns
I created 8 data inputs, each one is supposed to tail log files mathing a certain whitelist regex. These inputs see t...
by lennyburns Path Finder in Splunk Search 02-10-2012
1 20
1
20
FRoth
I am currently experimenting with the nmap scan output format and indexing the scan results with splunk. I noticed ...
by FRoth Contributor in Splunk Search 02-10-2012
0 1
0
1
kiersti
I have this field in my logs mail_date=08 Feb 2012. But it's not logging as a date or a number so I can't run time-b...
by kiersti Engager in Splunk Search 02-09-2012
2 2
2
2
dave_rook
I'm using this query right now: stats count by host, source, date_mday It only lists Linux hosts but lists the data ...
by dave_rook Engager in Splunk Search 02-09-2012
0 3
0
3
rajbahak
Hello, I need to be able to configure universal forwarder with more than one indexing server from the command line. ...
by rajbahak Path Finder in Splunk Search 02-09-2012
0 2
0
2
joshrabinowitz
upgraded from 4.2.5 to 4.3 and now all searches timeout, and saved searches take longer to run. hw is 2x 4-core opter...
by joshrabinowitz Path Finder in Splunk Search 02-09-2012
2 1
2
1
efelder0
I am extracting a field out of an XML feed. More specifically, this is the field: 2012-01-30T12:57:20/x:LastUpdated ...
by efelder0 Communicator in Splunk Search 02-09-2012
0 3
0
3
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...