Splunk Search

Splunk Search
Community Activity
Simeon
I have a scripted input that takes in rpm -qa output and want to find out the difference in packages installed on two...
by Simeon Splunk Employee Splunk Employee in Splunk Search 02-16-2012
0 1
0
1
atreece
I am working on a game, and have been asked to create an interesting dashboard. My superiors want to know how long it...
by atreece Path Finder in Splunk Search 02-16-2012
0 8
0
8
greg
I'm trying to compose a search like this: sourcetype=A | eval param=ceil(SomeField) | join Name [search sourcetype=B...
by greg Communicator in Splunk Search 02-16-2012
0 2
0
2
mundus
It seems that non-admin users are only able to have three searches running simultaneously. Is there a way to increas...
by mundus Path Finder in Splunk Search 02-15-2012
0 1
0
1
steveirogers
I have seen several questions about restricting access to "Manager" but all of the answers seem to require coding Jav...
by steveirogers Communicator in Splunk Search 02-15-2012
0 6
0
6
jcbrendsel
I am wrapping numerically names fields in $...$ to force splunk to interpret them as field names. This works great i...
by jcbrendsel Path Finder in Splunk Search 02-15-2012
1 6
1
6
gerald_huddlest
iam trying to extarct the room name fromt eh string below but the automatioc filed extraction does not fined enough e...
by gerald_huddlest Path Finder in Splunk Search 02-15-2012
0 1
0
1
eFlea
I'm running Splunk v4.1.5, and I'm trying to specify a time range in my search so that I can find events within a cer...
by eFlea New Member in Splunk Search 02-15-2012
0 2
0
2
kml_uvce
I am trying to get restful service from splunk curl -k -u username:password -k https:///services/search/jobs -d sea...
by kml_uvce Builder in Splunk Search 02-15-2012
0 1
0
1
namanjoshi
Hi, I running Splunk 4.1.6 and I'm trying to create a role which allows the user to only have read access to the Sea...
by namanjoshi Explorer in Splunk Search 02-14-2012
0 5
0
5
zservati
I am trying to perform a search and using regx and parameter can summarize the result based on two fields which are f...
by zservati Explorer in Splunk Search 02-14-2012
0 1
0
1
subhadipc
I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example...
by subhadipc Explorer in Splunk Search 02-14-2012
0 4
0
4
ryanmims
I have just turned on compression and have over 100 GB of uncompressed data. How can I compress it and Splunk still b...
by ryanmims Explorer in Splunk Search 02-14-2012
0 3
0
3
mundus
I'm following the instructions for implementing a reverse DNS lookup at search time. I either get an error saying th...
by mundus Path Finder in Splunk Search 02-14-2012
0 1
0
1
kiersti
I have the start of a query but I can't get it to limit a look up by time. I need to use the converted field sent_ti...
by kiersti Engager in Splunk Search 02-14-2012
0 1
0
1
rcovert
I am trying to do something very simple but cannot figure it out. I am new to splunk and using the web intelligence ...
by rcovert Path Finder in Splunk Search 02-14-2012
0 2
0
2
dwaddle
There is a similar question related to changing debug levels at runtime. But, what if I'm doing this on a Universal ...
by SplunkTrust SplunkTrust in Splunk Search 02-13-2012
3 3
3
3
jaoui
I am receiving logs that show me when a mac address appears on my network switch and when it is removed logs i recei...
by jaoui Path Finder in Splunk Search 02-13-2012
0 3
0
3
ssingh5
How can create a table containg date and time of oldest and most recent log per index in splunk ?
by ssingh5 Path Finder in Splunk Search 02-13-2012
0 1
0
1
willthames2
I can replicate this behaviour within a search head pool by Add a Lookup Table, and upload a CSV fileChange permissi...
by willthames2 Path Finder in Splunk Search 02-12-2012
1 2
1
2
astepanov
I need to find transactions that failed to complete. Transaction go across 4 systems, from front-end to back-end sys...
by astepanov Explorer in Splunk Search 02-11-2012
1 1
1
1
splunker_jim
Hi there, I have an computationally expensive query which is (manually) run on the main index. Instead of running it...
by splunker_jim Explorer in Splunk Search 02-10-2012
2 4
2
4
a212830
Hi, I'm trying to extract a field from a source, and when I test it, it appears to work, but in practice, it's grabb...
by a212830 Champion in Splunk Search 02-10-2012
0 8
0
8
subhadipc
I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example...
by subhadipc Explorer in Splunk Search 02-10-2012
0 1
0
1
gerald_huddlest
hi I have created an eventtype that looks for a certain event across 12 servers (cmchost). I created a dashboard show...
by gerald_huddlest Path Finder in Splunk Search 02-10-2012
0 4
0
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...