Splunk Search

Splunk Search
Community Activity
ssingh5
How can create a table containg date and time of oldest and most recent log per index in splunk ?
by ssingh5 Path Finder in Splunk Search 02-13-2012
0 1
0
1
willthames2
I can replicate this behaviour within a search head pool by Add a Lookup Table, and upload a CSV fileChange permissi...
by willthames2 Path Finder in Splunk Search 02-12-2012
1 2
1
2
astepanov
I need to find transactions that failed to complete. Transaction go across 4 systems, from front-end to back-end sys...
by astepanov Explorer in Splunk Search 02-11-2012
1 1
1
1
splunker_jim
Hi there, I have an computationally expensive query which is (manually) run on the main index. Instead of running it...
by splunker_jim Explorer in Splunk Search 02-10-2012
2 4
2
4
a212830
Hi, I'm trying to extract a field from a source, and when I test it, it appears to work, but in practice, it's grabb...
by a212830 Champion in Splunk Search 02-10-2012
0 8
0
8
subhadipc
I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example...
by subhadipc Explorer in Splunk Search 02-10-2012
0 1
0
1
gerald_huddlest
hi I have created an eventtype that looks for a certain event across 12 servers (cmchost). I created a dashboard show...
by gerald_huddlest Path Finder in Splunk Search 02-10-2012
0 4
0
4
lennyburns
I created 8 data inputs, each one is supposed to tail log files mathing a certain whitelist regex. These inputs see t...
by lennyburns Path Finder in Splunk Search 02-10-2012
1 20
1
20
FRoth
I am currently experimenting with the nmap scan output format and indexing the scan results with splunk. I noticed ...
by FRoth Contributor in Splunk Search 02-10-2012
0 1
0
1
kiersti
I have this field in my logs mail_date=08 Feb 2012. But it's not logging as a date or a number so I can't run time-b...
by kiersti Engager in Splunk Search 02-09-2012
2 2
2
2
dave_rook
I'm using this query right now: stats count by host, source, date_mday It only lists Linux hosts but lists the data ...
by dave_rook Engager in Splunk Search 02-09-2012
0 3
0
3
rajbahak
Hello, I need to be able to configure universal forwarder with more than one indexing server from the command line. ...
by rajbahak Path Finder in Splunk Search 02-09-2012
0 2
0
2
joshrabinowitz
upgraded from 4.2.5 to 4.3 and now all searches timeout, and saved searches take longer to run. hw is 2x 4-core opter...
by joshrabinowitz Path Finder in Splunk Search 02-09-2012
2 1
2
1
efelder0
I am extracting a field out of an XML feed. More specifically, this is the field: 2012-01-30T12:57:20/x:LastUpdated ...
by efelder0 Communicator in Splunk Search 02-09-2012
0 3
0
3
kjycls
Is it impossible ? | transaction maxspan=50ms session_id above search command not working.. Please help me~!
by kjycls Engager in Splunk Search 02-09-2012
0 2
0
2
Bulluk
Does anyone know if it's possible to perform a lookup when using the powershell resource kit's search functionality? ...
by Bulluk Path Finder in Splunk Search 02-09-2012
0 2
0
2
balbano
Hey guys, Got another one for ya: I need to lookup sourcetypes for the past year. I basically need to know how ...
by balbano Contributor in Splunk Search 02-08-2012
0 3
0
3
staze
Okay, I've done this once in Plone, but we've moved to Drupal, and things don't look the same. Basically, I want to...
by staze Path Finder in Splunk Search 02-08-2012
1 8
1
8
the_wolverine
I'd like to be able to historically search my events and be able to correlate events from 2 different sources. One s...
by the_wolverine Champion in Splunk Search 02-08-2012
0 2
0
2
DTERM
I found the following Splunk query that tells the local disk space. Is there a similar command that I could use to q...
by DTERM Contributor in Splunk Search 02-08-2012
0 4
0
4
mcm10285
Anyone has an idea on how to define a new field based on previously defined fields? Log format is a bit tricky, deli...
by mcm10285 Communicator in Splunk Search 02-08-2012
0 6
0
6
msarro
Greetings everyone. Is there any way to modify _time's value for the sake of a single search? One of our sources has ...
by msarro Builder in Splunk Search 02-08-2012
1 3
1
3
Ravan
Hi, How can we extract hostname from FQDN at runtime(Need to include with in the query) Ex: myhost.domain.com (OR)...
by Ravan Path Finder in Splunk Search 02-07-2012
0 3
0
3
eulalie
We have an application that does NOT generate it's own logs. We are in a position where we can get the logs generate...
by eulalie New Member in Splunk Search 02-07-2012
0 1
0
1
jonburt
Our gauge needs to display from 0 to 1, but after installing 4.3, the scale only shows 0 - 100. Below is the xml I a...
by jonburt Engager in Splunk Search 02-06-2012
1 2
1
2
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors