Splunk Search

Splunk Search
Community Activity
flo_cognosec
I add this to props.conf to detect shellscripts, but interesting enough this not only matches shell-scripts but also ...
by flo_cognosec Communicator in Splunk Search 12-21-2011
0 1
0
1
xiaoyuew
for example, i have the following 7 logs, 2011-DEC-17 slotid="Location-Maps-US-Sunnyvale" delta_msec="1487" seq="3" ...
by xiaoyuew Path Finder in Splunk Search 12-21-2011
0 1
0
1
adityapavan18
Hi Is there any way to write the search results (in table format) in to a lookup table i.e... | table field1,feil...
by adityapavan18 Contributor in Splunk Search 12-21-2011
1 1
1
1
rksubbu
I would like to calculate the total for the following sample. These are numbers but have comma. 122 3,871 17,896 33...
by rksubbu Explorer in Splunk Search 12-20-2011
2 6
2
6
xiaoyuew
My logs contain a field "A", i need to calculate a new field "B" based on the SLOT, when A=a1 OR A=a2, THEN B=avg of...
by xiaoyuew Path Finder in Splunk Search 12-20-2011
0 2
0
2
rbw78
Hello, I'm having an issue with a regex i did. I want to create a new column with my regex where there's 2 values po...
by rbw78 Communicator in Splunk Search 12-20-2011
0 3
0
3
gnovak
Hi there! I'm looking at this previous question here: [http://splunk-base.splunk.com/answers/2602/can-splunk-filter...
by gnovak Builder in Splunk Search 12-20-2011
0 2
0
2
kml_uvce
my field extractions are not working tranforms.conf file is [tms_iisfields] FIELDS = "date","time","s-ip","cs-metho...
by kml_uvce Builder in Splunk Search 12-20-2011
0 3
0
3
robgreen
i have yet to get lookups to work correctly in an app. The file is in the right place /opt/splunk/etc/apps/myapp...
by robgreen Path Finder in Splunk Search 12-20-2011
0 3
0
3
JSapienza
I am trying to extract the fields from an Oracle 10g Audit trail. Below is a sample of the raw log : Tue Feb 15 10:1...
by JSapienza Contributor in Splunk Search 12-20-2011
0 6
0
6
cafissimo
Hello, I have a source that contains events like these: "MONEY LEFT: 1.000,00" "MONEY LEFT: 000,00" "MONEY LEFT: 350...
by cafissimo Communicator in Splunk Search 12-20-2011
0 3
0
3
qas
Splunk's scrub command scrub data in queries/report. What are the steps to permanently remove certain logs from Splun...
by qas Engager in Splunk Search 12-19-2011
3 3
3
3
wbfoxii
I'm getting this error message twice every 30 sec. 12-19-2011 12:15:27.539 -0500 ERROR AuthenticationManagerLDAP - Co...
by wbfoxii Communicator in Splunk Search 12-19-2011
1 3
1
3
ianathompson
I am trying to set my host name equal to part of the file name with a regex (regular expression) and I am a regex nov...
by ianathompson Explorer in Splunk Search 12-19-2011
0 1
0
1
wsw70
Hello, I have data in the form of a date,server,events triplet. The fields are correctly extracted and assigned. da...
by wsw70 Communicator in Splunk Search 12-19-2011
0 2
0
2
kml_uvce
Hi I have an index named pci and the location of this is /windows/pci/db i want move it(existing and new) in another ...
by kml_uvce Builder in Splunk Search 12-19-2011
0 1
0
1
the3nd4u
Hi I have a problem with the field extraction. I am trying to extract out and name a field containing the data "--O-...
by the3nd4u New Member in Splunk Search 12-18-2011
0 1
0
1
npandith
We have couple of credit card data in splunk and we need to remove those from the splunk. I am using the below query ...
by npandith Explorer in Splunk Search 12-17-2011
0 1
0
1
stefanlasiewski
I am attempting to Index a file once from my Splunk server. The file contains a copy of syslog data. The lines look ...
by stefanlasiewski Contributor in Splunk Search 12-17-2011
0 6
0
6
DTERM
I'm trying to integrate information from this link http://splunk-base.splunk.com/answers/13482/plotting-trendlines-in...
by DTERM Contributor in Splunk Search 12-16-2011
0 3
0
3
lokival
Using Splunk 4.2.3 build 105575 I have a search which I use to compare the current status of a system (1 hr window) ...
by lokival Explorer in Splunk Search 12-16-2011
3 6
3
6
ericrobinson
Hello All, I recently deployed a new dashboard to look at response times and the count of the requests. We found that...
by ericrobinson Path Finder in Splunk Search 12-16-2011
0 2
0
2
khyoung7410
Hi search command "bucket" time sorting? My search commmand * | bucket _time span=1d | eval time=strftime(_time,"%...
by khyoung7410 Communicator in Splunk Search 12-15-2011
0 1
0
1
jchensor
Hello and thanks in advance for reading this question. I'm currently trying to generate a simple report of unique ho...
by jchensor Communicator in Splunk Search 12-15-2011
0 4
0
4
e82than
I have a set of data from a friend who is doing some statistical work and he want me to use splunk to give meaning to...
by e82than Communicator in Splunk Search 12-15-2011
0 14
0
14
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...