Splunk Search

Splunk Search
Community Activity
twinspop
This search works without issue in 4.2.4: sourcetype="teledebug" | transaction keeporphans=1 host source startswith=...
by twinspop Influencer in Splunk Search 01-12-2012
0 2
0
2
Bulluk
Hi I previously asked this question and marked it as answered following eelisio2's response. http://splunk-base.spl...
by Bulluk Path Finder in Splunk Search 01-12-2012
1 1
1
1
flo_cognosec
This props.conf stanza give me headaches. [source::/(testing2|bin|sbin|etc|lib|usr)/...] This does indeed work and ...
by flo_cognosec Communicator in Splunk Search 01-12-2012
0 2
0
2
mfrost8
As a sort of followup to my earlier question at Way to insert/create field based on source? we're interested in doi...
by mfrost8 Builder in Splunk Search 01-11-2012
0 4
0
4
carsonl
Hi all, Some background... We have a large amount of data coming in, and the filename is used to derive some of the ...
by carsonl Explorer in Splunk Search 01-11-2012
0 1
0
1
ehs
My log file has tabular (several columns) data that I need to parse. Each element in a row is separated by spaces, a...
by ehs New Member in Splunk Search 01-11-2012
0 1
0
1
mauroscreti
Hi all, i need to ecrypt some sensitive fields ( example number credit card, passord, username ecc ecc ) in 4.1 is ...
by mauroscreti Engager in Splunk Search 01-11-2012
1 1
1
1
Nieucel
Hello, I have several events with this kind of format: 2012-1-9 15.0.1.290021000 1:0 BD_PANDORA_PROD_TOTAL_USERS_DE=...
by Nieucel Engager in Splunk Search 01-11-2012
0 4
0
4
mikeely
I've got a file being spooled out from a database one row at a time, couple of example lines: 10-01-12:02:50:02, ...
by mikeely Path Finder in Splunk Search 01-10-2012
0 2
0
2
crberus
I am trying to parse useful per-protocol summary performance information from our NetApp SAN heads' syslogging and wo...
by crberus Explorer in Splunk Search 01-10-2012
2 4
2
4
kbecker
This error has started showing up when searching back across larger data sets. we have several indexers and only one...
by kbecker Communicator in Splunk Search 01-09-2012
1 10
1
10
are0002
Hello, I use external_lookup (dnslookup) for a host source info. I have configured this automatic lookup: dnslookup ...
by are0002 Path Finder in Splunk Search 01-09-2012
0 3
0
3
wsw70
Hello, I am trying to create a bubble chart (this is not very much documented, hopefully this example will help) for...
by wsw70 Communicator in Splunk Search 01-09-2012
0 6
0
6
jackyc
Hi all, I have a month (2010-Nov) SAR reports (30 copies) for my host which I want to import them to the Splunk ser...
by jackyc Explorer in Splunk Search 01-08-2012
0 2
0
2
bengridley
I noticed with splunk you can search subnets now. However I would like to search for all communications via my intern...
by bengridley New Member in Splunk Search 01-06-2012
0 2
0
2
rbw78
Hello, I have 2 sources of events with "almost" the same framework and some of them reference the same event with th...
by rbw78 Communicator in Splunk Search 01-06-2012
0 2
0
2
melonman
Hi, I have a logfile containing data that looks like the below: Nov 21 13:59:41 hostname1 data1 data2 data3 Nov 21 ...
by melonman Motivator in Splunk Search 01-06-2012
0 2
0
2
ppediaditis
I have a query in the form eventtype="search" | stats count as search_count by host | appendcols [search application...
by ppediaditis New Member in Splunk Search 01-05-2012
0 3
0
3
atornes
I am performing a search and sub search and would like to combine the results into a single result set. I have run t...
by atornes Path Finder in Splunk Search 01-05-2012
1 7
1
7
nhads18
Im sorry I am a little newbie with splunk, I would like to ask how to get cloudmark MTA logs to splunk?
by nhads18 New Member in Splunk Search 01-05-2012
0 2
0
2
rbonetti
Hi all, I would like to break some lines into mutliple events. The break condition is the time, as you can see below...
by rbonetti Engager in Splunk Search 01-05-2012
0 2
0
2
rkanalyst
Hi, I have to plot a graph from 0 to 1 for different clients but didn't finding any exact queries to do so. My prob...
by rkanalyst Explorer in Splunk Search 01-05-2012
0 1
0
1
rbonetti
Hi all, I would like to break a line in multiple events in my log files, you can see the break condition in bold: [...
by rbonetti Engager in Splunk Search 01-05-2012
1 1
1
1
anirbanukil
I have some saved searches which should not trigger during certain window. For example, everyday from 12:00 AM to 2:0...
by anirbanukil Explorer in Splunk Search 01-04-2012
0 1
0
1
naydenk
Hello I just setup a trial install of Splunk (running with an Enterprise license at the moment). My version is 4.2.5,...
by naydenk Path Finder in Splunk Search 01-04-2012
0 3
0
3
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...