Splunk Search

Splunk Search
Community Activity
Moogz
Hello all, brand new to Splunk so please bare with me. I have two csv files as two different sources with the same t...
by Moogz Splunk Employee Splunk Employee in Splunk Search 01-17-2012
2 2
2
2
Takajian
The number of scheduled search splunk is able to run at same time is 25% of maximum number of concurrent searches on ...
by Takajian Builder in Splunk Search 01-17-2012
0 1
0
1
gnovak
I'm not quite sure if I'm doing this right or going in the right direction. I have a log where the results are a bun...
by gnovak Builder in Splunk Search 01-17-2012
0 3
0
3
Cris
Is it possible to change the Fschange indexing date, not time? My need is: if a file is added/modified/deleted the d...
by Cris Explorer in Splunk Search 01-17-2012
0 1
0
1
rroberts
Doc mention http://docs.splunk.com/Documentation/Splunk/4.2.4/Installation/Systemrequirements Safari 3 support. When ...
by rroberts Splunk Employee Splunk Employee in Splunk Search 01-17-2012
0 1
0
1
suhprano
It appears that there are several ways to bulk export data from Splunk. -rest API -search query option: outputcsv -cl...
by suhprano Path Finder in Splunk Search 01-17-2012
1 3
1
3
Conradj
Hi, I have multiple fields returned in a search that I to plot as separate lines on a line graph. however, both fie...
by Conradj Path Finder in Splunk Search 01-16-2012
0 2
0
2
vaijpc
After upgrading to 4.3 I noticed one of my timecharts was not working correctly: searchterm NOT port=16 | timechart ...
by vaijpc Communicator in Splunk Search 01-16-2012
3 18
3
18
drgonzo65
I have a series of metrics that get dumped to a file every minute in this format: timestamp:XXXXXXXXXX metric1:XX me...
by drgonzo65 Engager in Splunk Search 01-15-2012
1 1
1
1
Simon
Hi guys Have a look at my events indexed in Splunk: Jan 12 09:29:11 myhost -bash: HISTORY: PID=28489 UID=501 id Jan...
by Simon Contributor in Splunk Search 01-15-2012
1 8
1
8
mcafeesecure
This is probably something simple that I am missing. Is there a way to filter out what are esentially blank log entr...
by mcafeesecure Explorer in Splunk Search 01-14-2012
0 2
0
2
hhopkins
I have created pie charts with data like this: index=default counter=10 color=blue index=default counter=5 color=gre...
by hhopkins Engager in Splunk Search 01-13-2012
0 1
0
1
vbumgarn
Which is more efficient, a scripted lookup or a command? I've written a piece of code as both, and the command is c...
by vbumgarn Path Finder in Splunk Search 01-13-2012
0 1
0
1
krusty
Hi there, is it possible to set the name of the attached pdf document? Usually the attached file was named by "splun...
by krusty Contributor in Splunk Search 01-13-2012
2 1
2
1
hartfoml
Here is what I am using: | eval siteName = case (Destination_IP == "199.47.*", dropbox.com) I have tried everythin...
by hartfoml Motivator in Splunk Search 01-12-2012
0 8
0
8
mlevenson
I'm trying to chart the total traffic that is flowing from inside my FW to the outside of my firewall. Here is an ex...
by mlevenson Explorer in Splunk Search 01-12-2012
1 1
1
1
twinspop
This search works without issue in 4.2.4: sourcetype="teledebug" | transaction keeporphans=1 host source startswith=...
by twinspop Influencer in Splunk Search 01-12-2012
0 2
0
2
Bulluk
Hi I previously asked this question and marked it as answered following eelisio2's response. http://splunk-base.spl...
by Bulluk Path Finder in Splunk Search 01-12-2012
1 1
1
1
flo_cognosec
This props.conf stanza give me headaches. [source::/(testing2|bin|sbin|etc|lib|usr)/...] This does indeed work and ...
by flo_cognosec Communicator in Splunk Search 01-12-2012
0 2
0
2
mfrost8
As a sort of followup to my earlier question at Way to insert/create field based on source? we're interested in doi...
by mfrost8 Builder in Splunk Search 01-11-2012
0 4
0
4
carsonl
Hi all, Some background... We have a large amount of data coming in, and the filename is used to derive some of the ...
by carsonl Explorer in Splunk Search 01-11-2012
0 1
0
1
ehs
My log file has tabular (several columns) data that I need to parse. Each element in a row is separated by spaces, a...
by ehs New Member in Splunk Search 01-11-2012
0 1
0
1
mauroscreti
Hi all, i need to ecrypt some sensitive fields ( example number credit card, passord, username ecc ecc ) in 4.1 is ...
by mauroscreti Engager in Splunk Search 01-11-2012
1 1
1
1
Nieucel
Hello, I have several events with this kind of format: 2012-1-9 15.0.1.290021000 1:0 BD_PANDORA_PROD_TOTAL_USERS_DE=...
by Nieucel Engager in Splunk Search 01-11-2012
0 4
0
4
mikeely
I've got a file being spooled out from a database one row at a time, couple of example lines: 10-01-12:02:50:02, ...
by mikeely Path Finder in Splunk Search 01-10-2012
0 2
0
2
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...