Splunk Search

Splunk Search
Community Activity
xiaoyuew
for example, i have the following 7 logs, 2011-DEC-17 slotid="Location-Maps-US-Sunnyvale" delta_msec="1487" seq="3" ...
by xiaoyuew Path Finder in Splunk Search 12-21-2011
0 1
0
1
adityapavan18
Hi Is there any way to write the search results (in table format) in to a lookup table i.e... | table field1,feil...
by adityapavan18 Contributor in Splunk Search 12-21-2011
1 1
1
1
rksubbu
I would like to calculate the total for the following sample. These are numbers but have comma. 122 3,871 17,896 33...
by rksubbu Explorer in Splunk Search 12-20-2011
2 6
2
6
xiaoyuew
My logs contain a field "A", i need to calculate a new field "B" based on the SLOT, when A=a1 OR A=a2, THEN B=avg of...
by xiaoyuew Path Finder in Splunk Search 12-20-2011
0 2
0
2
rbw78
Hello, I'm having an issue with a regex i did. I want to create a new column with my regex where there's 2 values po...
by rbw78 Communicator in Splunk Search 12-20-2011
0 3
0
3
gnovak
Hi there! I'm looking at this previous question here: [http://splunk-base.splunk.com/answers/2602/can-splunk-filter...
by gnovak Builder in Splunk Search 12-20-2011
0 2
0
2
kml_uvce
my field extractions are not working tranforms.conf file is [tms_iisfields] FIELDS = "date","time","s-ip","cs-metho...
by kml_uvce Builder in Splunk Search 12-20-2011
0 3
0
3
robgreen
i have yet to get lookups to work correctly in an app. The file is in the right place /opt/splunk/etc/apps/myapp...
by robgreen Path Finder in Splunk Search 12-20-2011
0 3
0
3
JSapienza
I am trying to extract the fields from an Oracle 10g Audit trail. Below is a sample of the raw log : Tue Feb 15 10:1...
by JSapienza Contributor in Splunk Search 12-20-2011
0 6
0
6
cafissimo
Hello, I have a source that contains events like these: "MONEY LEFT: 1.000,00" "MONEY LEFT: 000,00" "MONEY LEFT: 350...
by cafissimo Communicator in Splunk Search 12-20-2011
0 3
0
3
qas
Splunk's scrub command scrub data in queries/report. What are the steps to permanently remove certain logs from Splun...
by qas Engager in Splunk Search 12-19-2011
3 3
3
3
wbfoxii
I'm getting this error message twice every 30 sec. 12-19-2011 12:15:27.539 -0500 ERROR AuthenticationManagerLDAP - Co...
by wbfoxii Communicator in Splunk Search 12-19-2011
1 3
1
3
ianathompson
I am trying to set my host name equal to part of the file name with a regex (regular expression) and I am a regex nov...
by ianathompson Explorer in Splunk Search 12-19-2011
0 1
0
1
wsw70
Hello, I have data in the form of a date,server,events triplet. The fields are correctly extracted and assigned. da...
by wsw70 Communicator in Splunk Search 12-19-2011
0 2
0
2
kml_uvce
Hi I have an index named pci and the location of this is /windows/pci/db i want move it(existing and new) in another ...
by kml_uvce Builder in Splunk Search 12-19-2011
0 1
0
1
the3nd4u
Hi I have a problem with the field extraction. I am trying to extract out and name a field containing the data "--O-...
by the3nd4u New Member in Splunk Search 12-18-2011
0 1
0
1
npandith
We have couple of credit card data in splunk and we need to remove those from the splunk. I am using the below query ...
by npandith Explorer in Splunk Search 12-17-2011
0 1
0
1
stefanlasiewski
I am attempting to Index a file once from my Splunk server. The file contains a copy of syslog data. The lines look ...
by stefanlasiewski Contributor in Splunk Search 12-17-2011
0 6
0
6
DTERM
I'm trying to integrate information from this link http://splunk-base.splunk.com/answers/13482/plotting-trendlines-in...
by DTERM Contributor in Splunk Search 12-16-2011
0 3
0
3
lokival
Using Splunk 4.2.3 build 105575 I have a search which I use to compare the current status of a system (1 hr window) ...
by lokival Explorer in Splunk Search 12-16-2011
3 6
3
6
ericrobinson
Hello All, I recently deployed a new dashboard to look at response times and the count of the requests. We found that...
by ericrobinson Path Finder in Splunk Search 12-16-2011
0 2
0
2
khyoung7410
Hi search command "bucket" time sorting? My search commmand * | bucket _time span=1d | eval time=strftime(_time,"%...
by khyoung7410 Communicator in Splunk Search 12-15-2011
0 1
0
1
jchensor
Hello and thanks in advance for reading this question. I'm currently trying to generate a simple report of unique ho...
by jchensor Communicator in Splunk Search 12-15-2011
0 4
0
4
e82than
I have a set of data from a friend who is doing some statistical work and he want me to use splunk to give meaning to...
by e82than Communicator in Splunk Search 12-15-2011
0 14
0
14
mwagstaff
Hi all - are there any intellisense plug-ins that enhance the existing Splunk search bar? A few examples of enhanceme...
by mwagstaff Explorer in Splunk Search 12-15-2011
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...