Splunk Search

Splunk Search
Community Activity
Bulluk
I have a requirement from the business to register the time a user stayed on a news story, the idea being that this w...
by Bulluk Path Finder in Splunk Search 12-23-2011
1 1
1
1
dmaislin_splunk
I have some XML data that I parse into many fields, one of which is "relativePath" why can't I get the transforms to...
by dmaislin_splunk Splunk Employee Splunk Employee in Splunk Search 12-23-2011
0 4
0
4
sedo
Hi there, first of all congrats on the awesome software that splunk is. Having said that, I have noticed that the f...
by sedo New Member in Splunk Search 12-23-2011
0 2
0
2
sleathley
Trying to right a search that will extract and display all the hosts that have indexed data and their sourcetypes. An...
by sleathley Explorer in Splunk Search 12-22-2011
1 2
1
2
eric_splunk
I have some questions about Splunk for IPv6. C I want to know if the Splunk software architecture supports IPv6? Ot...
by eric_splunk New Member in Splunk Search 12-22-2011
0 1
0
1
mikeely
I've got a scripted input that dumps a line like the following every minute: 2011-12-22 08:46:56,0,30,6 What I'd l...
by mikeely Path Finder in Splunk Search 12-22-2011
0 2
0
2
cloud_cloud
How to combine these two stats count into one? ... | stats count by operation operation count added gid ...
by cloud_cloud Explorer in Splunk Search 12-22-2011
0 2
0
2
wsw70
Hello, I have log files which have both IP numbers (field IP) and corresponding names (field DNSNAME). I would like ...
by wsw70 Communicator in Splunk Search 12-22-2011
1 2
1
2
mataharry
I want to format nicely the fields or events at search time. by example : US phone : 11122223333 to (111) 222-3333 i...
by mataharry Communicator in Splunk Search 12-21-2011
0 1
0
1
achudnoff
I'm trying to write a search that will compare values from different data inputs and return the highest value to use ...
by achudnoff Explorer in Splunk Search 12-21-2011
0 2
0
2
Bulluk
Is there a way to perform an eval when using an automatic lookup? I'm using user IDs in IIS logs to find a user's rea...
by Bulluk Path Finder in Splunk Search 12-21-2011
1 6
1
6
atornes
I'm trying to combine the results of a search and subsearch. They have overlapping fields but different result sets....
by atornes Path Finder in Splunk Search 12-21-2011
0 1
0
1
efelder0
I am trying to assign a value to a Severity field when the sourcetype = "low" or "Med" or "high". I.e. - IF sourcety...
by efelder0 Communicator in Splunk Search 12-21-2011
1 6
1
6
flo_cognosec
I add this to props.conf to detect shellscripts, but interesting enough this not only matches shell-scripts but also ...
by flo_cognosec Communicator in Splunk Search 12-21-2011
0 1
0
1
xiaoyuew
for example, i have the following 7 logs, 2011-DEC-17 slotid="Location-Maps-US-Sunnyvale" delta_msec="1487" seq="3" ...
by xiaoyuew Path Finder in Splunk Search 12-21-2011
0 1
0
1
adityapavan18
Hi Is there any way to write the search results (in table format) in to a lookup table i.e... | table field1,feil...
by adityapavan18 Contributor in Splunk Search 12-21-2011
1 1
1
1
rksubbu
I would like to calculate the total for the following sample. These are numbers but have comma. 122 3,871 17,896 33...
by rksubbu Explorer in Splunk Search 12-20-2011
2 6
2
6
xiaoyuew
My logs contain a field "A", i need to calculate a new field "B" based on the SLOT, when A=a1 OR A=a2, THEN B=avg of...
by xiaoyuew Path Finder in Splunk Search 12-20-2011
0 2
0
2
rbw78
Hello, I'm having an issue with a regex i did. I want to create a new column with my regex where there's 2 values po...
by rbw78 Communicator in Splunk Search 12-20-2011
0 3
0
3
gnovak
Hi there! I'm looking at this previous question here: [http://splunk-base.splunk.com/answers/2602/can-splunk-filter...
by gnovak Builder in Splunk Search 12-20-2011
0 2
0
2
kml_uvce
my field extractions are not working tranforms.conf file is [tms_iisfields] FIELDS = "date","time","s-ip","cs-metho...
by kml_uvce Builder in Splunk Search 12-20-2011
0 3
0
3
robgreen
i have yet to get lookups to work correctly in an app. The file is in the right place /opt/splunk/etc/apps/myapp...
by robgreen Path Finder in Splunk Search 12-20-2011
0 3
0
3
JSapienza
I am trying to extract the fields from an Oracle 10g Audit trail. Below is a sample of the raw log : Tue Feb 15 10:1...
by JSapienza Contributor in Splunk Search 12-20-2011
0 6
0
6
cafissimo
Hello, I have a source that contains events like these: "MONEY LEFT: 1.000,00" "MONEY LEFT: 000,00" "MONEY LEFT: 350...
by cafissimo Communicator in Splunk Search 12-20-2011
0 3
0
3
qas
Splunk's scrub command scrub data in queries/report. What are the steps to permanently remove certain logs from Splun...
by qas Engager in Splunk Search 12-19-2011
3 3
3
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...