Splunk Search

Splunk Search
Community Activity
mataharry
I want to format nicely the fields or events at search time. by example : US phone : 11122223333 to (111) 222-3333 i...
by mataharry Communicator in Splunk Search 12-21-2011
0 1
0
1
achudnoff
I'm trying to write a search that will compare values from different data inputs and return the highest value to use ...
by achudnoff Explorer in Splunk Search 12-21-2011
0 2
0
2
Bulluk
Is there a way to perform an eval when using an automatic lookup? I'm using user IDs in IIS logs to find a user's rea...
by Bulluk Path Finder in Splunk Search 12-21-2011
1 6
1
6
atornes
I'm trying to combine the results of a search and subsearch. They have overlapping fields but different result sets....
by atornes Path Finder in Splunk Search 12-21-2011
0 1
0
1
efelder0
I am trying to assign a value to a Severity field when the sourcetype = "low" or "Med" or "high". I.e. - IF sourcety...
by efelder0 Communicator in Splunk Search 12-21-2011
1 6
1
6
flo_cognosec
I add this to props.conf to detect shellscripts, but interesting enough this not only matches shell-scripts but also ...
by flo_cognosec Communicator in Splunk Search 12-21-2011
0 1
0
1
xiaoyuew
for example, i have the following 7 logs, 2011-DEC-17 slotid="Location-Maps-US-Sunnyvale" delta_msec="1487" seq="3" ...
by xiaoyuew Path Finder in Splunk Search 12-21-2011
0 1
0
1
adityapavan18
Hi Is there any way to write the search results (in table format) in to a lookup table i.e... | table field1,feil...
by adityapavan18 Contributor in Splunk Search 12-21-2011
1 1
1
1
rksubbu
I would like to calculate the total for the following sample. These are numbers but have comma. 122 3,871 17,896 33...
by rksubbu Explorer in Splunk Search 12-20-2011
2 6
2
6
xiaoyuew
My logs contain a field "A", i need to calculate a new field "B" based on the SLOT, when A=a1 OR A=a2, THEN B=avg of...
by xiaoyuew Path Finder in Splunk Search 12-20-2011
0 2
0
2
rbw78
Hello, I'm having an issue with a regex i did. I want to create a new column with my regex where there's 2 values po...
by rbw78 Communicator in Splunk Search 12-20-2011
0 3
0
3
gnovak
Hi there! I'm looking at this previous question here: [http://splunk-base.splunk.com/answers/2602/can-splunk-filter...
by gnovak Builder in Splunk Search 12-20-2011
0 2
0
2
kml_uvce
my field extractions are not working tranforms.conf file is [tms_iisfields] FIELDS = "date","time","s-ip","cs-metho...
by kml_uvce Builder in Splunk Search 12-20-2011
0 3
0
3
robgreen
i have yet to get lookups to work correctly in an app. The file is in the right place /opt/splunk/etc/apps/myapp...
by robgreen Path Finder in Splunk Search 12-20-2011
0 3
0
3
JSapienza
I am trying to extract the fields from an Oracle 10g Audit trail. Below is a sample of the raw log : Tue Feb 15 10:1...
by JSapienza Contributor in Splunk Search 12-20-2011
0 6
0
6
cafissimo
Hello, I have a source that contains events like these: "MONEY LEFT: 1.000,00" "MONEY LEFT: 000,00" "MONEY LEFT: 350...
by cafissimo Communicator in Splunk Search 12-20-2011
0 3
0
3
qas
Splunk's scrub command scrub data in queries/report. What are the steps to permanently remove certain logs from Splun...
by qas Engager in Splunk Search 12-19-2011
3 3
3
3
wbfoxii
I'm getting this error message twice every 30 sec. 12-19-2011 12:15:27.539 -0500 ERROR AuthenticationManagerLDAP - Co...
by wbfoxii Communicator in Splunk Search 12-19-2011
1 3
1
3
ianathompson
I am trying to set my host name equal to part of the file name with a regex (regular expression) and I am a regex nov...
by ianathompson Explorer in Splunk Search 12-19-2011
0 1
0
1
wsw70
Hello, I have data in the form of a date,server,events triplet. The fields are correctly extracted and assigned. da...
by wsw70 Communicator in Splunk Search 12-19-2011
0 2
0
2
kml_uvce
Hi I have an index named pci and the location of this is /windows/pci/db i want move it(existing and new) in another ...
by kml_uvce Builder in Splunk Search 12-19-2011
0 1
0
1
the3nd4u
Hi I have a problem with the field extraction. I am trying to extract out and name a field containing the data "--O-...
by the3nd4u New Member in Splunk Search 12-18-2011
0 1
0
1
npandith
We have couple of credit card data in splunk and we need to remove those from the splunk. I am using the below query ...
by npandith Explorer in Splunk Search 12-17-2011
0 1
0
1
stefanlasiewski
I am attempting to Index a file once from my Splunk server. The file contains a copy of syslog data. The lines look ...
by stefanlasiewski Contributor in Splunk Search 12-17-2011
0 6
0
6
DTERM
I'm trying to integrate information from this link http://splunk-base.splunk.com/answers/13482/plotting-trendlines-in...
by DTERM Contributor in Splunk Search 12-16-2011
0 3
0
3
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...