Splunk Search

Splunk Search
Community Activity
dabarb1
So I'm attempting to re-use the same search query results multiple times in the same advanced view for performance re...
by dabarb1 Explorer in Splunk Search 11-18-2011
1 5
1
5
ldeakm
I am trying to simulate this type of date filter in splunk. Please help... In SQL I use select * from table where ...
by ldeakm Explorer in Splunk Search 11-18-2011
1 6
1
6
annoyedmildly
I want to find entries added to a sourcetype today, that haven't been seen in the last N days. I've tried search A |...
by annoyedmildly Engager in Splunk Search 11-18-2011
1 3
1
3
Samslara
I have a problem with how to write a splunk query for my use. I'm trying to fetch values from an event where that ev...
by Samslara Explorer in Splunk Search 11-18-2011
0 1
0
1
splunkgam
When a saved search sends an email with the results in a CSV file, the file never contains more than 1000 lines (plus...
by splunkgam New Member in Splunk Search 11-17-2011
0 2
0
2
tpsplunk
I'm having trouble crafting a regex that would pull key=value pairs where the pairs are separated by a character sequ...
by tpsplunk Communicator in Splunk Search 11-17-2011
1 9
1
9
pdovy
I've got a sourcetype which captures data for two nearly identical applications, the difference being that one calcul...
by pdovy New Member in Splunk Search 11-17-2011
0 1
0
1
iamniks
csv log file data PROJ_NAME TAG_NAME STATUS WIWEB-A WIWEB-A_1 ...
by iamniks Explorer in Splunk Search 11-17-2011
0 6
0
6
vramali1
Hi folks, I am using a forwarder/receiver model I want to audit details to report security breaches in a fatwire sys...
by vramali1 New Member in Splunk Search 11-17-2011
0 1
0
1
ajitsd
I am trying to find an hourly count of the content in Apache access log. 10.113.76.13 - - [16/Nov/2011:17:13:59 -08...
by ajitsd Explorer in Splunk Search 11-16-2011
0 3
0
3
lpolo
I have the following data indexed: initialTime Purchase_Time 2011-11-04T13:17Z 2011-11-04 09:18:20 2011-11-04T...
by lpolo Motivator in Splunk Search 11-16-2011
3 3
3
3
jshaynes
I have several use cases where i need to run a subsearch that is not limited to the default 10k results. ex. this se...
by jshaynes Explorer in Splunk Search 11-16-2011
1 1
1
1
jeffoptimizely
Is there a good Unixy way to check "is splunkweb running" and "is splunkd running"? I want to run a cronjob that che...
by jeffoptimizely Explorer in Splunk Search 11-16-2011
1 4
1
4
keshab
suppose two log file have common field named IPaddress. One log file has username filed with that IPaddress field and...
by keshab Path Finder in Splunk Search 11-16-2011
0 2
0
2
riderofyamaha
i have a simple form view set up to retrieve a specific ip address or username from the system. the results are then...
by riderofyamaha Explorer in Splunk Search 11-16-2011
1 2
1
2
keshab
I have a log which says when session was created and destroyed. What search string should I use to calculate the leng...
by keshab Path Finder in Splunk Search 11-16-2011
0 5
0
5
crescens
this looks very interesting. How much volume does this produce each day?
by crescens New Member in Splunk Search 11-15-2011
0 1
0
1
gnovak
I have a search that will basically look through some logs for a line "Inserting a record" and then take the username...
by gnovak Builder in Splunk Search 11-15-2011
0 13
0
13
jrialto
We have a large number of audit files from Oracle that have been written to the Local OS. In the audit files there is...
by jrialto New Member in Splunk Search 11-15-2011
0 3
0
3
camah4
I have an example log file with the following format: Nov 05 10:33:37 servername applicationserver: instance,ipaddre...
by camah4 New Member in Splunk Search 11-15-2011
0 2
0
2
c0mrade
I have a pretty long log that needs to be analyzed, not single lined though, here is example #1: .....some unimporta...
by c0mrade Explorer in Splunk Search 11-15-2011
1 2
1
2
hulahoop
Am curious what the performance difference is between sorted and unsorted lookups (sorting by the primary search key ...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 11-15-2011
3 2
3
2
tympaniplayer
When I use the windows app to search for a hardrive with less than a certain amount of space to set up alerts, I some...
by tympaniplayer Path Finder in Splunk Search 11-15-2011
0 3
0
3
e82than
Hi all, I have a question to ask about using regex to recognize a field. I did manage to pick the field out from my ...
by e82than Communicator in Splunk Search 11-15-2011
0 3
0
3
felixjs
Hi All, We have some indexes that have suddenly stopped indexing the custom fields we had configured on our logs. T...
by felixjs New Member in Splunk Search 11-14-2011
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...