Splunk Search

Splunk Search
Community Activity
timbCFCA
I'm attempting to map when the count of two event IDs - 4634 and 4624 is different over a time period. These events c...
by timbCFCA Path Finder in Splunk Search 11-11-2011
0 2
0
2
bfernandez
I am trying to extract some data from a script output. Sample: SERVICE_NAME: WebTrends - Data Retention Service DISPL...
by bfernandez Communicator in Splunk Search 11-11-2011
0 2
0
2
khyoung7410
Hi In timechart, how to Search for the values >n ? (ex) search : weblog " * | strcat clientip "@" uri A_COMBO | ti...
by khyoung7410 Communicator in Splunk Search 11-11-2011
0 2
0
2
keshab
search SessionID="*" | stats range(_time) AS Session_Duration_sec by SessionID I got the each session duration using...
by keshab Path Finder in Splunk Search 11-11-2011
1 2
1
2
mchan
Newbie to splunk, but I want to aggregate the log entries below based upon if it's the same ip address and request ur...
by mchan New Member in Splunk Search 11-10-2011
0 2
0
2
lpolo
I have the following log: 01/02/2011:00:00:01 q=UP 01/02/2011:00:00:02 q=UP A 01/02/2011:00:00:03 q=UP AL 01/02/2...
by lpolo Motivator in Splunk Search 11-10-2011
0 10
0
10
mcbradford
I have a dashboard with a few table views. I want the first event to be the most recent event (so sort by most recen...
by mcbradford Contributor in Splunk Search 11-10-2011
0 5
0
5
adityapavan18
Hi Is it possible to find the Average of only the best 50% transactions(i.e top 50% of less transaction times). I c...
by adityapavan18 Contributor in Splunk Search 11-10-2011
0 5
0
5
tven7
index=tbb sourcetype=tbb_server "No UserSession exists with the primary key" |eval delta=_time/3|stats count as erro...
by tven7 Path Finder in Splunk Search 11-10-2011
1 1
1
1
xiaoyuew
i have create a dashboard with multiple views on it, i would like to navigate them through the hyperlinks, so when i ...
by xiaoyuew Path Finder in Splunk Search 11-10-2011
0 1
0
1
tdnguyen1
Hi, I am new two splunk. I am wondering is there a way to calculate the delta of RXdropped from 5 minutes apart. 10...
by tdnguyen1 Explorer in Splunk Search 11-09-2011
1 5
1
5
Sqig
Hi. I have a need to include the start and end of the searched-for time range in the search results themselves. Ulti...
by Sqig Path Finder in Splunk Search 11-09-2011
0 2
0
2
steveirogers
I am running Splunk 4.2.3. I have a directory called "/var/log/atpco" which contains numerous log files. I have play...
by steveirogers Communicator in Splunk Search 11-09-2011
0 4
0
4
asingla
I am using dedup in my search and my time criteria is real time. The events are coming every minute but the results a...
by asingla Communicator in Splunk Search 11-09-2011
0 1
0
1
royhvaara
in inputs.conf: [tcp://:9995] connection_host = dns sourcetype = tcp:9995 source = tcp:9995 in props.conf: [sourc...
by royhvaara Engager in Splunk Search 11-09-2011
0 1
0
1
joejag
I would like to organise my saved searches into subfolders in the drop down on the search app. I noticed that the "E...
by joejag New Member in Splunk Search 11-09-2011
0 3
0
3
TheMarkHodgkins
Pardon my newbie'ness  Does anyone have an example where Search results are matched to table entries (simple CSV sh...
by TheMarkHodgkins Explorer in Splunk Search 11-09-2011
0 1
0
1
gooza
Hi, I'd like to add knowledge to our splunk data and divide ips or computers to different groups like test/productio...
by gooza Communicator in Splunk Search 11-08-2011
1 4
1
4
keshab
2011-11-07 13:25:35,145 FE (Exe 45) (pid 11788) destroyed 2011-11-07 13:25:35,152 PNG.exe (Exe 64) (pid 17286) des...
by keshab Path Finder in Splunk Search 11-08-2011
0 5
0
5
moonmyj
Hi All, I have Windows 2008 64bit & Windows 2003 64bit server. I've installed splunk 4.2.4 64bit(via administrator u...
by moonmyj New Member in Splunk Search 11-08-2011
0 8
0
8
jcfergus
From what I've been reading, I don't see that this is possible, but... Is there any way to create a saved search that...
by jcfergus Engager in Splunk Search 11-08-2011
0 2
0
2
cloudharmony
I'm running a search against about 1.2 million log records. Each record contains some geo tags and numeric values rep...
by cloudharmony Explorer in Splunk Search 11-07-2011
1 6
1
6
atomlinson81
a bit of background info - we use sophos av software, and all machines use a local account on the sophos management s...
by atomlinson81 New Member in Splunk Search 11-07-2011
0 4
0
4
dmlee
Hi I wrote a simple form search dashboard using <table> module . I found if the number of results over 50,000 , wh...
by dmlee Communicator in Splunk Search 11-07-2011
0 1
0
1
oreni
Hello, I'm running a saved search which runs perfectly fine, but when I'm trying to use Report Builder I'm getting ...
by oreni Explorer in Splunk Search 11-06-2011
1 1
1
1
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...