Splunk Search

Splunk Search
Community Activity
suhprano
Is it possible to view the most recent list of searches and queries executed in Splunk? If so, how?
by suhprano Path Finder in Splunk Search 10-20-2011
0 1
0
1
suhprano
Is it possible to view the most recent list of searches and queries executed in Splunk? If so, how?
by suhprano Path Finder in Splunk Search 10-20-2011
0 1
0
1
Samslara
Hi, I have a novice question, but is it possible to have more than one sourcetype for a given source?
by Samslara Explorer in Splunk Search 10-20-2011
0 1
0
1
hartfoml
I was collecting windows event logs using agent less Splunk server through remote WMI calls and the "sourcetype=WMI:W...
by hartfoml Motivator in Splunk Search 10-20-2011
0 5
0
5
mknowles
Hello, I've figured out how to start a real-time search job. I'm wondering if there's any way to trigger a shell co...
by mknowles Engager in Splunk Search 10-20-2011
2 7
2
7
anshumishra
Hi, I have a log where the, app logs the various steps for a unique opertaion id (id below) -> ...... ts=13188618399...
by anshumishra New Member in Splunk Search 10-19-2011
0 3
0
3
lisa_1
The transaction command matches only the first instance of the specified endswith, however it's possible and likely t...
by lisa_1 Explorer in Splunk Search 10-19-2011
2 4
2
4
adityapavan18
Hi, I have 2 search queries. sourcetype="zzz" Accepted | stats count as SuccessCases sourcetype="zzz" Rejected | s...
by adityapavan18 Contributor in Splunk Search 10-19-2011
0 7
0
7
hartfoml
I have this regex expresion: REGEX = (?m)^EventCode=(4674)|(ServerName\$) This works great to identify the two cond...
by hartfoml Motivator in Splunk Search 10-19-2011
0 10
0
10
myli12
I tried the following: host=A earliest=10/01/2011:0:0:0 latest=10/01/2011:11:0:0 | timechart span=1h count by msg W...
by myli12 Path Finder in Splunk Search 10-18-2011
0 1
0
1
sf_user_199
I have the following xml <module name="HiddenSearch" layoutPanel="panel_row2_col1" group="XXX" autoRun="True"> ...
by sf_user_199 Path Finder in Splunk Search 10-18-2011
1 5
1
5
JovanMilosevic
Hi, I have some events, and a User lookup. The Lookup holds the UserID, User Name, a WorkGroup, and dates when th...
by JovanMilosevic Path Finder in Splunk Search 10-18-2011
1 3
1
3
lanying
In a dashboard, calling a csv file query. Then I want to insert a present login account*(UserAccount)*. How can I ge...
by lanying Explorer in Splunk Search 10-18-2011
0 3
0
3
jcfergus
This seems like it should be such a straightforward thing, but having a hard time nailing down an answer we're happy ...
by jcfergus Engager in Splunk Search 10-17-2011
0 1
0
1
thejaspavithran
Hi, I have a set of logs in the following format 2011-10-17 14:16:11,117 [main] : DEBUG - <Application Id [461620...
by thejaspavithran New Member in Splunk Search 10-17-2011
0 2
0
2
timpet
I can check the DB size and it continues to grow but nothing new shows up in the search. I have 2 that are updating a...
by timpet New Member in Splunk Search 10-14-2011
0 1
0
1
merritsa
We have a search that someone from Splunk helped us put together a few years ago that we altered a bit: index="Firew...
by merritsa Path Finder in Splunk Search 10-14-2011
0 4
0
4
kholleran
Hi, I am sure the answer is out there but I am not exactly sure how to ask the question. My Splunk server has two p...
by kholleran Communicator in Splunk Search 10-14-2011
0 1
0
1
kmisaal
I have a simple configuration for few forwarders and an indexer. I have configured the field look-up on Splunk indexe...
by kmisaal New Member in Splunk Search 10-13-2011
0 1
0
1
kbecker
I was under the impression that this was taken care of automatically by the bundle replication however when trying to...
by kbecker Communicator in Splunk Search 10-13-2011
1 5
1
5
rachelneal
I am trying to set a field to the value of a string without the last 2 digits. For example: Hotel=297654 from 29765...
by rachelneal Path Finder in Splunk Search 10-13-2011
0 1
0
1
tasdienes
I upgraded from 4.2.2 to 4.2.3 (Windows). After the upgrade, this message appears in the top of my browser: Miscon...
by tasdienes Engager in Splunk Search 10-12-2011
0 6
0
6
johnnybravo
I want to use dedup to reduce occurrences of the same event like the following: %IP-4-DUPADDR: Duplicate address 1.1...
by johnnybravo Explorer in Splunk Search 10-12-2011
2 4
2
4
mcbradford
This is my search.... index=network source="/u01/noc/log/internetCisco.log" denied |top 100 src_ip | lookup geoip cl...
by mcbradford Contributor in Splunk Search 10-12-2011
0 8
0
8
Jason
I'm dealing with a stream of monitoring data with good and bad events, but no text to distinguish them apart. Good vs...
by Jason Motivator in Splunk Search 10-11-2011
0 5
0
5
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors