Splunk Search

Splunk Search
Community Activity
TheMarkHodgkins
Pardon my newbie'ness  Does anyone have an example where Search results are matched to table entries (simple CSV sh...
by TheMarkHodgkins Explorer in Splunk Search 11-09-2011
0 1
0
1
gooza
Hi, I'd like to add knowledge to our splunk data and divide ips or computers to different groups like test/productio...
by gooza Communicator in Splunk Search 11-08-2011
1 4
1
4
keshab
2011-11-07 13:25:35,145 FE (Exe 45) (pid 11788) destroyed 2011-11-07 13:25:35,152 PNG.exe (Exe 64) (pid 17286) des...
by keshab Path Finder in Splunk Search 11-08-2011
0 5
0
5
moonmyj
Hi All, I have Windows 2008 64bit & Windows 2003 64bit server. I've installed splunk 4.2.4 64bit(via administrator u...
by moonmyj New Member in Splunk Search 11-08-2011
0 8
0
8
jcfergus
From what I've been reading, I don't see that this is possible, but... Is there any way to create a saved search that...
by jcfergus Engager in Splunk Search 11-08-2011
0 2
0
2
cloudharmony
I'm running a search against about 1.2 million log records. Each record contains some geo tags and numeric values rep...
by cloudharmony Explorer in Splunk Search 11-07-2011
1 6
1
6
atomlinson81
a bit of background info - we use sophos av software, and all machines use a local account on the sophos management s...
by atomlinson81 New Member in Splunk Search 11-07-2011
0 4
0
4
dmlee
Hi I wrote a simple form search dashboard using <table> module . I found if the number of results over 50,000 , wh...
by dmlee Communicator in Splunk Search 11-07-2011
0 1
0
1
oreni
Hello, I'm running a saved search which runs perfectly fine, but when I'm trying to use Report Builder I'm getting ...
by oreni Explorer in Splunk Search 11-06-2011
1 1
1
1
rowshambow
I've set up a transaction to determine successful login using the following: index=main sourcetype=TELEM | transacti...
by rowshambow New Member in Splunk Search 11-06-2011
0 1
0
1
Josh
Hello All, What is the best way to extract into a single field mutiple values from a comma-seperated list: Example:...
by Josh Path Finder in Splunk Search 11-06-2011
1 3
1
3
keshab
I have two log line with the same information. How can I do search so that it displays just one log?? For e.g. 2011...
by keshab Path Finder in Splunk Search 11-04-2011
0 2
0
2
nickhills
We are logging data from a number of devices which send a periodic heartbeat back to us, which among other things inc...
by nickhills Ultra Champion in Splunk Search 11-04-2011
0 1
0
1
crobicha
I have ssh events in the following log format: sshd[31922]: pam_unix(sshd:session): session closed for user root ss...
by crobicha Explorer in Splunk Search 11-04-2011
0 2
0
2
mrdaniel
I have tried to get Splunk to recognize a new format of dates but im unable even to get the train date to understand ...
by mrdaniel Explorer in Splunk Search 11-04-2011
0 1
0
1
keshab
I have splunk indexed log for 6 months but I want to search log for 20 days only(from current date till 20 days ago) ...
by keshab Path Finder in Splunk Search 11-04-2011
0 3
0
3
keshab
What's the difference between daily, fivemin, and all backfilling python script? What does this script actually do ...
by keshab Path Finder in Splunk Search 11-03-2011
0 2
0
2
mbassettjr
I have the splunk irule working and I'm seeing information in the dashboards. However, the Top User Agents charts ...
by mbassettjr Explorer in Splunk Search 11-03-2011
0 2
0
2
Drainy
I am trying to implement similar functionality to that seen in the Deployment monitor whereby there is a single value...
by Drainy Champion in Splunk Search 11-03-2011
0 3
0
3
Ant1D
Hi, I would like to disable legend drilldown but in doing so, I want chart cell drilldown to not be disabled. Exampl...
by Ant1D Motivator in Splunk Search 11-03-2011
1 3
1
3
Drainy
I have a search; host=127.0.0.1 type=* notification_level=Warning device_ip=192.168.0.1 If I add earliest=-12h@h t...
by Drainy Champion in Splunk Search 11-03-2011
1 2
1
2
asingla
I am receiving events every 15 seconds. But when I enable real time search in default splunk search app for query sou...
by asingla Communicator in Splunk Search 11-02-2011
0 2
0
2
freephoneid
How do I use eval in below query to add hard coded value, say 1000 to the final count? index=myindex | stats first(i...
by freephoneid Path Finder in Splunk Search 11-01-2011
1 3
1
3
cloudharmony
I have a log with entries like this: region.0="us" region.1="us_west" region.2="us_west_pacific" region.3="us_ca". Th...
by cloudharmony Explorer in Splunk Search 11-01-2011
0 1
0
1
keshab
Hi, What will be the search condition if I wanna display only one log line if they occur within 5 min?? For e.g. 1...
by keshab Path Finder in Splunk Search 11-01-2011
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...