| I'm trying to put into practice what I saw in Michael Wilde's Regex video with regards to making rex searches persist... by jlixfeld Path Finder in Splunk Search 10-08-2011 0 8 | 0 | 8 | ||
| I tried to use subsearch to find the 2nd last synchronization event by using the following: synchronization [search ... by myli12 Path Finder in Splunk Search 10-07-2011 1 1 | 1 | 1 | ||
| My results are like... src_ip src_geo count 55.89.12.11 US 25 I want the result to b... by mcbradford Contributor in Splunk Search 10-07-2011 1 3 | 1 | 3 | ||
| Why can't use subsearch in case command? index="01_firewall" sourcetype="01_firewall" [search index=webping | rename... by ilove275 Path Finder in Splunk Search 10-07-2011 5 4 | 5 | 4 | ||
| Hi, I've a simple query as shown below to display the column chart over time. MY_QUERY: index=my_index sourcetype="... by freephoneid Path Finder in Splunk Search 10-07-2011 1 1 | 1 | 1 | ||
| I've following data in my summary index by time which runs in time range -1d@d to @d every day @ midnight: 09-01-11:... by freephoneid Path Finder in Splunk Search 10-06-2011 0 1 | 0 | 1 | ||
| Hey everyone, I am working on an issue right now and I'm running into a problem with my understanding of how splunk w... by msarro Builder in Splunk Search 10-06-2011 3 4 | 3 | 4 | ||
| I am wondering if we can change a search on a dashboard based upon the time range selected. EG: I have a hidden sear... by jdunlea_splunk Splunk Employee 1 2 | 1 | 2 | ||
| Hi, Currently, I'm getting number of users logged in last 24 hrs as below... index=myindex sourcetype="my_log" logi... by freephoneid Path Finder in Splunk Search 10-05-2011 0 5 | 0 | 5 | ||
| Trying to click on an item in the legend and have a new search come up based on item clicked. Here is my current wor... by talbot7 Path Finder in Splunk Search 10-05-2011 0 1 | 0 | 1 | ||
| I am using Exchange 2007 SP3 and it appears that my logs are flowing to the Splunk Instance. Some of the searches an... by donwant Explorer in Splunk Search 10-05-2011 0 1 | 0 | 1 | ||
| Hi, all. I was asked to get Exchange logs from an Exchange 2010 cluster going to Splunk. I've installed a forwarder ... by tgiles Path Finder in Splunk Search 10-05-2011 1 2 | 1 | 2 | ||
| I have a vendor log file that has numeric codes for the field names (i.e. E-1, E-710, etc). The vendor also provides... by cgl Explorer in Splunk Search 10-04-2011 2 6 | 2 | 6 | ||
| I want to extract two adjacent events, i.e., the first one with keyword "synchronization" and the event immediately f... by myli12 Path Finder in Splunk Search 10-04-2011 0 1 | 0 | 1 | ||
| I trying to rename sourcetype for this regex but won't work but when i remove the rename = httpd-access its work? [a... by catty Engager in Splunk Search 10-03-2011 0 2 | 0 | 2 | ||
| Hi, I have log messages like this: 1) ECMSELECT_SERVICE_RESPONSEReceived Tru2way Proxy Sync Response - selectServic... by anushamkrishna New Member in Splunk Search 10-03-2011 0 1 | 0 | 1 | ||
| I've clearly munged something in my transform: # props.conf [snmp-trap] pulldown_type = true maxDist = 3 TIME_FORM... by jlixfeld Path Finder in Splunk Search 10-03-2011 1 3 | 1 | 3 | ||
| Hi, Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same... by tgiles Path Finder in Splunk Search 10-03-2011 0 3 | 0 | 3 | ||
| I'm using the following search using Splunk 4.2.1: sourcetype=somesourcetype (tag=Metric AND tag=ResponseTime) NOT t... by johnboldt Explorer in Splunk Search 10-02-2011 1 2 | 1 | 2 | ||
| Hi, I would like to know how exactly scheduled saved search works. I've a saved search for which I gave the time ra... by freephoneid Path Finder in Splunk Search 10-02-2011 0 3 | 0 | 3 | ||
| Hi, I've below log lines in below format: [2011-09-30 23:33:20:465 GMT+00:00][F3951B38F4DF45440927EDF522D5C9FF.http... by freephoneid Path Finder in Splunk Search 10-02-2011 0 3 | 0 | 3 | ||
| <module Search> <search> search string </search> <module resultTable> <module Redirect autorun="true"> ... by joy76 Path Finder in Splunk Search 09-30-2011 0 1 | 0 | 1 | ||
| When I search for: index=unix pool=general1 dom0stat42 | delta stolen_cpu_ticks as sct | eval abssct=abs(sct) | ti... by talbot7 Path Finder in Splunk Search 09-30-2011 1 2 | 1 | 2 | ||
| Hi, I want to find out how many users have blue colors & how many of them have red color for all unique users? [201... by freephoneid Path Finder in Splunk Search 09-30-2011 0 1 | 0 | 1 | ||
| in the manual: http://docs.splunk.com/Documentation/Splunk/4.2.3/Deploy/Mounttheknowledgebundle#Use_mounted_bundles_w... by tpsplunk Communicator in Splunk Search 09-30-2011 2 3 | 2 | 3 |