| in the manual: http://docs.splunk.com/Documentation/Splunk/4.2.3/Deploy/Mounttheknowledgebundle#Use_mounted_bundles_w... by tpsplunk Communicator in Splunk Search 09-30-2011 2 3 | 2 | 3 | ||
| I am trying to write a query to return host, source, last updated. However, it appears as though the source and host... by tmurray3 Path Finder in Splunk Search 09-30-2011 1 2 | 1 | 2 | ||
| Sorry for the horrible title but I cannot think of a good, succinct description of the problem I am trying to solve (... by Wilcooley Path Finder in Splunk Search 09-30-2011 1 1 | 1 | 1 | ||
| My search looks like this: index=webproxy | regex user=".+a" | top 100 user results are j9999la I want to list t... by mcbradford Contributor in Splunk Search 09-30-2011 0 3 | 0 | 3 | ||
| Hi, I would to know if it is possible to use a part of the source events file path ie "foobar" from /weblogs/123/htt... by pl123 Path Finder in Splunk Search 09-30-2011 1 3 | 1 | 3 | ||
| I'm trying to extract these values into a field called Data. from sample 1: CMD(XYZ) Val(*12A) In props.conf [log... by remy06 Contributor in Splunk Search 09-30-2011 0 10 | 0 | 10 | ||
| My set up is that I have splunk forwarders sending data to two load balanced indexers. I then have a search head that... by builder Path Finder in Splunk Search 09-30-2011 2 6 | 2 | 6 | ||
| Hey all, If you were to manually update the tags.conf file and remove a tagging for a specific server, what is neede... by dayrobertj Engager in Splunk Search 09-29-2011 1 1 | 1 | 1 | ||
| Greetings everyone. This is hopefully a pretty simple question - is there a way to "flatten" transactions? After it r... by msarro Builder in Splunk Search 09-29-2011 0 1 | 0 | 1 | ||
| Log: 2011-09-28 16:13:12,399 INFO [ProxyImpl] [INT1] [Interface] Time taken by Call: 743 milliseconds Requireme... by anirbanukil Explorer in Splunk Search 09-29-2011 1 2 | 1 | 2 | ||
| Hello, I want to create a saved search that will send an email with a report on daily index volumes to know when I'm... by williamsweat Path Finder in Splunk Search 09-29-2011 0 2 | 0 | 2 | ||
| Hi, We have a sql log where the format is not conducive to a predictable pattern for delimiting. Or so i think. In a... by tven7 Path Finder in Splunk Search 09-28-2011 0 5 | 0 | 5 | ||
| Hey everyone. One of my sources has a field which repeats occasionally. I want to filter out any events where there i... by msarro Builder in Splunk Search 09-28-2011 0 2 | 0 | 2 | ||
| Hello, I currently have a problem with my RADIUS logs. I have to retrieve the name of all users whose connection wa... by pascal37 New Member in Splunk Search 09-28-2011 0 1 | 0 | 1 | ||
| Hi, How can I extract hostname from path? /dir/server1/*.log /dir/server2/*.log /dir/server3/*.log I want server1... by rahiparikh Explorer in Splunk Search 09-28-2011 1 3 | 1 | 3 | ||
| hello, i have a subset of results from a search. i now that if I have a clientIP=x.x.x.x, this is proxied and i need ... by johnnymc Path Finder in Splunk Search 09-28-2011 0 7 | 0 | 7 | ||
| I am a total splunk noob (thought I'd throw that out early) I was wondering if there was a way to set up a single va... by appmandan Path Finder in Splunk Search 09-27-2011 1 2 | 1 | 2 | ||
| i have the following jboss http log entry 00.00.00.253 11.11.111.111 [27/Sep/2011:00:45:31 -0700] GET /xyz/images/sp... by tven7 Path Finder in Splunk Search 09-27-2011 0 2 | 0 | 2 | ||
| Cab someone please explain what the following parts of the query do (just the bolded portion, not the entire query). ... by DTERM Contributor in Splunk Search 09-27-2011 1 3 | 1 | 3 | ||
| Other than making a saved search private, is there any way to hide saved searches so users who have no no administrat... by itsomana Path Finder in Splunk Search 09-27-2011 0 1 | 0 | 1 | ||
| If I have more than one splunk user interface that users log into, either for regional goals, or for load balancing, ... by jrodman Splunk Employee 3 8 | 3 | 8 | ||
| Hi, I've a bar graph containing some values on X-axis & its count on Y-axis (....chart count by contentValue...). H... by freephoneid Path Finder in Splunk Search 09-26-2011 1 3 | 1 | 3 | ||
| I have a sourcetype called sourcetype1 that contains the following three events: foo=a foo=b foo=c I then have a s... by kevintelford Path Finder in Splunk Search 09-26-2011 0 6 | 0 | 6 | ||
| I am battling with the use of the map search command. I have some queries that work fine by themselves, but when I t... by raoul Path Finder in Splunk Search 09-26-2011 0 3 | 0 | 3 | ||
| Hey everyone. Right now I am working with a transaction. I currently have two sources which I am trying to correlate ... by msarro Builder in Splunk Search 09-26-2011 0 1 | 0 | 1 |