Splunk Search

Splunk Search
Community Activity
mknowles
Hello, I've figured out how to start a real-time search job. I'm wondering if there's any way to trigger a shell co...
by mknowles Engager in Splunk Search 10-20-2011
2 7
2
7
anshumishra
Hi, I have a log where the, app logs the various steps for a unique opertaion id (id below) -> ...... ts=13188618399...
by anshumishra New Member in Splunk Search 10-19-2011
0 3
0
3
lisa_1
The transaction command matches only the first instance of the specified endswith, however it's possible and likely t...
by lisa_1 Explorer in Splunk Search 10-19-2011
2 4
2
4
adityapavan18
Hi, I have 2 search queries. sourcetype="zzz" Accepted | stats count as SuccessCases sourcetype="zzz" Rejected | s...
by adityapavan18 Contributor in Splunk Search 10-19-2011
0 7
0
7
hartfoml
I have this regex expresion: REGEX = (?m)^EventCode=(4674)|(ServerName\$) This works great to identify the two cond...
by hartfoml Motivator in Splunk Search 10-19-2011
0 10
0
10
myli12
I tried the following: host=A earliest=10/01/2011:0:0:0 latest=10/01/2011:11:0:0 | timechart span=1h count by msg W...
by myli12 Path Finder in Splunk Search 10-18-2011
0 1
0
1
sf_user_199
I have the following xml <module name="HiddenSearch" layoutPanel="panel_row2_col1" group="XXX" autoRun="True"> ...
by sf_user_199 Path Finder in Splunk Search 10-18-2011
1 5
1
5
JovanMilosevic
Hi, I have some events, and a User lookup. The Lookup holds the UserID, User Name, a WorkGroup, and dates when th...
by JovanMilosevic Path Finder in Splunk Search 10-18-2011
1 3
1
3
lanying
In a dashboard, calling a csv file query. Then I want to insert a present login account*(UserAccount)*. How can I ge...
by lanying Explorer in Splunk Search 10-18-2011
0 3
0
3
jcfergus
This seems like it should be such a straightforward thing, but having a hard time nailing down an answer we're happy ...
by jcfergus Engager in Splunk Search 10-17-2011
0 1
0
1
thejaspavithran
Hi, I have a set of logs in the following format 2011-10-17 14:16:11,117 [main] : DEBUG - <Application Id [461620...
by thejaspavithran New Member in Splunk Search 10-17-2011
0 2
0
2
timpet
I can check the DB size and it continues to grow but nothing new shows up in the search. I have 2 that are updating a...
by timpet New Member in Splunk Search 10-14-2011
0 1
0
1
merritsa
We have a search that someone from Splunk helped us put together a few years ago that we altered a bit: index="Firew...
by merritsa Path Finder in Splunk Search 10-14-2011
0 4
0
4
kholleran
Hi, I am sure the answer is out there but I am not exactly sure how to ask the question. My Splunk server has two p...
by kholleran Communicator in Splunk Search 10-14-2011
0 1
0
1
kmisaal
I have a simple configuration for few forwarders and an indexer. I have configured the field look-up on Splunk indexe...
by kmisaal New Member in Splunk Search 10-13-2011
0 1
0
1
kbecker
I was under the impression that this was taken care of automatically by the bundle replication however when trying to...
by kbecker Communicator in Splunk Search 10-13-2011
1 5
1
5
rachelneal
I am trying to set a field to the value of a string without the last 2 digits. For example: Hotel=297654 from 29765...
by rachelneal Path Finder in Splunk Search 10-13-2011
0 1
0
1
tasdienes
I upgraded from 4.2.2 to 4.2.3 (Windows). After the upgrade, this message appears in the top of my browser: Miscon...
by tasdienes Engager in Splunk Search 10-12-2011
0 6
0
6
johnnybravo
I want to use dedup to reduce occurrences of the same event like the following: %IP-4-DUPADDR: Duplicate address 1.1...
by johnnybravo Explorer in Splunk Search 10-12-2011
2 4
2
4
mcbradford
This is my search.... index=network source="/u01/noc/log/internetCisco.log" denied |top 100 src_ip | lookup geoip cl...
by mcbradford Contributor in Splunk Search 10-12-2011
0 8
0
8
Jason
I'm dealing with a stream of monitoring data with good and bad events, but no text to distinguish them apart. Good vs...
by Jason Motivator in Splunk Search 10-11-2011
0 5
0
5
jerrad
I have spent some time reading through the UI examples App and have attempted to duplicate a basic drill down action ...
by jerrad Path Finder in Splunk Search 10-11-2011
0 4
0
4
mcbradford
This is my search... index=webproxy | regex user=".+a" | top 100 user | eval user_name=substr(user,1,5) I have a...
by mcbradford Contributor in Splunk Search 10-11-2011
1 1
1
1
esp
Is it possible to dynamically calculate the RHS of a search comparison? I'm looking to use Splunk to do latency meas...
by esp New Member in Splunk Search 10-11-2011
0 5
0
5
erga00
I have a extremely slow search and I cannot understand why it is so. I'd appreciate any pointers. Hardware is not a ...
by erga00 Path Finder in Splunk Search 10-10-2011
1 1
1
1
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...