Splunk Search

Splunk Search
Community Activity
esp
Is it possible to dynamically calculate the RHS of a search comparison? I'm looking to use Splunk to do latency meas...
by esp New Member in Splunk Search 10-11-2011
0 5
0
5
erga00
I have a extremely slow search and I cannot understand why it is so. I'd appreciate any pointers. Hardware is not a ...
by erga00 Path Finder in Splunk Search 10-10-2011
1 1
1
1
itsomana
I have configured a dashboard with 28 boxes which change from green to red depending on the parameters of the saved s...
by itsomana Path Finder in Splunk Search 10-10-2011
0 1
0
1
Katsche
Hi all, I have two searches here, which are nearly the same (5 Events more at one of them). Is it somehow possible t...
by Katsche Path Finder in Splunk Search 10-10-2011
0 6
0
6
Marinus
I've been tinkering with a custom search command that uses win32com.client. When I try to invoke my search command I ...
by Marinus Communicator in Splunk Search 10-10-2011
1 3
1
3
motzgogh
I am a complete splunk newbie and I'm trying to find information on how powerful the searches and reports can be. Let...
by motzgogh Engager in Splunk Search 10-10-2011
0 1
0
1
dang
I've got a splunk query like the following: ...| timechart span=10m max(CurrentAnonymousUsers) by ComputerName Bec...
by dang Path Finder in Splunk Search 10-08-2011
2 1
2
1
jlixfeld
I'm trying to put into practice what I saw in Michael Wilde's Regex video with regards to making rex searches persist...
by jlixfeld Path Finder in Splunk Search 10-08-2011
0 8
0
8
myli12
I tried to use subsearch to find the 2nd last synchronization event by using the following: synchronization [search ...
by myli12 Path Finder in Splunk Search 10-07-2011
1 1
1
1
mcbradford
My results are like... src_ip src_geo count 55.89.12.11 US 25 I want the result to b...
by mcbradford Contributor in Splunk Search 10-07-2011
1 3
1
3
ilove275
Why can't use subsearch in case command? index="01_firewall" sourcetype="01_firewall" [search index=webping | rename...
by ilove275 Path Finder in Splunk Search 10-07-2011
5 4
5
4
freephoneid
Hi, I've a simple query as shown below to display the column chart over time. MY_QUERY: index=my_index sourcetype="...
by freephoneid Path Finder in Splunk Search 10-07-2011
1 1
1
1
freephoneid
I've following data in my summary index by time which runs in time range -1d@d to @d every day @ midnight: 09-01-11:...
by freephoneid Path Finder in Splunk Search 10-06-2011
0 1
0
1
msarro
Hey everyone, I am working on an issue right now and I'm running into a problem with my understanding of how splunk w...
by msarro Builder in Splunk Search 10-06-2011
3 4
3
4
jdunlea_splunk
I am wondering if we can change a search on a dashboard based upon the time range selected. EG: I have a hidden sear...
by jdunlea_splunk Splunk Employee Splunk Employee in Splunk Search 10-05-2011
1 2
1
2
freephoneid
Hi, Currently, I'm getting number of users logged in last 24 hrs as below... index=myindex sourcetype="my_log" logi...
by freephoneid Path Finder in Splunk Search 10-05-2011
0 5
0
5
talbot7
Trying to click on an item in the legend and have a new search come up based on item clicked. Here is my current wor...
by talbot7 Path Finder in Splunk Search 10-05-2011
0 1
0
1
donwant
I am using Exchange 2007 SP3 and it appears that my logs are flowing to the Splunk Instance. Some of the searches an...
by donwant Explorer in Splunk Search 10-05-2011
0 1
0
1
tgiles
Hi, all. I was asked to get Exchange logs from an Exchange 2010 cluster going to Splunk. I've installed a forwarder ...
by tgiles Path Finder in Splunk Search 10-05-2011
1 2
1
2
cgl
I have a vendor log file that has numeric codes for the field names (i.e. E-1, E-710, etc). The vendor also provides...
by cgl Explorer in Splunk Search 10-04-2011
2 6
2
6
myli12
I want to extract two adjacent events, i.e., the first one with keyword "synchronization" and the event immediately f...
by myli12 Path Finder in Splunk Search 10-04-2011
0 1
0
1
catty
I trying to rename sourcetype for this regex but won't work but when i remove the rename = httpd-access its work? [a...
by catty Engager in Splunk Search 10-03-2011
0 2
0
2
anushamkrishna
Hi, I have log messages like this: 1) ECMSELECT_SERVICE_RESPONSEReceived Tru2way Proxy Sync Response - selectServic...
by anushamkrishna New Member in Splunk Search 10-03-2011
0 1
0
1
jlixfeld
I've clearly munged something in my transform: # props.conf [snmp-trap] pulldown_type = true maxDist = 3 TIME_FORM...
by jlixfeld Path Finder in Splunk Search 10-03-2011
1 3
1
3
tgiles
Hi, Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same...
by tgiles Path Finder in Splunk Search 10-03-2011
0 3
0
3
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors