| Thread Info | |||||
|---|---|---|---|---|---|
|
What is the expected outcome of the "Yesterday" time function when applied to data from multiple timezones. I have a ...
by
matt
Splunk Employee
in
Splunk Search
09-21-2010
|
2
|
2
| |||
|
In the search field, I entered: source=/logs/*/*.log it matches /logs/*/*.log and /logs/*/*/*.log. I need to see only...
by
laughterjj
New Member
in
Splunk Search
09-05-2011
|
0
|
2
| |||
|
I have a extracted value from log, puserid. now I have map that Id to a user in lookup table. now when I am applying ...
by
sumitnagal
Path Finder
in
Splunk Search
09-04-2011
|
0
|
1
| |||
|
I create a search called: "poral_app_server", I made a modification to the search string, click "save search" and typ...
by
laughterjj
New Member
in
Splunk Search
09-04-2011
|
0
|
1
| |||
|
Hi, I'm trying to understand how the Field Discovery part works by default while dealing with a multi-value string c...
by
swapsapar
New Member
in
Splunk Search
09-02-2011
|
0
|
1
| |||
|
I currently have some medical records in doc form that are binary text created in ms office word.
I want to create...
by
maverick
Splunk Employee
in
Splunk Search
08-04-2011
|
0
|
3
| |||
|
I have a bunch of uris to extract and categorize. And after that i need to timechart it by category.
so say the lo...
by
tven7
Path Finder
in
Splunk Search
09-02-2011
|
0
|
1
| |||
|
I've got a chart that works great but just wanting to re-arrange the result.
timechart eval(sum(Logical_Capacity_...
by
clintla
Contributor
in
Splunk Search
08-31-2011
|
0
|
7
| |||
|
Hi All,
I have the following setup in my environment: 1) light forwarder installed on the machine where logs are g...
by
sscandoit
Explorer
in
Splunk Search
08-31-2011
|
0
|
2
| |||
|
I have a problem where I have a table that has a _time column and two other columns, I have a search that sorts that ...
by
Dark_Ichigo
Builder
in
Splunk Search
08-30-2011
|
1
|
6
| |||
|
I do realize there is another thread where someone asks the same question, but he solved his problem when he checked ...
by
jchensor
Communicator
in
Splunk Search
09-01-2011
|
0
|
1
| |||
|
We have a flat file that contains user data. Changes made to this file are not audited. I'd like Splunk to report on ...
by
JovanMilosevic
Path Finder
in
Splunk Search
09-01-2011
|
1
|
2
| |||
|
I created a search time that works as expected when I do a search on only the sourcetype that I created the extractio...
by
cpenkert
Path Finder
in
Splunk Search
08-29-2011
|
1
|
5
| |||
|
Hi, Hoping this is something simple that I'm not understanding.
Example Data:
Sourcetype=A Sport1=baseball
S...
by
cramasta
Builder
in
Splunk Search
08-31-2011
|
0
|
5
| |||
|
I have an _raw event with data that I would like to break out into key value pairs. I was wondering if anyone had any...
by
lisaac
Path Finder
in
Splunk Search
08-31-2011
|
0
|
1
| |||
|
Hi,
I am new to splunk and heard it can do nearly every type of reporting. I have an ADSL router creating logs in ...
by
huaraz
Explorer
in
Splunk Search
08-27-2011
|
0
|
4
| |||
|
I'm getting error an on piping one command into another. The result is a "Search operation 'earliest' is unknown. You...
by
DTERM
Contributor
in
Splunk Search
08-26-2011
|
0
|
3
| |||
|
How can I check if my custom fields work ? How can I list the content of custom fields ?
Thank you
Markus
by
huaraz
Explorer
in
Splunk Search
08-30-2011
|
0
|
3
| |||
|
Hello fellow Splunkers!
ipc=ipc1-r6c10 Intake-Temperature=70 Exhaust-Temperature=82 Humidity=44% Amps=6 Volta...
by
zachvida
Path Finder
in
Splunk Search
08-31-2011
|
0
|
2
| |||
|
I just setup my test forefront proxy server to forward logs to my test Splunk indexer. Is there a stash of existing q...
by
mikefoti
Communicator
in
Splunk Search
08-29-2011
|
1
|
6
| |||
|
I have blue bar notification in each view informing me that an event was received "for unconfigured/disabled index='s...
by
muebel
SplunkTrust
in
Splunk Search
05-20-2010
|
2
|
7
| |||
|
I have a field that looks like this: key1=value1*key2=value2*key3=value3
I put in a stanza in transforms that look...
by
kkalmbach
Path Finder
in
Splunk Search
08-25-2011
|
0
|
3
| |||
|
i have following data
playdate, adid, store,
2011-08-23, 1 , s1
2011-08-23, 2, s2
2011-08-23, 1, s2
2011-08-25, 2...
by
desi
New Member
in
Splunk Search
08-29-2011
|
0
|
1
| |||
|
I'm encountering something that seemed non-intuitive to me in my Search app through the web interface. I'm trying to ...
by
phatfingers
Explorer
in
Splunk Search
08-29-2011
|
1
|
2
| |||
|
Hello.
I have a set of advanced views, dashboards, searches, etc for the search app, which i have developed using ...
by
smtnw666
Engager
in
Splunk Search
08-29-2011
|
3
|
1
|