Splunk Search

Splunk Search
Community Activity
timbCFCA
I am attempting to extract key value pairs from a data stream with the following syntax. Successful Logon: User ...
by timbCFCA Path Finder in Splunk Search 09-14-2011
0 2
0
2
joshrabinowitz
Tried suggestions from other Q/A, but alas. Trying to route syslog data from one host to an index other than main. th...
by joshrabinowitz Path Finder in Splunk Search 09-14-2011
0 3
0
3
netwrkr
Assume we have a log file with at least the following fields timestamp field A field B field C ..... ex: ...
by netwrkr Communicator in Splunk Search 09-14-2011
0 1
0
1
michael_bates_1
Evening All, I am currently collecting a feed of syslog messages from a RADIUS platform. I need to be able to detect...
by michael_bates_1 Path Finder in Splunk Search 09-14-2011
1 1
1
1
rpeters_tlm
We were using the download-trial license. It expired but we didn't notice for two weeks, so we exceeded for each of t...
by rpeters_tlm New Member in Splunk Search 09-14-2011
0 3
0
3
huaraz
Hi, How is splunk dealing with logfiles which rotate like syslog ? Will splunk loose data during the rotation ? To ...
by huaraz Explorer in Splunk Search 09-14-2011
0 2
0
2
sideview
I'm trying to create a scripted lookup and I'm finding it a little frustrating because any time there's a python exce...
by SplunkTrust SplunkTrust in Splunk Search 09-13-2011
2 9
2
9
tpsplunk
I have a web request log with searchtime extracted fields customer_id, object_id, response_time. I would like to cra...
by tpsplunk Communicator in Splunk Search 09-13-2011
0 2
0
2
lisheridan
I'd like to change the favicon in my custom app. What is the recommended way to do this (for app only, not global).
by lisheridan Explorer in Splunk Search 09-13-2011
2 1
2
1
huaraz
Hi, I would like to find out that my transactions are correctly put together so that I don't get invalid transaction...
by huaraz Explorer in Splunk Search 09-13-2011
0 1
0
1
timbCFCA
I love Splunk's ability to dynamically pull fields at runtime with name=value pairs. I have several log formats whic...
by timbCFCA Path Finder in Splunk Search 09-13-2011
0 6
0
6
huaraz
Hi I have logfiles where I have a start event and a stop event and I would like to search for all events between th...
by huaraz Explorer in Splunk Search 09-13-2011
0 2
0
2
sf-mike
I have the value "N/A" that is applied to any field that doesn't have an entry. I need to change this to a numerical ...
by sf-mike Splunk Employee Splunk Employee in Splunk Search 09-13-2011
1 1
1
1
rturk
Greetings Splunkers (and Splunkettes), I have a large amount of raw data in the default index of sourcetype "hsl_f5_...
by rturk Builder in Splunk Search 09-13-2011
0 11
0
11
Takajian
Is there any way to sepcify the time range "holiday"? I know the time modifier "w0" is Sunday. But I do not know how...
by Takajian Builder in Splunk Search 09-13-2011
0 2
0
2
oreni
The subsearch documentation says the following: maxout = * Maximum number of results to return from a subsearch. *...
by oreni Explorer in Splunk Search 09-13-2011
0 1
0
1
rachelneal
Here is my search: source="/usr/local/logs/request/request.log" Supplier="LO" OR Supplier="AL" Type= "Availability"...
by rachelneal Path Finder in Splunk Search 09-12-2011
0 6
0
6
MBerikcurtis
I'm using the search to get a count of Windows Event Codes. If I remove stats count by EventCode, I get the Event Des...
by MBerikcurtis Path Finder in Splunk Search 09-12-2011
2 5
2
5
rachelneal
I have several error logs that have a similar format: Cannot set Single Use Prices on Single Room Standard Room ( C...
by rachelneal Path Finder in Splunk Search 09-12-2011
0 5
0
5
mikefoti
I would like to filter for events that occurred immediately before and after a given windows eventID. For example, if...
by mikefoti Communicator in Splunk Search 09-09-2011
0 1
0
1
mlulmer
Feature Request: Setup F5 Big-IP product has many applications (ASM, FirePass, LTM); we might not use all of these o...
by mlulmer Explorer in Splunk Search 09-09-2011
0 1
0
1
Marinus
I've recently split up my data into indexes and some of my searches that make use of sub searches are now breaking. ...
by Marinus Communicator in Splunk Search 09-09-2011
1 2
1
2
bbingham
When setting up my own application, what are my options for creating a "setup experience". Will Setup.xml meet all m...
by bbingham Builder in Splunk Search 09-08-2011
1 4
1
4
araitz
Are field values case sensitive? Is this behavior the same in 3.x and 4.x versions of Splunk?
by araitz Splunk Employee Splunk Employee in Splunk Search 09-08-2011
7 3
7
3
xipander
I'm trying to graph a custom long that gives the round trip time of a web service request. I've got sourcetype="wspi...
by xipander New Member in Splunk Search 09-08-2011
0 5
0
5
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...