Splunk Search

Splunk Search
Community Activity
jdunlea_splunk
I am wondering if we can change a search on a dashboard based upon the time range selected. EG: I have a hidden sear...
by jdunlea_splunk Splunk Employee Splunk Employee in Splunk Search 10-05-2011
1 2
1
2
freephoneid
Hi, Currently, I'm getting number of users logged in last 24 hrs as below... index=myindex sourcetype="my_log" logi...
by freephoneid Path Finder in Splunk Search 10-05-2011
0 5
0
5
talbot7
Trying to click on an item in the legend and have a new search come up based on item clicked. Here is my current wor...
by talbot7 Path Finder in Splunk Search 10-05-2011
0 1
0
1
donwant
I am using Exchange 2007 SP3 and it appears that my logs are flowing to the Splunk Instance. Some of the searches an...
by donwant Explorer in Splunk Search 10-05-2011
0 1
0
1
tgiles
Hi, all. I was asked to get Exchange logs from an Exchange 2010 cluster going to Splunk. I've installed a forwarder ...
by tgiles Path Finder in Splunk Search 10-05-2011
1 2
1
2
cgl
I have a vendor log file that has numeric codes for the field names (i.e. E-1, E-710, etc). The vendor also provides...
by cgl Explorer in Splunk Search 10-04-2011
2 6
2
6
myli12
I want to extract two adjacent events, i.e., the first one with keyword "synchronization" and the event immediately f...
by myli12 Path Finder in Splunk Search 10-04-2011
0 1
0
1
catty
I trying to rename sourcetype for this regex but won't work but when i remove the rename = httpd-access its work? [a...
by catty Engager in Splunk Search 10-03-2011
0 2
0
2
anushamkrishna
Hi, I have log messages like this: 1) ECMSELECT_SERVICE_RESPONSEReceived Tru2way Proxy Sync Response - selectServic...
by anushamkrishna New Member in Splunk Search 10-03-2011
0 1
0
1
jlixfeld
I've clearly munged something in my transform: # props.conf [snmp-trap] pulldown_type = true maxDist = 3 TIME_FORM...
by jlixfeld Path Finder in Splunk Search 10-03-2011
1 3
1
3
tgiles
Hi, Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same...
by tgiles Path Finder in Splunk Search 10-03-2011
0 3
0
3
johnboldt
I'm using the following search using Splunk 4.2.1: sourcetype=somesourcetype (tag=Metric AND tag=ResponseTime) NOT t...
by johnboldt Explorer in Splunk Search 10-02-2011
1 2
1
2
freephoneid
Hi, I would like to know how exactly scheduled saved search works. I've a saved search for which I gave the time ra...
by freephoneid Path Finder in Splunk Search 10-02-2011
0 3
0
3
freephoneid
Hi, I've below log lines in below format: [2011-09-30 23:33:20:465 GMT+00:00][F3951B38F4DF45440927EDF522D5C9FF.http...
by freephoneid Path Finder in Splunk Search 10-02-2011
0 3
0
3
joy76
<module Search> <search> search string </search> <module resultTable> <module Redirect autorun="true"> ...
by joy76 Path Finder in Splunk Search 09-30-2011
0 1
0
1
talbot7
When I search for: index=unix pool=general1 dom0stat42 | delta stolen_cpu_ticks as sct | eval abssct=abs(sct) | ti...
by talbot7 Path Finder in Splunk Search 09-30-2011
1 2
1
2
freephoneid
Hi, I want to find out how many users have blue colors & how many of them have red color for all unique users? [201...
by freephoneid Path Finder in Splunk Search 09-30-2011
0 1
0
1
tpsplunk
in the manual: http://docs.splunk.com/Documentation/Splunk/4.2.3/Deploy/Mounttheknowledgebundle#Use_mounted_bundles_w...
by tpsplunk Communicator in Splunk Search 09-30-2011
2 3
2
3
tmurray3
I am trying to write a query to return host, source, last updated. However, it appears as though the source and host...
by tmurray3 Path Finder in Splunk Search 09-30-2011
1 2
1
2
Wilcooley
Sorry for the horrible title but I cannot think of a good, succinct description of the problem I am trying to solve (...
by Wilcooley Path Finder in Splunk Search 09-30-2011
1 1
1
1
mcbradford
My search looks like this: index=webproxy | regex user=".+a" | top 100 user results are j9999la I want to list t...
by mcbradford Contributor in Splunk Search 09-30-2011
0 3
0
3
pl123
Hi, I would to know if it is possible to use a part of the source events file path ie "foobar" from /weblogs/123/htt...
by pl123 Path Finder in Splunk Search 09-30-2011
1 3
1
3
remy06
I'm trying to extract these values into a field called Data. from sample 1: CMD(XYZ) Val(*12A) In props.conf [log...
by remy06 Contributor in Splunk Search 09-30-2011
0 10
0
10
builder
My set up is that I have splunk forwarders sending data to two load balanced indexers. I then have a search head that...
by builder Path Finder in Splunk Search 09-30-2011
2 6
2
6
dayrobertj
Hey all, If you were to manually update the tags.conf file and remove a tagging for a specific server, what is neede...
by dayrobertj Engager in Splunk Search 09-29-2011
1 1
1
1
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors