| Thread Info | |||||
|---|---|---|---|---|---|
| 
        We've got an XML file that is being parsed correctly (and easily - just piped into xmlkv) but one of the fields is nu...
        
         
           by 
           
                
                    
                        mikeely
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-18-2011
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        How can I format the output from a Splunk query? 
  For example I have three fields extracted, A, B, C. I'd like to o...
        
         
           by 
           
                
                    
                        timbCFCA
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-18-2011
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello, 
  I was wondering if it's possible to schedule a search to run in increments less than 1 minute? 
  Thanks
        
         
           by 
           
                
                    
                        samiomer
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-16-2011
             
           
         
        | 
		
		2
   | 
	  
	  3
	 | |||
| 
        All, 
  I have a search that is looking for two specific events. One is for new 2008 OS's and up, the other is 2003 O...
        
         
           by 
           
                
                    
                        jcrensh
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-18-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have a field like this:  
  ... group="Group One,Group2,Some Other Group" ...
 
  Using 'makemv delim="," group' is...
        
         
           by 
           
                
                    
                        mw
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               12-14-2010
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        If I use the metadata command it only gives me keys for the main index, can I call it for other indexes? For example ...
        
         
           by 
           
                
                    
                        Marinus
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-16-2011
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have the following two queries: 
  index=MyApp earliest=-30d@d-2h latest=-1d@d+10h | bucket _time span=24h | stats ...
        
         
           by 
           
                
                    
                        DTERM
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-16-2011
             
           
         
        | 
		
		1
   | 
	  
	  6
	 | |||
| 
        I'm new to all of this and can mainly do nothing but some simple searches. But if I wanted to create a graph showing ...
        
         
           by 
           
                
                    
                        jcott28
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-17-2011
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hey everyone. I'm having a dumb moment, so please be gentle. I have a number of records, and each one has an ID to id...
        
         
           by 
           
                
                    
                        msarro
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               08-17-2011
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        We have set up many alerts to trigger based on a count threshold for a specific event over a set period of time. Give...
        
         
           by 
           
                
                    
                        agthurber
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-16-2011
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I installed splunk 4.2.3 and I want to monitor statistics of BIND 9.7.2 (DNS) queries through it. I used SPLUNK FOR B...
        
         
           by 
           
                
                    
                        sdsajjadi
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-13-2011
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        How do I develop a query that groups events by product names? I don't know what the product names are. But I need a q...
        
         
           by 
           
                
                    
                        DTERM
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-15-2011
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi all,  
  I have some statistical log like: Unit Type (M) Used Rqs Size (K) Rqs Rqs 
   1  4326    35165  63.4     ...
        
         
           by 
           
                
                    
                        katalinali
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-15-2011
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi  
  I'm not sure if this is just me but, I'm running Splunk on Windows 7 Professional, 6 gig Ram, Intel i5 2.30 Gh...
        
         
           by 
           
                
                    
                        luke_mitchell
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-11-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Today we revceived a request from a Customer asking us for useful use-cases and searches they could use to put togeth...
        
         
           by 
           
                
                    
                        Mick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               11-11-2010
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Let's say I have logs that look like: date,USER=Joe,ACTION=Open,RESULT=Success  
  If there are four different types ...
        
         
           by 
           
                
                    
                        mundus
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-12-2011
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I am at a client where they are setting up a system based on a CSV lookup file. This file is managed by another syste...
        
         
           by 
           
                
                    
                        Jason
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               08-11-2011
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        This is a follow up to a previous question I had regarding FreeBSD and zfs. I understand that currently splunk does n...
        
         
           by 
           
                
                    
                        spoon
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               02-04-2011
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        Dear all, 
  If now I extract top 10 src-ip and use this src-ip to do further outer search, but I still wanna keep th...
        
         
           by 
           
                
                    
                        hjwang
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-12-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I've set up two linux machines as forwarders, and suddenly I have a very large number of entries in the hosts field w...
        
         
           by 
           
                
                    
                        mikeely
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-12-2011
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        how to calculate response time from syslog? which field to use?  
  Jun 4 04:02:18 vmlbsmt logger: 10.10.10.10 [04/Ju...
        
         
           by 
           
                
                    
                        xiaoyuew
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-11-2011
             
           
         
        | 
		
		0
   | 
	  
	  7
	 | |||
| 
        The following query  
  index=test | top Hostname 
  produces a chart that has percentages included in the chart alon...
        
         
           by 
           
                
                    
                        DTERM
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-12-2011
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        How could I add and additional (in my case total) field after the timechart is grouped by a field (e.g. httpcode) 
  ...
        
         
           by 
           
                
                    
                        Thomas
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-11-2011
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Scenerio 
  We are receiving over 700 sources forwarded from a Syslog-ng[remote source] service and they are being co...
        
         
           by 
           
                
                    
                        jason_hubbard
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-08-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        If I run "search latest=1/5/2011:0:0:0 | head limit=1" the results are returned immediately. But if I run "search ear...
        
         
           by 
           
                
                    
                        justinjohn83
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               02-17-2011
             
           
         
        | 
		
		2
   | 
	  
	  2
	 |