Splunk Search

Splunk Search
Community Activity
matze4matze
Hi everyone, I got three Dashboards to list my different sourcetypes. ALL, test, production ALL: | metadata type=s...
by matze4matze Engager in Splunk Search 08-22-2011
0 1
0
1
wtanaka
How can I calculate a graph where: For each point plotted on the graph, the y-axis is a count of the number of disti...
by wtanaka Explorer in Splunk Search 08-19-2011
0 2
0
2
wtanaka
I have a log where each event can be given a boolean field with: | eval myfield=case(n > 0, "A", n=0, "B") So some ...
by wtanaka Explorer in Splunk Search 08-19-2011
2 2
2
2
mikeely
We've got an XML file that is being parsed correctly (and easily - just piped into xmlkv) but one of the fields is nu...
by mikeely Path Finder in Splunk Search 08-19-2011
0 2
0
2
timbCFCA
How can I format the output from a Splunk query? For example I have three fields extracted, A, B, C. I'd like to out...
by timbCFCA Path Finder in Splunk Search 08-19-2011
0 3
0
3
samiomer
Hello, I was wondering if it's possible to schedule a search to run in increments less than 1 minute? Thanks
by samiomer Path Finder in Splunk Search 08-18-2011
2 3
2
3
jcrensh
All, I have a search that is looking for two specific events. One is for new 2008 OS's and up, the other is 2003 OS...
by jcrensh Explorer in Splunk Search 08-18-2011
0 1
0
1
mw
I have a field like this: ... group="Group One,Group2,Some Other Group" ... Using 'makemv delim="," group' is eas...
by mw Splunk Employee Splunk Employee in Splunk Search 08-18-2011
0 4
0
4
Marinus
If I use the metadata command it only gives me keys for the main index, can I call it for other indexes? For example ...
by Marinus Communicator in Splunk Search 08-18-2011
0 2
0
2
DTERM
I have the following two queries: index=MyApp earliest=-30d@d-2h latest=-1d@d+10h | bucket _time span=24h | stats su...
by DTERM Contributor in Splunk Search 08-17-2011
1 6
1
6
jcott28
I'm new to all of this and can mainly do nothing but some simple searches. But if I wanted to create a graph showing...
by jcott28 Explorer in Splunk Search 08-17-2011
0 4
0
4
msarro
Hey everyone. I'm having a dumb moment, so please be gentle. I have a number of records, and each one has an ID to id...
by msarro Builder in Splunk Search 08-17-2011
1 2
1
2
agthurber
We have set up many alerts to trigger based on a count threshold for a specific event over a set period of time. Give...
by agthurber Explorer in Splunk Search 08-17-2011
1 2
1
2
sdsajjadi
I installed splunk 4.2.3 and I want to monitor statistics of BIND 9.7.2 (DNS) queries through it. I used SPLUNK FOR B...
by sdsajjadi New Member in Splunk Search 08-16-2011
0 3
0
3
DTERM
How do I develop a query that groups events by product names? I don't know what the product names are. But I need a...
by DTERM Contributor in Splunk Search 08-16-2011
0 4
0
4
katalinali
Hi all, I have some statistical log like: Unit Type (M) Used Rqs Size (K) Rqs Rqs 1 4326 3...
by katalinali Path Finder in Splunk Search 08-16-2011
0 3
0
3
luke_mitchell
Hi I'm not sure if this is just me but, I'm running Splunk on Windows 7 Professional, 6 gig Ram, Intel i5 2.30 Ghz,...
by luke_mitchell New Member in Splunk Search 08-15-2011
0 1
0
1
Mick
Today we revceived a request from a Customer asking us for useful use-cases and searches they could use to put togeth...
by Mick Splunk Employee Splunk Employee in Splunk Search 08-15-2011
0 3
0
3
mundus
Let's say I have logs that look like: date,USER=Joe,ACTION=Open,RESULT=Success If there are four different types ...
by mundus Path Finder in Splunk Search 08-13-2011
0 2
0
2
Jason
I am at a client where they are setting up a system based on a CSV lookup file. This file is managed by another syste...
by Jason Motivator in Splunk Search 08-13-2011
1 1
1
1
spoon
This is a follow up to a previous question I had regarding FreeBSD and zfs. I understand that currently splunk does n...
by spoon Engager in Splunk Search 08-13-2011
1 2
1
2
hjwang
Dear all, If now I extract top 10 src-ip and use this src-ip to do further outer search, but I still wanna keep the ...
by hjwang Contributor in Splunk Search 08-13-2011
0 1
0
1
mikeely
I've set up two linux machines as forwarders, and suddenly I have a very large number of entries in the hosts field w...
by mikeely Path Finder in Splunk Search 08-12-2011
1 1
1
1
xiaoyuew
how to calculate response time from syslog? which field to use? Jun 4 04:02:18 vmlbsmt logger: 10.10.10.10 [04/Jun...
by xiaoyuew Path Finder in Splunk Search 08-12-2011
0 7
0
7
DTERM
The following query index=test | top Hostname produces a chart that has percentages included in the chart along wi...
by DTERM Contributor in Splunk Search 08-12-2011
0 2
0
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors