Splunk Search

Splunk Search
Community Activity
rcolby
I am sending my sonic wall data to splunk via syslog. I am trying to get a report to show me how many open connectio...
by rcolby Engager in Splunk Search 07-22-2011
2 4
2
4
jeffa
I'm trying to identify the source of a performance slow down that has occurred twice over the last two days. Each sl...
by jeffa Path Finder in Splunk Search 07-22-2011
0 3
0
3
cejohnson
I have log data that tracks the completion of jobs. I'd like to be able to track the completed jobs, but for 4 differ...
by cejohnson Explorer in Splunk Search 07-22-2011
1 3
1
3
rgcox1
I'm trying to run a search for a large number (45) of suspect IP addresses. The search runs for 12 hours or more but ...
by rgcox1 Communicator in Splunk Search 07-21-2011
0 4
0
4
the_wolverine
I thought there was a way (command) that would users with the right permissions to read a file on the Splunk filesyst...
by the_wolverine Champion in Splunk Search 07-21-2011
0 2
0
2
sirishag
In my application the SystemOut logs from the Websphere logs are sent to Splunk Server. In these logs i have a log st...
by sirishag New Member in Splunk Search 07-21-2011
0 1
0
1
williamavila12
I have installed the app and faithfully followed the instructions provided but I still see no result when I try to la...
by williamavila12 Explorer in Splunk Search 07-21-2011
0 5
0
5
vaijpc
I've got some logs where a certain field ('randomletter') is normally X, but occasionally changes to Y (or even Z!) ...
by vaijpc Communicator in Splunk Search 07-21-2011
0 1
0
1
Drainy
I have created a regex; (\d+)(:)(\d+)(:)(\d+)(\.)(\d+) To act as my LINE_BREAKER in the props conf file for an app...
by Drainy Champion in Splunk Search 07-21-2011
1 1
1
1
b4ggio
I have a log file that contains multiple fields that are time oriented fields. The fields in this instance are the st...
by b4ggio Explorer in Splunk Search 07-21-2011
0 5
0
5
g_prez
Trying to do an inline regex on the snip of log below. The item that I am trying to extract is the hostname admin.te...
by g_prez Path Finder in Splunk Search 07-20-2011
0 3
0
3
jcbrendsel
We are running the new splunk universal forwarder on an application server. It has the standard setup to recursively...
by jcbrendsel Path Finder in Splunk Search 07-20-2011
0 1
0
1
wrangler2x
I am using this search: | metadata index=* type=hosts | eval age = now()-lastTime | where age > (2*86400) | sort age...
by wrangler2x Motivator in Splunk Search 07-20-2011
0 1
0
1
ikerfresh
Hi, I'm trying to do this search "sourcetype="MySQL" | multikv fields Variable_name Value | search Variable_name="In...
by ikerfresh New Member in Splunk Search 07-20-2011
0 1
0
1
damogallagher
Hi I am using a Pie chart and I want to be able to drill down into see the results, but when I try this, I get the f...
by damogallagher New Member in Splunk Search 07-20-2011
0 1
0
1
bhiley
I have data eg. as follows :- rectype=031 OMD_StrtTime_002="Wed Jul 20 02:59:59 2011" OMD_Endtime_003="Wed Jul 20 03...
by bhiley Explorer in Splunk Search 07-19-2011
0 2
0
2
TomCollick
I need to know how to write a search query with 2 searches where the second search takes the value of the field, IP a...
by TomCollick Explorer in Splunk Search 07-19-2011
1 2
1
2
TomCollick
How would I add field x to the results of count(y) as z so that the results are x z count(y)? I know it is ...
by TomCollick Explorer in Splunk Search 07-19-2011
0 3
0
3
bhiley
I want to report the number of events in a given index using a scheduled overnight report and send the PDF output to ...
by bhiley Explorer in Splunk Search 07-19-2011
0 1
0
1
remy06
After I've upgraded splunk from 4.1.5 to 4.2.1,some of the saved searches encountered errors now,while some are ok. ...
by remy06 Contributor in Splunk Search 07-18-2011
0 1
0
1
bazcurtis
Hi, I have installed the Cisco Security suite and Cisco Firewall apps. I have setup UDP port 514 and told the ASA to...
by bazcurtis Explorer in Splunk Search 07-18-2011
1 3
1
3
mfeeny1
Hello. I am fairly new, and I am studying hard to learn the nuances of Searching and building Dashboards. I thought...
by mfeeny1 Path Finder in Splunk Search 07-18-2011
0 1
0
1
jedinerd
I have followed the documentation to create an advanced view that should utilize post processing to generate multiple...
by jedinerd New Member in Splunk Search 07-16-2011
0 1
0
1
sideview
Say that you have a huge volume of events, and they come in big batches. Each batch is a discrete unit, and mixing i...
by SplunkTrust SplunkTrust in Splunk Search 07-15-2011
2 5
2
5
david_fresne
How to get elapsed time? I have the following |eval tnow = now() |convert ctime(tnow) as currtime | eval el_time =(c...
by david_fresne New Member in Splunk Search 07-15-2011
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...