Splunk Search

Splunk Search
Community Activity
hedima
Hi i'm working on a master thesis wich splunk ist one of the software. I don't have very much experiance with splunk...
by hedima New Member in Splunk Search 08-10-2011
0 3
0
3
oarandes
Hi, I am trying to extract some custom fields form a log file which is delimited by :: and i made the following set...
by oarandes New Member in Splunk Search 08-09-2011
0 5
0
5
sscandoit
Hi, I have to rename _time to "Download DateTime" in my view. I did the same using following in the search command: ...
by sscandoit Explorer in Splunk Search 08-09-2011
0 2
0
2
gpullis
I want to filter out Windows security events whose TaskCategory begins with "Kerberos". props.conf [source::WinEven...
by gpullis Communicator in Splunk Search 08-09-2011
0 4
0
4
OL
Hi all, I'd like to retrieve a field value from the previous event. I've used streamstats last(myfield), but this ta...
by OL Communicator in Splunk Search 08-08-2011
0 3
0
3
rkanalyst
I am facing the problem when i am adding "\" inside the searchTemplate query for conditional checks.The same query is...
by rkanalyst Explorer in Splunk Search 08-08-2011
0 4
0
4
RicoSuave
I'm having an issue where one of my slavese is complaining about a lookup table that i have setup on my master. I get...
by RicoSuave Builder in Splunk Search 08-05-2011
1 1
1
1
jcrensh
I have a saved search returns the number of failed logins to a domain over a 24 hour period. source="wineventlog:sec...
by jcrensh Explorer in Splunk Search 08-05-2011
0 2
0
2
chca
search * | eval userAgentType=if(searchmatch("cs_User_Agent_=*MSIE*"), "Internet Explorer", "Other") | search userAge...
by chca Path Finder in Splunk Search 08-05-2011
0 2
0
2
fraserhardy
Hi, Sorry if this has been asked before but I could do with a quick straightforward answer for this one. We have a...
by fraserhardy New Member in Splunk Search 08-05-2011
0 4
0
4
pero1234
How to clean Searches and reports cache? I just rename stanza from [Report TEST] to [Report All Users] in my savedse...
by pero1234 Path Finder in Splunk Search 08-05-2011
0 2
0
2
hjwang
Hi~there Does anyone know if real-time search on dashboard can display last accumulated results such as last -1h whe...
by hjwang Contributor in Splunk Search 08-05-2011
0 2
0
2
chca
Assuming my URL_Query field contains the following data: cdata=153&orgid=0012 orgid=3924&cdata=129 cdata=153&orgid=3...
by chca Path Finder in Splunk Search 08-04-2011
0 2
0
2
lanying
I'm collecting a disk space log. I want to extract fields. ==> Filesystem , Type , Size , Used , Avail , UsePct , Mou...
by lanying Explorer in Splunk Search 08-03-2011
0 1
0
1
rturk
Hi Splunkers, So I'm getting started with multikv extractions, and I've come across this issue. I'm attempting to g...
by rturk Builder in Splunk Search 08-03-2011
0 2
0
2
Lowell
We would like to be able to send splunk events from our integration platform, but the existing logging infrastructure...
by Lowell Super Champion in Splunk Search 08-03-2011
0 3
0
3
dianbo_1
I noticed the following item in 4.1.4' change logs Consistent redirect to login page when running searches in Splunk...
by dianbo_1 Path Finder in Splunk Search 08-03-2011
2 2
2
2
acdevlin
I'm trying to set up a pie chart displaying the average response time to a particular server. The pie chart should ha...
by acdevlin Communicator in Splunk Search 08-03-2011
1 2
1
2
EUSTobias
I have a server onto which I installed Spunk last night. Just prior to the installation I installed flash 10.3, but I...
by EUSTobias Engager in Splunk Search 08-03-2011
1 1
1
1
nishil
Hi. I have a query that returns a number count based on the occurence of 2 keywords: sourcetype=hwa_other source=/va...
by nishil New Member in Splunk Search 08-03-2011
0 1
0
1
sdevadas
I have a set of events which are of the type: Type=httpPreReply Guid=b6d4d009-4643-4ff2-8fad-e20868ce3a17 Datetime=07...
by sdevadas Path Finder in Splunk Search 08-02-2011
0 1
0
1
DTERM
index=MyApp earliest="@d-1" latest="@d+11h" | stats count That query provides an event count of all events that occ...
by DTERM Contributor in Splunk Search 08-02-2011
2 2
2
2
dwengi
Hi Everyone, I'm trying to craft a timechart that shows the top "hits per source" and then only display the top sour...
by dwengi Engager in Splunk Search 08-02-2011
0 2
0
2
mataharry
I want to change the source filename for my data to remove the timestamp. from mypath\to\my\folder\userentrypoint17_...
by mataharry Communicator in Splunk Search 08-02-2011
1 2
1
2
maxdessureault
I am using the following to extract two fields at search time, extract_domain and extract_ip source="dns2.log" | r...
by maxdessureault Engager in Splunk Search 08-02-2011
0 2
0
2
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...