Splunk Search

Splunk Search
Community Activity
ikerfresh
Hi, I'm trying to do this search "sourcetype="MySQL" | multikv fields Variable_name Value | search Variable_name="In...
by ikerfresh New Member in Splunk Search 07-20-2011
0 1
0
1
damogallagher
Hi I am using a Pie chart and I want to be able to drill down into see the results, but when I try this, I get the f...
by damogallagher New Member in Splunk Search 07-20-2011
0 1
0
1
bhiley
I have data eg. as follows :- rectype=031 OMD_StrtTime_002="Wed Jul 20 02:59:59 2011" OMD_Endtime_003="Wed Jul 20 03...
by bhiley Explorer in Splunk Search 07-19-2011
0 2
0
2
TomCollick
I need to know how to write a search query with 2 searches where the second search takes the value of the field, IP a...
by TomCollick Explorer in Splunk Search 07-19-2011
1 2
1
2
TomCollick
How would I add field x to the results of count(y) as z so that the results are x z count(y)? I know it is ...
by TomCollick Explorer in Splunk Search 07-19-2011
0 3
0
3
bhiley
I want to report the number of events in a given index using a scheduled overnight report and send the PDF output to ...
by bhiley Explorer in Splunk Search 07-19-2011
0 1
0
1
remy06
After I've upgraded splunk from 4.1.5 to 4.2.1,some of the saved searches encountered errors now,while some are ok. ...
by remy06 Contributor in Splunk Search 07-18-2011
0 1
0
1
bazcurtis
Hi, I have installed the Cisco Security suite and Cisco Firewall apps. I have setup UDP port 514 and told the ASA to...
by bazcurtis Explorer in Splunk Search 07-18-2011
1 3
1
3
mfeeny1
Hello. I am fairly new, and I am studying hard to learn the nuances of Searching and building Dashboards. I thought...
by mfeeny1 Path Finder in Splunk Search 07-18-2011
0 1
0
1
jedinerd
I have followed the documentation to create an advanced view that should utilize post processing to generate multiple...
by jedinerd New Member in Splunk Search 07-16-2011
0 1
0
1
sideview
Say that you have a huge volume of events, and they come in big batches. Each batch is a discrete unit, and mixing i...
by SplunkTrust SplunkTrust in Splunk Search 07-15-2011
2 5
2
5
david_fresne
How to get elapsed time? I have the following |eval tnow = now() |convert ctime(tnow) as currtime | eval el_time =(c...
by david_fresne New Member in Splunk Search 07-15-2011
0 1
0
1
oliverquick
A question regarding the search in the CLI. I need to search the metadata via the CLI - it appears I can not ./splu...
by oliverquick New Member in Splunk Search 07-15-2011
0 3
0
3
tpsplunk
For a particular sourcetype I need to have two fields extracted at index time and also 10+ fields extracted at search...
by tpsplunk Communicator in Splunk Search 07-15-2011
1 9
1
9
lpolo
I have the following Splunk search query that is working fine: sourcetype="x" "ABC" NOT D| lookup rr_by_dd dd as dd ...
by lpolo Motivator in Splunk Search 07-15-2011
0 2
0
2
tawollen
I have a user that is scheduling a saved search and has results get sent to multiple users. When the users click on t...
by tawollen Path Finder in Splunk Search 07-15-2011
2 4
2
4
jknowles
I am trying to have my Imail Logs indexed correctly. Right now there is no order to the events. They should be separa...
by jknowles Engager in Splunk Search 07-14-2011
0 1
0
1
zservati1
I have the following search : index="efept" source=/var/log/efe/server.log host=efeprodapp13 FilingTypeId: AND Routi...
by zservati1 New Member in Splunk Search 07-14-2011
0 1
0
1
timmy13
I want a form that will allow a user to "build" the appropriate "source" (or log file name) based on selecting variou...
by timmy13 Communicator in Splunk Search 07-14-2011
1 2
1
2
rsimmons
Disabling search assistant under the search app
by rsimmons Splunk Employee Splunk Employee in Splunk Search 07-14-2011
0 1
0
1
markgo
I've had the misfortune of feeding 30K input files from Amazon S3 Cloudfront logs into my live Splunk instance, witho...
by markgo Engager in Splunk Search 07-13-2011
1 1
1
1
JoeTF2
I need to monitor for unscheduled downtime while avoiding scheduled downtime that happens at unequal hour boundary. ...
by JoeTF2 New Member in Splunk Search 07-13-2011
0 5
0
5
glennh
Hi folks, I'm trying to create an eventtype to match ERROR in my tomcat logs. The log messages for a single servic...
by glennh Engager in Splunk Search 07-13-2011
1 1
1
1
brandonf
Hi Is it possible to get search head pooling to work on *nix with a remote fs (shared storage) other than NFS - perh...
by brandonf Path Finder in Splunk Search 07-13-2011
0 1
0
1
ageld
I am breaking my head over this. Sometimes our users login to our web application using username: "myuser" or "myd...
by ageld Path Finder in Splunk Search 07-13-2011
1 4
1
4
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...