Splunk Search

Splunk Search
Community Activity
Masa
I have two search heads, four indexers, and several forwarders. When I go to Manager -> Indexes, my main index shows...
by Masa Splunk Employee Splunk Employee in Splunk Search 06-24-2011
2 1
2
1
HY
Anyone knows how to develop batch jobs to process and produce the required information for Field Lookup?
by HY Explorer in Splunk Search 06-24-2011
0 4
0
4
clintla
I've got 2 folders of config data- both have 21 files. Splunk is only adding 17 from one folder & 9 from the other....
by clintla Contributor in Splunk Search 06-23-2011
1 14
1
14
ruisantos
Hi, I'm getting an error on my Search Head when browsing for content related to some LOOKUP directives I have in my ...
by ruisantos Path Finder in Splunk Search 06-23-2011
0 2
0
2
jamesklassen
I have a search that sends me the top 10 errors on all of our servers each morning: error OR Error OR alert OR Alert...
by jamesklassen Path Finder in Splunk Search 06-23-2011
0 3
0
3
jstockamp
I've looked at the splunk documentation but can't make sense of it, maybe it's too early int he morning. I'm having ...
by jstockamp Communicator in Splunk Search 06-23-2011
1 4
1
4
DTERM
What is wrong with the following? index="app" | top productName NOT productName = "Not Specified" I want to extract...
by DTERM Contributor in Splunk Search 06-23-2011
0 1
0
1
BSoni
The servers sending data via syslog aren't resolving their host name....I edited my inputs.conf file in local dir as ...
by BSoni New Member in Splunk Search 06-23-2011
0 1
0
1
Glenn
I have a requirement to create a dashboard for a team's morning checks. It needs to search for logs between 18:00 the...
by Glenn Builder in Splunk Search 06-23-2011
1 5
1
5
dineshkumar
Hello, i created a bar chart for an event. That chart is Error vs Count, when i add that chart to dashboard, i am g...
by dineshkumar New Member in Splunk Search 06-23-2011
0 1
0
1
howyagoin
I've got an index with some 80 million events in it (thus far) and I want to search it for a list of some 100+ values...
by howyagoin Contributor in Splunk Search 06-23-2011
0 1
0
1
geetanjali
hi, I want to display sum of latest values in "SingleValue" module. what would be my query? i am using :- <module n...
by geetanjali Path Finder in Splunk Search 06-23-2011
0 1
0
1
johndunlea
I have a SINGLE event in the following format (this is only part of the log): /root/pegaruninit: Empty file /root/...
by johndunlea Explorer in Splunk Search 06-22-2011
0 2
0
2
tkrpata5588
I am trying to figure out something that I think should be fairly simple: given an index, what is the date/time range...
by tkrpata5588 New Member in Splunk Search 06-22-2011
0 3
0
3
Jared_Copeland
Hi I am new to splunk and hopefully this is a simple question to answer, i need to filter certain lines from the splu...
by Jared_Copeland New Member in Splunk Search 06-22-2011
0 1
0
1
RNB
The last few days I have been coming into work and the Splunk server is out of disk space. The culprit is always a 2...
by RNB Path Finder in Splunk Search 06-22-2011
1 1
1
1
fi5033
I am trying to extract some values from the Host field. For example, variations of host name being: labAppdev03, labW...
by fi5033 Engager in Splunk Search 06-22-2011
0 1
0
1
nclarkau
I cannot get the automatic k/v field extraction to completely extract all fields from this event... 18 May 2010 16:0...
by nclarkau Path Finder in Splunk Search 06-22-2011
1 9
1
9
bhiley
I have telephony log data containing multiple record types each with their own set of numerically tagged data fields....
by bhiley Explorer in Splunk Search 06-21-2011
0 3
0
3
clintla
The below chart works great chart sum(free_contig) over source by RaidGroup_Type I'd like my sum (in megabytes) to ...
by clintla Contributor in Splunk Search 06-21-2011
0 3
0
3
ehoward
Will, the MAXMIND app is incorrectly identifying an IP address in Centreville, Va as being in Miami, Fl. What is the...
by ehoward Path Finder in Splunk Search 06-21-2011
0 1
0
1
HY
Can someone provide me the commands to search for "top 10 CPU" and "top 10 memory" in Linux?
by HY Explorer in Splunk Search 06-21-2011
0 4
0
4
rmavery
I'm trying to tweak a search to create an alert for it. I started with a pretty long search... 560 host="rhea" ...
by rmavery Explorer in Splunk Search 06-21-2011
1 3
1
3
rahiparikh
Hi, Previously I was searching and extracting field at search time by explicitly specifying rex command. Now, I want...
by rahiparikh Explorer in Splunk Search 06-20-2011
0 5
0
5
IgorB
Eaxmple: Sourcetype "test" contains only one event. The event's _raw is "The quick brown fox jumps over the lazy d...
by IgorB Path Finder in Splunk Search 06-20-2011
2 2
2
2
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...