| I have two search heads, four indexers, and several forwarders. When I go to Manager -> Indexes, my main index shows... by Masa Splunk Employee 2 1 | 2 | 1 | ||
| Anyone knows how to develop batch jobs to process and produce the required information for Field Lookup? by HY Explorer in Splunk Search 06-24-2011 0 4 | 0 | 4 | ||
| I've got 2 folders of config data- both have 21 files. Splunk is only adding 17 from one folder & 9 from the other.... by clintla Contributor in Splunk Search 06-23-2011 1 14 | 1 | 14 | ||
| Hi, I'm getting an error on my Search Head when browsing for content related to some LOOKUP directives I have in my ... by ruisantos Path Finder in Splunk Search 06-23-2011 0 2 | 0 | 2 | ||
| I have a search that sends me the top 10 errors on all of our servers each morning: error OR Error OR alert OR Alert... by jamesklassen Path Finder in Splunk Search 06-23-2011 0 3 | 0 | 3 | ||
| I've looked at the splunk documentation but can't make sense of it, maybe it's too early int he morning. I'm having ... by jstockamp Communicator in Splunk Search 06-23-2011 1 4 | 1 | 4 | ||
| What is wrong with the following? index="app" | top productName NOT productName = "Not Specified" I want to extract... by DTERM Contributor in Splunk Search 06-23-2011 0 1 | 0 | 1 | ||
| The servers sending data via syslog aren't resolving their host name....I edited my inputs.conf file in local dir as ... by BSoni New Member in Splunk Search 06-23-2011 0 1 | 0 | 1 | ||
| I have a requirement to create a dashboard for a team's morning checks. It needs to search for logs between 18:00 the... by Glenn Builder in Splunk Search 06-23-2011 1 5 | 1 | 5 | ||
| Hello, i created a bar chart for an event. That chart is Error vs Count, when i add that chart to dashboard, i am g... by dineshkumar New Member in Splunk Search 06-23-2011 0 1 | 0 | 1 | ||
| I've got an index with some 80 million events in it (thus far) and I want to search it for a list of some 100+ values... by howyagoin Contributor in Splunk Search 06-23-2011 0 1 | 0 | 1 | ||
| hi, I want to display sum of latest values in "SingleValue" module. what would be my query? i am using :- <module n... by geetanjali Path Finder in Splunk Search 06-23-2011 0 1 | 0 | 1 | ||
| I have a SINGLE event in the following format (this is only part of the log): /root/pegaruninit: Empty file /root/... by johndunlea Explorer in Splunk Search 06-22-2011 0 2 | 0 | 2 | ||
| I am trying to figure out something that I think should be fairly simple: given an index, what is the date/time range... by tkrpata5588 New Member in Splunk Search 06-22-2011 0 3 | 0 | 3 | ||
| Hi I am new to splunk and hopefully this is a simple question to answer, i need to filter certain lines from the splu... by Jared_Copeland New Member in Splunk Search 06-22-2011 0 1 | 0 | 1 | ||
| The last few days I have been coming into work and the Splunk server is out of disk space. The culprit is always a 2... by RNB Path Finder in Splunk Search 06-22-2011 1 1 | 1 | 1 | ||
| I am trying to extract some values from the Host field. For example, variations of host name being: labAppdev03, labW... by fi5033 Engager in Splunk Search 06-22-2011 0 1 | 0 | 1 | ||
| I cannot get the automatic k/v field extraction to completely extract all fields from this event... 18 May 2010 16:0... by nclarkau Path Finder in Splunk Search 06-22-2011 1 9 | 1 | 9 | ||
| I have telephony log data containing multiple record types each with their own set of numerically tagged data fields.... by bhiley Explorer in Splunk Search 06-21-2011 0 3 | 0 | 3 | ||
| The below chart works great chart sum(free_contig) over source by RaidGroup_Type I'd like my sum (in megabytes) to ... by clintla Contributor in Splunk Search 06-21-2011 0 3 | 0 | 3 | ||
| Will, the MAXMIND app is incorrectly identifying an IP address in Centreville, Va as being in Miami, Fl. What is the... by ehoward Path Finder in Splunk Search 06-21-2011 0 1 | 0 | 1 | ||
| Can someone provide me the commands to search for "top 10 CPU" and "top 10 memory" in Linux? by HY Explorer in Splunk Search 06-21-2011 0 4 | 0 | 4 | ||
| I'm trying to tweak a search to create an alert for it. I started with a pretty long search... 560 host="rhea" ... by rmavery Explorer in Splunk Search 06-21-2011 1 3 | 1 | 3 | ||
| Hi, Previously I was searching and extracting field at search time by explicitly specifying rex command. Now, I want... by rahiparikh Explorer in Splunk Search 06-20-2011 0 5 | 0 | 5 | ||
| Eaxmple: Sourcetype "test" contains only one event. The event's _raw is "The quick brown fox jumps over the lazy d... by IgorB Path Finder in Splunk Search 06-20-2011 2 2 | 2 | 2 |