Splunk Search

Splunk Search
Community Activity
geetanjali
hi, I want to display sum of latest values in "SingleValue" module. what would be my query? i am using :- <module n...
by geetanjali Path Finder in Splunk Search 06-23-2011
0 1
0
1
johndunlea
I have a SINGLE event in the following format (this is only part of the log): /root/pegaruninit: Empty file /root/...
by johndunlea Explorer in Splunk Search 06-22-2011
0 2
0
2
tkrpata5588
I am trying to figure out something that I think should be fairly simple: given an index, what is the date/time range...
by tkrpata5588 New Member in Splunk Search 06-22-2011
0 3
0
3
Jared_Copeland
Hi I am new to splunk and hopefully this is a simple question to answer, i need to filter certain lines from the splu...
by Jared_Copeland New Member in Splunk Search 06-22-2011
0 1
0
1
RNB
The last few days I have been coming into work and the Splunk server is out of disk space. The culprit is always a 2...
by RNB Path Finder in Splunk Search 06-22-2011
1 1
1
1
fi5033
I am trying to extract some values from the Host field. For example, variations of host name being: labAppdev03, labW...
by fi5033 Engager in Splunk Search 06-22-2011
0 1
0
1
nclarkau
I cannot get the automatic k/v field extraction to completely extract all fields from this event... 18 May 2010 16:0...
by nclarkau Path Finder in Splunk Search 06-22-2011
1 9
1
9
bhiley
I have telephony log data containing multiple record types each with their own set of numerically tagged data fields....
by bhiley Explorer in Splunk Search 06-21-2011
0 3
0
3
clintla
The below chart works great chart sum(free_contig) over source by RaidGroup_Type I'd like my sum (in megabytes) to ...
by clintla Contributor in Splunk Search 06-21-2011
0 3
0
3
ehoward
Will, the MAXMIND app is incorrectly identifying an IP address in Centreville, Va as being in Miami, Fl. What is the...
by ehoward Path Finder in Splunk Search 06-21-2011
0 1
0
1
HY
Can someone provide me the commands to search for "top 10 CPU" and "top 10 memory" in Linux?
by HY Explorer in Splunk Search 06-21-2011
0 4
0
4
rmavery
I'm trying to tweak a search to create an alert for it. I started with a pretty long search... 560 host="rhea" ...
by rmavery Explorer in Splunk Search 06-21-2011
1 3
1
3
rahiparikh
Hi, Previously I was searching and extracting field at search time by explicitly specifying rex command. Now, I want...
by rahiparikh Explorer in Splunk Search 06-20-2011
0 5
0
5
IgorB
Eaxmple: Sourcetype "test" contains only one event. The event's _raw is "The quick brown fox jumps over the lazy d...
by IgorB Path Finder in Splunk Search 06-20-2011
2 2
2
2
EricPartington
How do I search for and return the max index size as defined by the indexes.conf file? I want to get the same value ...
by EricPartington Communicator in Splunk Search 06-18-2011
0 2
0
2
tincupchalice
Is there a way to take a value from one lookup or search and make it the field name for the other. Example: | eval i...
by tincupchalice Path Finder in Splunk Search 06-17-2011
1 2
1
2
HY
Can anyone provide for me apart from CPU and memory, what else can I search for under system process?
by HY Explorer in Splunk Search 06-17-2011
0 1
0
1
Mike_H
Hey folks: I'd like to do a little looping/grouping of search results but aren't familiar enough with Splunk command...
by Mike_H Engager in Splunk Search 06-17-2011
0 1
0
1
jeklof
Hi allknowing Splunkbase! I have events that have the value x_duration and start time - With this value we can calcu...
by jeklof Engager in Splunk Search 06-17-2011
0 3
0
3
HY
What are the configuration/setup I have to do in order to use Splunk in Redhat Enterprise Linux? What is the reason o...
by HY Explorer in Splunk Search 06-16-2011
0 3
0
3
HY
How can I show and update the real-time alert whenever I have created the dashboard previously?
by HY Explorer in Splunk Search 06-16-2011
0 4
0
4
pkincaid
I have a CSV file (test.csv) that contains malicious domains and want to use that to see via Squid logs if anyone has...
by pkincaid New Member in Splunk Search 06-16-2011
0 1
0
1
bhiley
How does a receiving Splunk know what's being sent - or do I have to refer to the forwarding Splunk to know about the...
by bhiley Explorer in Splunk Search 06-16-2011
1 1
1
1
ken_t_huang
Excuse me, I have a data like this: index=test, product=a, category="1";"3";"6",..... how do I set the multi fields...
by ken_t_huang Explorer in Splunk Search 06-16-2011
2 4
2
4
builder
I refered to the following documentation to try and get this working: http://www.splunk.com/base/Documentation/3.0.2...
by builder Path Finder in Splunk Search 06-16-2011
0 8
0
8
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...