Splunk Search

Splunk Search
Community Activity
quanta
Hi, I have only one the OSSEC server (manager) where I install Splunk. When I access OSSEC Agent Status from the Das...
by quanta New Member in Splunk Search 06-14-2011
0 2
0
2
drawnsle
Sorry complete newbie, having trouble getting my head around splitting this log into distinct event. The default proc...
by drawnsle Engager in Splunk Search 06-13-2011
1 2
1
2
Justin_Grant
We're building an app for WebSphere and trying to come up with a naming convention for field names. I'm nervous abo...
by Justin_Grant Contributor in Splunk Search 06-11-2011
2 4
2
4
ephemeric
Is it possible to set this up? Upon landing on the jobs page to have the 'Owner' as myself (currently logged in) wit...
by ephemeric Contributor in Splunk Search 06-11-2011
0 1
0
1
simuvid
What is wrong with following search: sourcetype="security" ip=[search sourcetype=access_combined status=401 clientip...
by simuvid Splunk Employee Splunk Employee in Splunk Search 06-10-2011
1 2
1
2
tkadale
I want to customize time intervals for the options in Time Range Picker. For Ex- If I select Last 7 days from drop do...
by tkadale Path Finder in Splunk Search 06-10-2011
1 6
1
6
hjwang
dear all i wanna show ratio in bar chart by special field, for example i use my search | stats count by DEST_IP | s...
by hjwang Contributor in Splunk Search 06-10-2011
0 4
0
4
tkadale
I have 5 Screens. For Screen 1,2 and 3 I want "Real Time" option in Time Range Picker. But for Screen 4 and 5, I do...
by tkadale Path Finder in Splunk Search 06-10-2011
1 1
1
1
the_wolverine
I'm sure this is really simple but I've been unable to figure out the syntax to combine these 2 regexes in my transfo...
by the_wolverine Champion in Splunk Search 06-09-2011
2 2
2
2
mxgaccount
Sorry... I'm completely new to this. I have used punct (search feature) to select the type of record from my home aut...
by mxgaccount New Member in Splunk Search 06-09-2011
0 2
0
2
chowell
On a Windows 2008 R2 server, I've been comparing the %Processor Time counter on the _Total instance from Perfmon with...
by chowell Explorer in Splunk Search 06-09-2011
0 3
0
3
pburkholder
When I do the following search sourcetype="access*" [ search method="POST" |fields clientip | rename clientip as que...
by pburkholder New Member in Splunk Search 06-09-2011
0 3
0
3
keiichilam
following best view with courier font  I need to create a report from QMAIL log.  There will be more then one threa...
by keiichilam Explorer in Splunk Search 06-09-2011
0 1
0
1
remy06
Hi, I'm using this command to search for hosts that have stopped sending data within the last 24 hours.Using this,an...
by remy06 Contributor in Splunk Search 06-08-2011
1 1
1
1
bhiley
It seems I need to use 'xmlkvrecursive' to properly parse XML log files where the tags may contain many attributes. H...
by bhiley Explorer in Splunk Search 06-08-2011
1 2
1
2
blee_i365
My log files: ============= 2011-06-05 05:11:23.234 Program Version 10.02.2345 2011-06-05 05:11:23.239 event 1 20...
by blee_i365 Explorer in Splunk Search 06-08-2011
1 4
1
4
Jason
Say you have a stream of events, such as web page accesses. There is no field for amount of time on a certain page, s...
by Jason Motivator in Splunk Search 06-08-2011
2 7
2
7
JYTTEJ
I have following search which calculates seconds UNavailablity: host=psdkxp* FMT=IOSTAT* APP=TMA PRJ=IPSMON RCD=0 |...
by JYTTEJ Communicator in Splunk Search 06-08-2011
3 2
3
2
tkadale
I have Screen 1 for which I have set default time range in viewstates.conf for a user as follows: [Screen_1:_current...
by tkadale Path Finder in Splunk Search 06-07-2011
0 2
0
2
geetanjali
Hello, I have following query. $HostSelectBoxValue$ is drop down field name. I have to run this query on page load ...
by geetanjali Path Finder in Splunk Search 06-07-2011
0 1
0
1
vmallipe
Hi There, I'm pretty new to the splunk. we have 3 physical splunk servers and all the forweders are forwarding to 1...
by vmallipe New Member in Splunk Search 06-07-2011
0 2
0
2
jambajuice
I would like to build a dashboard that contains form fields for the start time/date and end time/date of a series of ...
by jambajuice Communicator in Splunk Search 06-07-2011
1 4
1
4
timmy13
Consider log entries such as the following: 20110605.132223 CONNECT misc.data 10.10.10.2 ID=12345 20110605.132298 A...
by timmy13 Communicator in Splunk Search 06-07-2011
0 3
0
3
blurblebot
Yodas, I'm getting odd returns for a transaction in which the final search operator works one way for exact matches...
by blurblebot Communicator in Splunk Search 06-07-2011
1 2
1
2
klbiggs
When using the REST API through a Java application I only receive fields that I explicitly search for (e.g. "51094833...
by klbiggs Engager in Splunk Search 06-07-2011
1 1
1
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...