Splunk Search

Splunk Search
Community Activity
msarro
Hey everyone, simple question. Is it possible to append or use a subsearch to return a count? Here is how I'm current...
by msarro Builder in Splunk Search 05-03-2011
0 3
0
3
eFlea
I'm trying to generate a list of all IP addresses from all events where the user "timg" has a login failure. I have ...
by eFlea New Member in Splunk Search 05-02-2011
0 7
0
7
yumology
I'm having trouble conceptualizing how to have two or more lines that represent data on a single line chart. For ins...
by yumology Path Finder in Splunk Search 05-02-2011
2 3
2
3
Nixon1023
How can I have a start time on my search, so that it starts every time reflecting the current time. I want to displa...
by Nixon1023 New Member in Splunk Search 05-02-2011
0 1
0
1
rgeddes
basic set up: - splunk 4.2 on ubuntu 10.04 - rsyslog collects logs from other machines, and splunk reads and tabula...
by rgeddes Engager in Splunk Search 05-02-2011
0 1
0
1
tkadale
What is the use of ConvertToRedirect Module?? How to use this module?? Can we use this module to pass values across...
by tkadale Path Finder in Splunk Search 05-02-2011
1 1
1
1
natrixia
I'm aggregating some values via 'chart list(value) as jobs by something' and then later on I want to produce a table ...
by natrixia Explorer in Splunk Search 05-01-2011
0 3
0
3
Bero
Hi! I am a relative new user of Splunk so I have only used basic search that works fine. Background: I'm a member of...
by Bero New Member in Splunk Search 05-01-2011
0 3
0
3
joshd
Within the PCI CC App it seems that some of the info boxes do not update with the proper information but instead retu...
by joshd Builder in Splunk Search 05-01-2011
0 2
0
2
oscargarcia
Hi, I have a bunch of files that I need to push into Splunk that I am struggling to parse correctly. The format is t...
by oscargarcia Path Finder in Splunk Search 04-30-2011
1 6
1
6
the_wolverine
I want to add a form field to a dashboard that would allow a user to input some text. Somehow this text, perhaps usi...
by the_wolverine Champion in Splunk Search 04-29-2011
2 5
2
5
Sqig
Hi. We are not yet ready to upgrade to 4.2, where we can use the Search Head Pooling feature. Until we can, we stil...
by Sqig Path Finder in Splunk Search 04-29-2011
0 2
0
2
randok
I can get events from any other event log on the Exchange server but the "Exchange Auditing" log. Does anybody else h...
by randok New Member in Splunk Search 04-29-2011
0 9
0
9
frink
I've got some log data that has a multi-line event this format: 2011-04-28 11:40:00|ACTION|1304005199906869|stuff|st...
by frink Explorer in Splunk Search 04-29-2011
0 2
0
2
DotTest37
Im trying to solve a problem with my regex. Im extracting the username from an XML transaction. Sometimes the usernam...
by DotTest37 Path Finder in Splunk Search 04-28-2011
0 4
0
4
gharpe2
How do I conduct a search for unique usernames and get a count of how many people are logged on at any given time?
by gharpe2 Explorer in Splunk Search 04-28-2011
0 1
0
1
johnboldt
I'm adding a new field to an existing lookup table but it's not showing up in any searches. These are the steps I fol...
by johnboldt Explorer in Splunk Search 04-28-2011
0 1
0
1
msarro
Hey everyone. I am working on parsing through data from call data records. In every record there is a "local call ID"...
by msarro Builder in Splunk Search 04-28-2011
1 1
1
1
beaumaris
We have a report that shows bandwidth over time. The data is obtained from a summary index that counts the total num...
by beaumaris Communicator in Splunk Search 04-27-2011
0 3
0
3
tinhuty
one of my log file has this key-value: pageLoadTime=xxx, where xxx is number of milliseconds. how do I write the sea...
by tinhuty Engager in Splunk Search 04-27-2011
0 3
0
3
hiddenkirby
i need some search help... index=myindex | somefilter | stats count(field) by field gives me close to what i want....
by hiddenkirby Contributor in Splunk Search 04-27-2011
0 2
0
2
briang67
I'm trying to route syslog messages that contain the term "nc3ldaprealm" to an index other than main. I'm using the ...
by briang67 Communicator in Splunk Search 04-27-2011
0 1
0
1
Phil_T_
I have a scenario where A and B are indexers with one being the clone of the other. The idea being A is in one data c...
by Phil_T_ Engager in Splunk Search 04-27-2011
5 6
5
6
tkadale
I am showing a timechart by users. I want to show top 10 users on the graph having some particular condition. How to ...
by tkadale Path Finder in Splunk Search 04-27-2011
0 4
0
4
tkadale
I want to show a graph for min free disk space for the hosts. But I want to show only first 10 hosts on graph having ...
by tkadale Path Finder in Splunk Search 04-27-2011
0 3
0
3
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors