Thread Info | |||||
---|---|---|---|---|---|
I need to add something to the following search string (or rewrite it) that captures the following;
UserDestinatio...
by
sdagostino
Engager
in
Splunk Search
05-27-2010
|
3
|
6
| |||
I have Windows Security events that tell me when a user logged on and I have an ActiveDirectory event that tells me t...
by
maverick
Splunk Employee
in
Splunk Search
05-19-2010
|
1
|
8
| |||
Good morning Splunkers,
I'm working on the search detailed below.
By using two subsearches I'm trying to ident...
by
nik_splunk
Path Finder
in
Splunk Search
06-04-2010
|
0
|
3
| |||
I'm trying to build transaction that has an optional leading starting event. The events I'm using don't have any help...
by
Lowell
Super Champion
in
Splunk Search
04-22-2010
|
1
|
9
| |||
When I click on extract fields from the drop down box on a search result I keep getting this error messsage
...
by
snortymcsnort
New Member
in
Splunk Search
06-03-2010
|
0
|
6
| |||
hello
I have a search problem
I would like to set a time interval
Interval last Monday to last Sunday
if ...
by
shirolu
Explorer
in
Splunk Search
05-31-2010
|
0
|
3
| |||
The first search (1) will return host values and time values. Need to have those values used in another search (2)
...
by
Jaci
Splunk Employee
in
Splunk Search
06-02-2010
|
0
|
3
| |||
I looked at the documentation here: http://www.splunk.com/base/Documentation/4.1.1/SearchReference/CLIsearchsyntax
...
by
seanlon11
Path Finder
in
Splunk Search
06-04-2010
|
0
|
3
| |||
sourcetype=package_formatted [search sourcetype=package_formatted | stats dc(version) as version_test by name | searc...
by
oreoshake
Communicator
in
Splunk Search
06-03-2010
|
0
|
1
| |||
Hi,
There are login messages and logout messages in the log files. I want to get those users who have not been log...
by
dianbo_1
Path Finder
in
Splunk Search
06-02-2010
|
1
|
4
| |||
Hi
We have a scheduled-search that does summary indexing. For some reason, it doesn't capture all of the data tha...
by
sranga
Path Finder
in
Splunk Search
06-02-2010
|
0
|
6
| |||
So i have some custom app logs that contain an ip address in the filename. I am attempting to extract them. any ideas...
by
hiddenkirby
Contributor
in
Splunk Search
04-30-2010
|
1
|
11
| |||
On my LightWeightForwader (LWF), if I set the bandwidth thruput limit in limits.conf too low and the queue fills up o...
by
maverick
Splunk Employee
in
Splunk Search
06-04-2010
|
1
|
1
| |||
Hi
We have a summary indexed search that puts events into buckets for a day. We then use that to get the top 5 va...
by
sranga
Path Finder
in
Splunk Search
06-03-2010
|
0
|
8
| |||
I actually need a right join in some cases.
I know im not supposed to use joins at all, and wherever possible use...
by
sideview
SplunkTrust
in
Splunk Search
06-04-2010
|
0
|
4
| |||
I am attempting to use the real time view over time. It stops displaying events that are happening and hangs...the ti...
by
Jaci
Splunk Employee
in
Splunk Search
06-03-2010
|
1
|
1
| |||
I'd like to remove all data that matches a given search from my Splunk 3.4.14 for Windows install. I've found Windows...
by
straffin
Explorer
in
Splunk Search
06-02-2010
|
0
|
3
| |||
I need to add something to the following string (or rewrite it) that captures users sum by url by date. Any help woul...
by
Jaci
Splunk Employee
in
Splunk Search
06-03-2010
|
1
|
1
| |||
Hi
I am trying to do the following.
I have to prepare a report which contains the TransactionId, servername, s...
by
jeni
New Member
in
Splunk Search
06-02-2010
|
0
|
7
| |||
In Splunk, what is an intention? The Splexicon somewhat describes it .. but not really:
http://www.splunk.com/base...
by
the_wolverine
Champion
in
Splunk Search
05-24-2010
|
4
|
3
| |||
The fields command in 4.1.2, build 79191 has a bug.
It includes all results from the _* fields even when specified...
by
rayfoo
Path Finder
in
Splunk Search
05-30-2010
|
0
|
3
| |||
Is there a way to apply a SED like filter after a search. The plumbing is there to filter and sanitize data going int...
by
Marinus
Communicator
in
Splunk Search
06-02-2010
|
1
|
2
| |||
For some reason this search maxes out at 10000 (i.e. only returns 10000 sources, there are more...), and I can't seem...
by
parallaxed
Path Finder
in
Splunk Search
06-02-2010
|
1
|
3
| |||
Hi experts,
I would like to know if it is possible to exclude the result of 'addcoltotals' from the y axis scale. ...
by
sflisher
Explorer
in
Splunk Search
06-02-2010
|
1
|
1
| |||
I have some log like following:
13:47:04 -2 receive request [type=0|desc=TimeStamp] <---event one | [8 ] [BCA3.5] ...
by
mzorzi
Splunk Employee
in
Splunk Search
06-02-2010
|
2
|
1
|