| Thread Info | |||||
|---|---|---|---|---|---|
| 
        I reinstalled splunk to a different volume and now I get this message when trying to search for any string. How can I...
        
         
           by 
           
                
                    
                        timstiles
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               03-08-2011
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        This problem generally occurs when you want to create a dashboard that contains a timerange picker and want to popula...
        
         
           by 
           
                
                    
                        steveyz
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-07-2011
             
           
         
        | 
		
		2
   | 
	  
	  2
	 | |||
| 
        I am trying to get a case to work with the eval statement inside of a macro and have been unsuccessfull. 
  I can get...
        
         
           by 
           
                
                    
                        fk319
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               11-12-2010
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I am trying to extract the username into a field that I can use and have so far been unsuccessful. I am doing this ba...
        
         
           by 
           
                
                    
                        gceraso
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               03-07-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I am using :join" query to show one table with different columns from different sourcetypes. However some of the sour...
        
         
           by 
           
                
                    
                        Anvita
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               03-03-2011
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        I need to reduce our licensing usage by filtering common, valid, no-news-is-good-news domains out of our Barracuda We...
        
         
           by 
           
                
                    
                        mileserickson
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               10-15-2010
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        Hi, 
  I am not Able to see sourcetype="websphere:MBean:stats" on splunk websphere dashboard. 
  Since this source is...
        
         
           by 
           
                
                    
                        lalitgoyal87
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               03-01-2011
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi all, I'm having a few issues with using a subsearch within an eval statement.  
  index="capacityanalysisindex01" ...
        
         
           by 
           
                
                    
                        jarrodrobins
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               03-07-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Here's the situation: 
  I have one set of web log events that represent people using my app which I generally displa...
        
         
           by 
           
                
                    
                        markgo
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               03-05-2011
             
           
         
        | 
		
		4
   | 
	  
	  3
	 | |||
| 
        Should be simple to solve, but i'm drawing a blank. 
  i have three fields i wnat to look at in dhcp logs mac hostnam...
        
         
           by 
           
                
                    
                        EricPartington
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-03-2011
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        Does splunk> do any internal caching of recent searches?  
  More to the point... 
  Can I be 100% certain that my se...
        
         
           by 
           
                
                    
                        tylr
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               03-04-2011
             
           
         
        | 
		
		2
   | 
	  
	  2
	 | |||
| 
        I think i may have stumbled upon an error in Splunk. 
  The following search will filter out any 10.x.x.x and 172 pri...
        
         
           by 
           
                
                    
                        I-Man
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-04-2011
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I'm trying to deal with a report that contain an asterisk to denote a "true/false" condition. My goal is to use trans...
        
         
           by 
           
                
                    
                        hacktastic
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-11-2010
             
           
         
        | 
		
		1
   | 
	  
	  6
	 | |||
| 
        Hello, 
  I am trying to bring back a set number of fields in a query even if that field isn't in the indexed data. F...
        
         
           by 
           
                
                    
                        jlechem
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               03-02-2011
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I have server farms made up of 4 servers each. I have various stats from each posted once per minute. I want to group...
        
         
           by 
           
                
                    
                        twinspop
                    
                
           
             
             
               Influencer
             
           
           in
           Splunk Search
           
           
              
               03-03-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        My log directories are structured like so -  
  /var/myapplogs/<app-name>/logs/*.log
 
  How can I extract <app-name>...
        
         
           by 
           
                
                    
                        Mick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               04-13-2010
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        I have a search that is returning the value of a field called num_oracle_batch. I am using the following to get a per...
        
         
           by 
           
                
                    
                        ericrobinson
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-02-2011
             
           
         
        | 
		
		1
   | 
	  
	  3
	 | |||
| 
        I'm interested to know the average hits per minute by distinct source IP address from my web log data for a given tim...
        
         
           by 
           
                
                    
                        mattreidy
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               02-28-2011
             
           
         
        | 
		
		1
   | 
	  
	  6
	 | |||
| 
        I have lots of little searches and postProcess searches all over the place, where the request only needs a single sor...
        
         
           by 
           
                
                    
                        sideview
                    
                
           
             
             
               SplunkTrust
             
           
           in
           Splunk Search
           
           
              
               03-03-2011
             
           
         
        | 
		
		3
   | 
	  
	  1
	 | |||
| 
        Trying to get a search working where instead of the whole result set passing to the next command as one, they would p...
        
         
           by 
           
                
                    
                        skippylou
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               03-02-2011
             
           
         
        | 
		
		2
   | 
	  
	  2
	 | |||
| 
        Hi, 
  does Splunk has a possibility to run server side scripts (python, ruby) based on a splunk search result? The s...
        
         
           by 
           
                
                    
                        lwalhoefer
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               03-03-2011
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        Hi everyone , i would like to add a field in splunk.but field value does not come in result. 
  here my source are:- ...
        
         
           by 
           
                
                    
                        chandansingh
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               03-03-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hey, 
  There is a field named OTHER which tends to appear at times in my search results. However, if I drilldown on ...
        
         
           by 
           
                
                    
                        Ant1D
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               02-25-2011
             
           
         
        | 
		
		2
   | 
	  
	  5
	 | |||
| 
        Hi, I'm looking for a possibility to add a download link to a column within a result table ( e.g. ... | table field1)...
        
         
           by 
           
                
                    
                        lwalhoefer
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               02-28-2011
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        I have icinga debug logs from a server called monitoring01 looking like: 
  [1284468200.195107] Checking service 'sys...
        
         
           by 
           
                
                    
                        Thomas_Gresch
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               09-14-2010
             
           
         
        | 
		
		0
   | 
	  
	  5
	 |