Splunk Search

Splunk Search
Community Activity
tylr
Does splunk> do any internal caching of recent searches? More to the point... Can I be 100% certain that my searc...
by tylr Engager in Splunk Search 03-05-2011
2 2
2
2
I-Man
I think i may have stumbled upon an error in Splunk. The following search will filter out any 10.x.x.x and 172 priva...
by I-Man Communicator in Splunk Search 03-04-2011
0 2
0
2
hacktastic
I'm trying to deal with a report that contain an asterisk to denote a "true/false" condition. My goal is to use trans...
by hacktastic Path Finder in Splunk Search 03-04-2011
1 6
1
6
jlechem
Hello, I am trying to bring back a set number of fields in a query even if that field isn't in the indexed data. Fo...
by jlechem New Member in Splunk Search 03-04-2011
0 3
0
3
twinspop
I have server farms made up of 4 servers each. I have various stats from each posted once per minute. I want to group...
by twinspop Influencer in Splunk Search 03-04-2011
0 1
0
1
Mick
My log directories are structured like so - /var/myapplogs/<app-name>/logs/*.log How can I extract <app-name> as ...
by Mick Splunk Employee Splunk Employee in Splunk Search 03-03-2011
1 3
1
3
ericrobinson
I have a search that is returning the value of a field called num_oracle_batch. I am using the following to get a per...
by ericrobinson Path Finder in Splunk Search 03-03-2011
1 3
1
3
mattreidy
I'm interested to know the average hits per minute by distinct source IP address from my web log data for a given tim...
by mattreidy Engager in Splunk Search 03-03-2011
1 6
1
6
sideview
I have lots of little searches and postProcess searches all over the place, where the request only needs a single sor...
by SplunkTrust SplunkTrust in Splunk Search 03-03-2011
3 1
3
1
skippylou
Trying to get a search working where instead of the whole result set passing to the next command as one, they would p...
by skippylou Communicator in Splunk Search 03-03-2011
2 2
2
2
lwalhoefer
Hi, does Splunk has a possibility to run server side scripts (python, ruby) based on a splunk search result? The sea...
by lwalhoefer Engager in Splunk Search 03-03-2011
1 2
1
2
chandansingh
Hi everyone , i would like to add a field in splunk.but field value does not come in result. here my source are:- 1....
by chandansingh Explorer in Splunk Search 03-03-2011
0 1
0
1
Ant1D
Hey, There is a field named OTHER which tends to appear at times in my search results. However, if I drilldown on th...
by Ant1D Motivator in Splunk Search 03-03-2011
2 5
2
5
lwalhoefer
Hi, I'm looking for a possibility to add a download link to a column within a result table ( e.g. ... | table field1)...
by lwalhoefer Engager in Splunk Search 03-02-2011
0 1
0
1
Thomas_Gresch
I have icinga debug logs from a server called monitoring01 looking like: [1284468200.195107] Checking service 'sys -...
by Thomas_Gresch Explorer in Splunk Search 03-02-2011
0 5
0
5
Kyle_Brandt
I am somewhat confused on how to set up my searches to populate my summary index. For example, two of the reports wil...
by Kyle_Brandt Path Finder in Splunk Search 03-02-2011
0 1
0
1
lwalhoefer
Hi, I've the following _raw event base: line1 field1=field1Value field2=field2Value sometext: a_stringline2 field1=...
by lwalhoefer Engager in Splunk Search 03-01-2011
0 1
0
1
jbsplunk
I was asked to look into building a report on how much an item moves vs. a baseline. I was trying to compare CPU Uti...
by jbsplunk Splunk Employee Splunk Employee in Splunk Search 03-01-2011
12 3
12
3
Kyle_Brandt
I am moving my web log reporting to Splunk. Even when I don't log static content I have about 1.5 Million events per ...
by Kyle_Brandt Path Finder in Splunk Search 03-01-2011
0 1
0
1
craigmunro
Hi, I was hoping to use a lookup table to add some fields but it doesn't seem to do quite what I was hoping. I have ...
by craigmunro Path Finder in Splunk Search 03-01-2011
3 3
3
3
justinjohn83
I'm looking for ideas on how to possibly optimize this query. Right now I see two options A) Get faster hardware B) ...
by justinjohn83 Explorer in Splunk Search 03-01-2011
0 8
0
8
dan_growler
Let's say I have a field called "host" and it can take the following values: host1, host2, host3. I'm having trouble...
by dan_growler Engager in Splunk Search 03-01-2011
0 1
0
1
pdevlin
This was partly answered by this related question. http://answers.splunk.com/questions/510/error-savedsplunker-no-r...
by pdevlin Explorer in Splunk Search 02-28-2011
0 1
0
1
bwenge
I have configured ossec server and splunk on the same box.Ossec agents are also configured.I have tried to login as r...
by bwenge Explorer in Splunk Search 02-28-2011
0 2
0
2
leo_wang
I recently followed this document to customize the event display for my own eventtype : http://www.splunk.com/base/Do...
by leo_wang Path Finder in Splunk Search 02-28-2011
1 4
1
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...