Splunk Search

Splunk Search
Community Activity
cafissimo
Hello, please, I would like to know if it is possible to use multiple and different sourcetypes with the splunk "tran...
by cafissimo Communicator in Splunk Search 02-25-2011
0 3
0
3
chienly
Hi, Just wondering if anyone here knows if the GoogleMap apps can take in longitude and latitude data without any IP...
by chienly New Member in Splunk Search 02-25-2011
0 3
0
3
joberget
Does Search Head servers have anything more in common than which Indexer they are connected to? If I want two Search ...
by joberget Path Finder in Splunk Search 02-25-2011
0 2
0
2
swillgoss
Hi Guys, I have two systems running splunk, and for some as-yet unknown reason the exact same search on both systems...
by swillgoss Explorer in Splunk Search 02-25-2011
1 6
1
6
splunker30039
I would like to create a dashboard that consists of 2 main parts: 1 - open search bar allowing any search 2 - result...
by splunker30039 Path Finder in Splunk Search 02-24-2011
0 5
0
5
wisespot
Hi, all, I am a newbie in splunk. I have encounter a problem when play around with *NIX app in Splunk. I am going t...
by wisespot New Member in Splunk Search 02-24-2011
0 1
0
1
cramasta
Hello, I have a saved search set up that uses the append command. The subsearch of the append command give me the f...
by cramasta Builder in Splunk Search 02-24-2011
4 2
4
2
smcap
Im not sure what i am doing wrong... I read the documentation and googled and cannot seem to figure it out. Im usin...
by smcap New Member in Splunk Search 02-23-2011
0 3
0
3
mataharry
how to call a macro from the CLI ? I tried splunk search " * | mymacro | table *" and got Error in 'SearchParser': Mi...
by mataharry Communicator in Splunk Search 02-23-2011
1 1
1
1
drewbfl
Hi, I have created a saved search that removes all text but the value I want to chart, ie. host="machine" "uniquesear...
by drewbfl Path Finder in Splunk Search 02-23-2011
0 6
0
6
yazapage
I need to set the owner and permissions on saved searches after upgrading to 4.1.5 - where can I set these?
by yazapage Explorer in Splunk Search 02-23-2011
1 1
1
1
sideview
In some conditions the head command knows that the search has completed all the information that the user asked for, ...
by SplunkTrust SplunkTrust in Splunk Search 02-23-2011
1 1
1
1
rturk
Greetings fellow Splunkers, I'm having some issues with extracting the correct host name from log file names on inde...
by rturk Builder in Splunk Search 02-23-2011
0 3
0
3
Jason
I'm setting the timezone for hundreds of forwarders at once by using props.conf wildcards on host: [host::DN*] # Den...
by Jason Motivator in Splunk Search 02-22-2011
1 3
1
3
kholleran
Hello, I set up Active Directory monitoring with Splunk a couple weeks ago. I am running a search that searches for...
by kholleran Communicator in Splunk Search 02-22-2011
0 3
0
3
dikaye
Hi All, Here are some log entries from cisco ironport email security appliance: Feb 21 10:16:55 212.167.24.57 Feb 2...
by dikaye Path Finder in Splunk Search 02-22-2011
0 4
0
4
mikel8
Hopefully this is just a stupid regex error: I'm using SplunkLightForwarder on AIX to send a few .sh_history logs to...
by mikel8 Explorer in Splunk Search 02-22-2011
3 10
3
10
the_wolverine
I have a ton of useragent type fields, like MacOutlook/some_version_x_os_version_etc and Entourage/other_version_x_os...
by the_wolverine Champion in Splunk Search 02-18-2011
1 2
1
2
thepocketwade
Is it possible to start a new search in a new window or tab just by clicking on part of an entry in my current result...
by thepocketwade Path Finder in Splunk Search 02-18-2011
1 4
1
4
StefanB
Hey, I try to figure out if it is possible to have splunk to build a result for my special needings: I have 2 diffe...
by StefanB Explorer in Splunk Search 02-18-2011
0 4
0
4
vlapeintuit
I am creating several event types and have found when adding searches longer than 98 char it trims the rest off. Is t...
by vlapeintuit Explorer in Splunk Search 02-18-2011
0 1
0
1
dang
I'm hoping this doesn't stretch the bounds of "no question is too 'newbie'" part of the FAQ: I'm attempting to perfo...
by dang Path Finder in Splunk Search 02-17-2011
1 2
1
2
aahadqj
Hi, I would like to build a query to compare the var1 and var2 and then determinecount. Example lets say var1 = "a...
by aahadqj Explorer in Splunk Search 02-17-2011
0 1
0
1
Jason
I am trying to extract data from the Host field at search time, using a REPORT- in props.conf. The extraction works ...
by Jason Motivator in Splunk Search 02-17-2011
0 1
0
1
Steve_Litras
So I want to do a general field extraction of IP addresses for a sourcetype that may have them in multiple places in ...
by Steve_Litras Path Finder in Splunk Search 02-17-2011
2 2
2
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...