Thread Info | |||||
---|---|---|---|---|---|
I have an Apache Access log which I'm searching for any .cgi or .pl file hit with the latest date it's been hit.
S...
by
Brian_Osburn
Builder
in
Splunk Search
07-09-2010
|
2
|
2
| |||
I have a saved search that I modified in the Splunkweb Manager. I look at the same search in the savedsearch.conf fil...
by
muebel
SplunkTrust
in
Splunk Search
07-12-2010
|
1
|
5
| |||
I would like to create an alert if the number on events is different in two subsearches.
subsearch1 = "index=index...
by
imrago
Contributor
in
Splunk Search
07-12-2010
|
1
|
1
| |||
I have setup alerts based on a scheduled search in the logs. The application writes a log messages every minute while...
by
sureshchinta
Explorer
in
Splunk Search
07-09-2010
|
1
|
1
| |||
I could renamed the field of timechart. For example: Changed count to 'YYY' . But,I couldn't renamed the '_time' fiel...
by
benny8021
New Member
in
Splunk Search
07-10-2010
|
0
|
1
| |||
I'm seeing this in my splunkd.log:
07-09-2010 12:53:21.299 WARN DateParserVerbose - Time parsed (Fri Jul 9 12:53:1...
by
b1nki3
Explorer
in
Splunk Search
07-09-2010
|
0
|
2
| |||
I remember being able to include a standard text file, perhaps a .csv, in the 3.x branch. The search would then itera...
by
b1nki3
Explorer
in
Splunk Search
06-25-2010
|
1
|
3
| |||
Is there a kind of conditional search command that can be used to stop or prematurely terminate a search based on a g...
by
Lowell
Super Champion
in
Splunk Search
07-08-2010
|
2
|
2
| |||
We are required to produce monthly audits of access to files that are covered by SOX. There are 8 groups of folders t...
by
jambajuice
Communicator
in
Splunk Search
07-08-2010
|
0
|
1
| |||
Hi. How would I run a search command in command line. The problem is that I would also like to set an alert condition...
by
alextsui
Path Finder
in
Splunk Search
07-06-2010
|
3
|
3
| |||
I have the following content in the log file
====
ONLN|2010-07-06 13:53:52.000|test.tester.com|1068|db_server_n...
by
klkumar10
Explorer
in
Splunk Search
07-07-2010
|
0
|
5
| |||
I am indexing results from facter which logs information about each host. I can get the most up to date list of these...
by
muebel
SplunkTrust
in
Splunk Search
07-07-2010
|
0
|
4
| |||
Hello,
I am trying to compare two fields with a simple operator but it does not seem to perform as expected. I am ...
by
srw46
Path Finder
in
Splunk Search
07-06-2010
|
1
|
2
| |||
In a datasource that uses single quotes as the event delimiter, like so:
field1='value1' field2='value2' field3=''...
by
jwestberg
Splunk Employee
in
Splunk Search
07-03-2010
|
2
|
10
| |||
Hi,
We've created two transactions to correlate logs spanning several components. We needed to define alias terms...
by
treena
Explorer
in
Splunk Search
07-06-2010
|
5
|
6
| |||
I'm running into some really slow performance searching on WMI sources. In this case I'm just trying to get some gene...
by
Lowell
Super Champion
in
Splunk Search
07-02-2010
|
1
|
3
| |||
Does anyone have a good way (or am I missing the something obvious?) of calculating for a defined time range the aver...
by
Derek
Path Finder
in
Splunk Search
07-05-2010
|
0
|
2
| |||
Since it does not appear that you can pass a number into the random() function, I'm curious to know what is being use...
by
maverick
Splunk Employee
in
Splunk Search
07-02-2010
|
3
|
3
| |||
I have an event that is coming from a Windows forwarder. When you view the event in the log file on the server it loo...
by
Derek
Path Finder
in
Splunk Search
07-02-2010
|
0
|
2
| |||
Ok. Not having a spectacular regex day...
I have this:
Recipients: joe.smith@mig.mydomain.com, jane.smith@mig.m...
by
Derek
Path Finder
in
Splunk Search
07-02-2010
|
1
|
2
| |||
I have saved searches and all of a sudden with no changes they are returning this error to the python.log file.
ER...
by
jtwcarboy
New Member
in
Splunk Search
06-02-2010
|
0
|
7
| |||
I'm unable to list the transactions that have events matching with startWith clause but no events for endsWith clause...
by
Krishna_R
Path Finder
in
Splunk Search
06-10-2010
|
1
|
9
| |||
I've been breaking my head over this very simple field extraction.
My extraction (see eg., below) has problems be...
by
pjmenon
Explorer
in
Splunk Search
06-29-2010
|
0
|
21
| |||
Is the wildcard search star * supported by logs in splunk? Im trying to see if splunk is seeing changes being made in...
by
riderofyamaha
Explorer
in
Splunk Search
06-30-2010
|
0
|
3
| |||
Hi,
question about restoration of indexed data. I know how to restore(or search old) indexes data by putting neces...
by
melonman
Motivator
in
Splunk Search
06-08-2010
|
1
|
1
|