Splunk Search

Splunk Search
Community Activity
drewbfl
Hi, I have created a saved search that removes all text but the value I want to chart, ie. host="machine" "uniquesear...
by drewbfl Path Finder in Splunk Search 02-23-2011
0 6
0
6
yazapage
I need to set the owner and permissions on saved searches after upgrading to 4.1.5 - where can I set these?
by yazapage Explorer in Splunk Search 02-23-2011
1 1
1
1
sideview
In some conditions the head command knows that the search has completed all the information that the user asked for, ...
by SplunkTrust SplunkTrust in Splunk Search 02-23-2011
1 1
1
1
rturk
Greetings fellow Splunkers, I'm having some issues with extracting the correct host name from log file names on inde...
by rturk Builder in Splunk Search 02-23-2011
0 3
0
3
Jason
I'm setting the timezone for hundreds of forwarders at once by using props.conf wildcards on host: [host::DN*] # Den...
by Jason Motivator in Splunk Search 02-22-2011
1 3
1
3
kholleran
Hello, I set up Active Directory monitoring with Splunk a couple weeks ago. I am running a search that searches for...
by kholleran Communicator in Splunk Search 02-22-2011
0 3
0
3
dikaye
Hi All, Here are some log entries from cisco ironport email security appliance: Feb 21 10:16:55 212.167.24.57 Feb 2...
by dikaye Path Finder in Splunk Search 02-22-2011
0 4
0
4
mikel8
Hopefully this is just a stupid regex error: I'm using SplunkLightForwarder on AIX to send a few .sh_history logs to...
by mikel8 Explorer in Splunk Search 02-22-2011
3 10
3
10
the_wolverine
I have a ton of useragent type fields, like MacOutlook/some_version_x_os_version_etc and Entourage/other_version_x_os...
by the_wolverine Champion in Splunk Search 02-18-2011
1 2
1
2
thepocketwade
Is it possible to start a new search in a new window or tab just by clicking on part of an entry in my current result...
by thepocketwade Path Finder in Splunk Search 02-18-2011
1 4
1
4
StefanB
Hey, I try to figure out if it is possible to have splunk to build a result for my special needings: I have 2 diffe...
by StefanB Explorer in Splunk Search 02-18-2011
0 4
0
4
vlapeintuit
I am creating several event types and have found when adding searches longer than 98 char it trims the rest off. Is t...
by vlapeintuit Explorer in Splunk Search 02-18-2011
0 1
0
1
dang
I'm hoping this doesn't stretch the bounds of "no question is too 'newbie'" part of the FAQ: I'm attempting to perfo...
by dang Path Finder in Splunk Search 02-17-2011
1 2
1
2
aahadqj
Hi, I would like to build a query to compare the var1 and var2 and then determinecount. Example lets say var1 = "a...
by aahadqj Explorer in Splunk Search 02-17-2011
0 1
0
1
Jason
I am trying to extract data from the Host field at search time, using a REPORT- in props.conf. The extraction works ...
by Jason Motivator in Splunk Search 02-17-2011
0 1
0
1
Steve_Litras
So I want to do a general field extraction of IP addresses for a sourcetype that may have them in multiple places in ...
by Steve_Litras Path Finder in Splunk Search 02-17-2011
2 2
2
2
beaumaris
We have situations where we just want to show what happened "today", which is defined as from Midnight to now. That'...
by beaumaris Communicator in Splunk Search 02-17-2011
1 1
1
1
splunker30039
I would like to create a dashboard that consists of 2 main parts: 1 - open search bar allowing any search 2 - result...
by splunker30039 Path Finder in Splunk Search 02-17-2011
1 3
1
3
ashishv
so i have a log which has column/field which will be populated with "Y" if there is an ERROR, feild name is ERROR_FLA...
by ashishv Explorer in Splunk Search 02-17-2011
2 6
2
6
gpburgett
I got a challenging request from a customer regarding their access logs. They want to monitor access patterns across ...
by gpburgett Splunk Employee Splunk Employee in Splunk Search 02-17-2011
1 7
1
7
briang67
Hello, I have a case opened for this - but it seems that this forum can be quicker at times... I run between 100-20...
by briang67 Communicator in Splunk Search 02-17-2011
1 4
1
4
mw
I'm trying to wrap my head around some of the more advanced/esoteric search commands. It seems like there's a lot of...
by mw Splunk Employee Splunk Employee in Splunk Search 02-17-2011
3 3
3
3
jrodman
Suppose I have a search such as sourcetype=apache errors which finds errors that I care about. Now, suppose I wa...
by jrodman Splunk Employee Splunk Employee in Splunk Search 02-16-2011
2 1
2
1
mtanadsk
Hi, For some reason, in a query that contains a transaction of some Juniper SSL VPN logs, my duration doesn't seem t...
by mtanadsk Explorer in Splunk Search 02-16-2011
1 1
1
1
jambajuice
We have events that look like this: edit 4 set srcintf "port1" set dstintf "port2" set srcaddr "0....
by jambajuice Communicator in Splunk Search 02-16-2011
1 5
1
5
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors