Splunk Search

Splunk Search
Community Activity
kholleran
Hello, I set up Active Directory monitoring with Splunk a couple weeks ago. I am running a search that searches for...
by kholleran Communicator in Splunk Search 02-22-2011
0 3
0
3
dikaye
Hi All, Here are some log entries from cisco ironport email security appliance: Feb 21 10:16:55 212.167.24.57 Feb 2...
by dikaye Path Finder in Splunk Search 02-22-2011
0 4
0
4
mikel8
Hopefully this is just a stupid regex error: I'm using SplunkLightForwarder on AIX to send a few .sh_history logs to...
by mikel8 Explorer in Splunk Search 02-22-2011
3 10
3
10
the_wolverine
I have a ton of useragent type fields, like MacOutlook/some_version_x_os_version_etc and Entourage/other_version_x_os...
by the_wolverine Champion in Splunk Search 02-18-2011
1 2
1
2
thepocketwade
Is it possible to start a new search in a new window or tab just by clicking on part of an entry in my current result...
by thepocketwade Path Finder in Splunk Search 02-18-2011
1 4
1
4
StefanB
Hey, I try to figure out if it is possible to have splunk to build a result for my special needings: I have 2 diffe...
by StefanB Explorer in Splunk Search 02-18-2011
0 4
0
4
vlapeintuit
I am creating several event types and have found when adding searches longer than 98 char it trims the rest off. Is t...
by vlapeintuit Explorer in Splunk Search 02-18-2011
0 1
0
1
dang
I'm hoping this doesn't stretch the bounds of "no question is too 'newbie'" part of the FAQ: I'm attempting to perfo...
by dang Path Finder in Splunk Search 02-17-2011
1 2
1
2
aahadqj
Hi, I would like to build a query to compare the var1 and var2 and then determinecount. Example lets say var1 = "a...
by aahadqj Explorer in Splunk Search 02-17-2011
0 1
0
1
Jason
I am trying to extract data from the Host field at search time, using a REPORT- in props.conf. The extraction works ...
by Jason Motivator in Splunk Search 02-17-2011
0 1
0
1
Steve_Litras
So I want to do a general field extraction of IP addresses for a sourcetype that may have them in multiple places in ...
by Steve_Litras Path Finder in Splunk Search 02-17-2011
2 2
2
2
beaumaris
We have situations where we just want to show what happened "today", which is defined as from Midnight to now. That'...
by beaumaris Communicator in Splunk Search 02-17-2011
1 1
1
1
splunker30039
I would like to create a dashboard that consists of 2 main parts: 1 - open search bar allowing any search 2 - result...
by splunker30039 Path Finder in Splunk Search 02-17-2011
1 3
1
3
ashishv
so i have a log which has column/field which will be populated with "Y" if there is an ERROR, feild name is ERROR_FLA...
by ashishv Explorer in Splunk Search 02-17-2011
2 6
2
6
gpburgett
I got a challenging request from a customer regarding their access logs. They want to monitor access patterns across ...
by gpburgett Splunk Employee Splunk Employee in Splunk Search 02-17-2011
1 7
1
7
briang67
Hello, I have a case opened for this - but it seems that this forum can be quicker at times... I run between 100-20...
by briang67 Communicator in Splunk Search 02-17-2011
1 4
1
4
mw
I'm trying to wrap my head around some of the more advanced/esoteric search commands. It seems like there's a lot of...
by mw Splunk Employee Splunk Employee in Splunk Search 02-17-2011
3 3
3
3
jrodman
Suppose I have a search such as sourcetype=apache errors which finds errors that I care about. Now, suppose I wa...
by jrodman Splunk Employee Splunk Employee in Splunk Search 02-16-2011
2 1
2
1
mtanadsk
Hi, For some reason, in a query that contains a transaction of some Juniper SSL VPN logs, my duration doesn't seem t...
by mtanadsk Explorer in Splunk Search 02-16-2011
1 1
1
1
jambajuice
We have events that look like this: edit 4 set srcintf "port1" set dstintf "port2" set srcaddr "0....
by jambajuice Communicator in Splunk Search 02-16-2011
1 5
1
5
rgonzale6
I've got a search that results in an IP address. I use that search as a subsearch which takes the IP and uses it as ...
by rgonzale6 Path Finder in Splunk Search 02-15-2011
2 3
2
3
sanju005ind
Given a splunk username how do i search for the following. The roles that the user has - The last 15 searches perfo...
by sanju005ind Communicator in Splunk Search 02-15-2011
1 3
1
3
Beth
I am trying to compare two multivalue fields using the below search: index="weblogic" "Dynamic Server List" | rex f...
by Beth Engager in Splunk Search 02-15-2011
2 1
2
1
thepocketwade
I'm running a search that compiles its results in a table by source and displays the number of logs per source. I'm ...
by thepocketwade Path Finder in Splunk Search 02-15-2011
1 2
1
2
hbazan
Hi! I have a view, with this structure: <ExtendedFieldSearch> <HiddenSearch> <HiddenPostProcess/> ...
by hbazan Path Finder in Splunk Search 02-15-2011
3 5
3
5
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...