Splunk Search

Splunk Search
Community Activity
dikaye
Hi, My mail server logs display recipient info like that: Feb 14 16:04:25 224.67.24.175 Feb 14 16:04:25 mail_log...
by dikaye Path Finder in Splunk Search 02-15-2011
0 3
0
3
sideview
I have multiline events where there's a fair bit of auto-kv extraction that is good, but then there's a lot of noise ...
by SplunkTrust SplunkTrust in Splunk Search 02-15-2011
1 6
1
6
aahadqj
Hi, I am trying to plot the percentage data over a period of span 1h. host="abc" sourcetype="xyz" ("Eurl" ) | eval ...
by aahadqj Explorer in Splunk Search 02-15-2011
1 7
1
7
phoenixdigital
Hi All, I'll start with the data we are dealing with. It deals with predictions of a price into the future. We recei...
by phoenixdigital Builder in Splunk Search 02-15-2011
2 5
2
5
hmahendrakumar
I want to compute average across columns for a table(that I get as a result from stats command). I am trying to do so...
by hmahendrakumar Path Finder in Splunk Search 02-14-2011
0 3
0
3
anthonycohn
Hi, I am having ADSL line problems as a result I am using splunk to monitor my syslog, especially interested in lines...
by anthonycohn New Member in Splunk Search 02-14-2011
0 3
0
3
dikaye
Dear Sir, We will have two indexer servers for our account login to manage they account founctions, so how to centra...
by dikaye Path Finder in Splunk Search 02-14-2011
0 3
0
3
DaClyde
I need to be able to show how long it has been since a user uploaded or downloaded a specific type of data based on t...
by DaClyde Contributor in Splunk Search 02-12-2011
1 5
1
5
dpgrant
My Enterprise Trial license was just about to expire, so I applied the "free" license. Since there is no authenticat...
by dpgrant Engager in Splunk Search 02-11-2011
1 1
1
1
castle1126
I'm writing a search that performs a simple eval: eval changed = case (NOT address="-",address,NOT city="-",city,NOT...
by castle1126 Communicator in Splunk Search 02-11-2011
3 3
3
3
the_wolverine
I'm not sure how to workaround an issue where my field extraction is working on multiple values of the same field. F...
by the_wolverine Champion in Splunk Search 02-11-2011
0 4
0
4
jambajuice
I'm doing some field extractions for a sourcetype and Splunk is saying the field has already been extracted. I went ...
by jambajuice Communicator in Splunk Search 02-10-2011
0 2
0
2
Rob_Jordan
I want to extract fields from WebLogic logs to use in reports.
by Rob_Jordan Explorer in Splunk Search 02-10-2011
3 2
3
2
Ron_Naken
When I configure Splunk to index a folder containing config files and text documents, it indexes each line of the fil...
by Ron_Naken Splunk Employee Splunk Employee in Splunk Search 02-10-2011
2 2
2
2
jq06
I am using lookup to "house" this long list of keywords. Now, I want to run a query against field A (eg. ABC-DEF-ZYL)...
by jq06 New Member in Splunk Search 02-10-2011
0 3
0
3
jambajuice
I want to create a single lookup table based on the results of three different searches. I've tried using subsearche...
by jambajuice Communicator in Splunk Search 02-10-2011
3 2
3
2
I-Man
Hey Splunkers, I cannot get the following rex statement to match in Splunk. I read that using (?m) in the transforms...
by I-Man Communicator in Splunk Search 02-10-2011
2 4
2
4
sanju005ind
I would like to display the volume indexed from several indexed into following chart. Past 24hrs log volume by time...
by sanju005ind Communicator in Splunk Search 02-09-2011
0 3
0
3
wyang6
http://www.splunk.com/base/Documentation/latest/User/Fieldlookupstutorial Error 'Could not find all of the spec...
by wyang6 Path Finder in Splunk Search 02-09-2011
0 1
0
1
ruffieuxlu
Hi, I am trying to create an arborescence of saved search but I have some problems. I would like to have something li...
by ruffieuxlu New Member in Splunk Search 02-09-2011
0 4
0
4
nbharadwaj
I am parsing through a lot of data, so I want to do this preferably in one search command. 1) I want to generate dis...
by nbharadwaj Path Finder in Splunk Search 02-08-2011
3 3
3
3
fk319
I would like to do an eval on every log entry, from a certian sourcetype. In this case I have a real number that I w...
by fk319 Builder in Splunk Search 02-08-2011
0 2
0
2
dhaffner
It would be very helpful to have a documented list of error codes. Does anyone know of such a thing? Even if there i...
by dhaffner Path Finder in Splunk Search 02-08-2011
3 5
3
5
jambajuice
I have a timechart that is based on count by score, where score is a whole number between 0 and 10. Every time I mak...
by jambajuice Communicator in Splunk Search 02-08-2011
2 1
2
1
gregwilliams
We are conducting a study in our organization surrounding productivity and user behavior. Currently I'm receiving al...
by gregwilliams Path Finder in Splunk Search 02-08-2011
3 1
3
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...