Splunk Search

Splunk Search
Community Activity
jdurham1
Hello - I am sending the results of a saved search/query to an email destination but the results seem to get cut off...
by jdurham1 New Member in Splunk Search 01-06-2011
0 2
0
2
sranga
Hi We recently upgraded our Splunk instance from 4.0.10 to 4.1.4. After the upgrade we are seeing the following er...
by sranga Path Finder in Splunk Search 01-06-2011
0 7
0
7
RNB
I started seeing this error yesterday, and the Splunk>answers responses so far don't seem to fit a pattern I am seein...
by RNB Path Finder in Splunk Search 01-06-2011
0 4
0
4
nocostk
I'm extracting a partial line from a multi-line event. When I test the extract out everything returns as it should. ...
by nocostk Communicator in Splunk Search 01-06-2011
1 4
1
4
MasterOogway
I have a set of router and switch syslog events that I am trying to define 'error' Fields for but I don't see the REX...
by MasterOogway Communicator in Splunk Search 01-05-2011
0 2
0
2
rroberts
Need a comprehensive list of possible DEST_KEY values.
by rroberts Splunk Employee Splunk Employee in Splunk Search 01-05-2011
1 1
1
1
john_loch
Hi all, Can anyone tell me whether it's possible to chart 2 series on different Y axis ? I have a need to represent...
by john_loch Explorer in Splunk Search 01-04-2011
4 2
4
2
ddholstadz
I get this error which I suspect is from reading in a file whith no timestamps in it? Error in 'IndexScopedSearch':...
by ddholstadz Explorer in Splunk Search 01-04-2011
1 1
1
1
Lowell
Is it possible to get your current timezone with an eval search command? Background: I'm trying build a search th...
by Lowell Super Champion in Splunk Search 01-04-2011
3 14
3
14
msarro
I am trying to set up a fairly simple search: index="sandbox" sourcetype="as-cdr" |stats count(eval(Calling_Number=*...
by msarro Builder in Splunk Search 01-04-2011
1 3
1
3
bsonposh
I want to be able to do a search like "UserName=Bleh sourcetype=ns_log" but it doesn't seem to work. Does the API use...
by bsonposh Communicator in Splunk Search 01-04-2011
1 1
1
1
berndg
Hi, i'm currently trying to "optimize" a dashboard by reusing a base search for different panels. This is the dashb...
by berndg Engager in Splunk Search 01-04-2011
1 2
1
2
nuuki
Hi, I'm new to Splunk but getting a lot of value from it. I've gotten a reasonable way using trial and error and a l...
by nuuki New Member in Splunk Search 01-04-2011
0 3
0
3
ndoshi
The transaction search command will automatically compute the duration from the first event to the last event within ...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 01-03-2011
3 9
3
9
Lowell
Is it possible to tell splunk what the default permissions should be when an object is created from the Splunk UI? T...
by Lowell Super Champion in Splunk Search 01-03-2011
1 1
1
1
fisk12
Hello I have begin try to build up splunk to use as an event handler. Ssh seemed to be a good place to start and lear...
by fisk12 Path Finder in Splunk Search 01-03-2011
0 3
0
3
jackyc
Hi there, I am constructing a series of searches for a dashboard for annual audit. Because it is necessary to parse ...
by jackyc Explorer in Splunk Search 01-03-2011
1 4
1
4
tawollen
I tried looking for something like this in answers and splunk docs and may not be using the right keywords. Is ther...
by tawollen Path Finder in Splunk Search 12-30-2010
1 4
1
4
infrauser
Hi Folks, I'd appreciate any advice on a good way to add site specific information to events. I have a distributed ...
by infrauser Explorer in Splunk Search 12-30-2010
0 7
0
7
axsolis
Hi, I am think there is a simple solution to this but I am not having much luck finding it. I have a portion of the...
by axsolis Path Finder in Splunk Search 12-30-2010
1 2
1
2
Blu3fish
Is it possible to edit a saved search after its initial creation in order to change the chart type (via the cli or ui...
by Blu3fish Path Finder in Splunk Search 12-30-2010
2 4
2
4
freeti00
but due to a number of reasons I need to run very large job via monthly cron initiated script. How do I avoid the nee...
by freeti00 Explorer in Splunk Search 12-29-2010
0 2
0
2
conf0101
I am seeing my log entries prepended with strings like: _internal\x00\x00\x00\x00\x14MetaData:Sourcetype\x00\x00\x00...
by conf0101 Engager in Splunk Search 12-28-2010
1 2
1
2
Yancy
I'm trying to make a UserAgent report on from a summary index that I'm populating with a count for each browser/os th...
by Yancy Path Finder in Splunk Search 12-28-2010
1 1
1
1
pl123
Hi there, My Splunk environment is made up from 1 Deployment Server, 1 Indexer and 20+ light forwarders. How coul...
by pl123 Path Finder in Splunk Search 12-27-2010
1 3
1
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...