Splunk Search

Splunk Search
Community Activity
markrussell
I am having trouble extract the data from an apache log. Below is one message from the log, there is some header in...
by markrussell New Member in Splunk Search 01-13-2011
0 2
0
2
davidanso
Hi I have installed the pdfserver 1.2 on a SLES10 SP2 box and an Ubuntu 10.04 box. Both installations are running S...
by davidanso Explorer in Splunk Search 01-13-2011
0 1
0
1
MasterOogway
If I have a lookup table with the following information in it (see below), how do I send an email if the "event" foun...
by MasterOogway Communicator in Splunk Search 01-13-2011
2 5
2
5
jambajuice
Here is my transforms.conf for the lookup table in question: [ossim_plugins] filename = ossim_plugins.csv max_matche...
by jambajuice Communicator in Splunk Search 01-13-2011
1 1
1
1
staze
So, question relating to pulling useful data out of AFP (Apple File Protocol) logs on the server. A line in the log...
by staze Path Finder in Splunk Search 01-13-2011
0 4
0
4
Marinus
I'm currently collecting logs on a lightweight forwarder. I'm adding a special field to the messages which I'd like t...
by Marinus Communicator in Splunk Search 01-13-2011
0 4
0
4
srw46
Hello all, I'm trying to create a report that compares the number of transactions (from the same system) between dif...
by srw46 Path Finder in Splunk Search 01-13-2011
0 2
0
2
stjack99
I'm trying to generate a table that is a count of things by the 12 months of the year. For instance, the chart might ...
by stjack99 Explorer in Splunk Search 01-12-2011
0 2
0
2
jambajuice
I am trying to parse a bunch of Nessus vulnerability plugin files and extract the CVE and OSVDB reference IDs from ea...
by jambajuice Communicator in Splunk Search 01-12-2011
0 3
0
3
Lowell
Can anyone tell me the reasons why timestartpos, timeendpos, and all the date_* fields would be missing from an event...
by Lowell Super Champion in Splunk Search 01-12-2011
2 4
2
4
joshd
Hello, to begin here is a sample of the data I am working with, they are events grouped using the transaction command...
by joshd Builder in Splunk Search 01-12-2011
0 2
0
2
castle1126
I'm trying to come up with a search that would help me find emails that share the same subject line but the IP addres...
by castle1126 Communicator in Splunk Search 01-12-2011
0 5
0
5
Rob
The following example events are indexed by Splunk: Dec 1 00:47:58 serverName data-collector[1234]: #A_RECV# 1234, 5...
by Rob Splunk Employee Splunk Employee in Splunk Search 01-12-2011
2 1
2
1
jambajuice
I'm trying to create a dashboard that will add vulnerability data from OSVDB to the results of a Nessus scan. I've c...
by jambajuice Communicator in Splunk Search 01-12-2011
1 1
1
1
briang67
The analyzefields seems to be interesting in its ability to correlate across multiple fields, but I cannot determine ...
by briang67 Communicator in Splunk Search 01-11-2011
3 2
3
2
jambajuice
I'm working with a number of files in a CSV comma delimited format that don't contain header rows. Is it possible to...
by jambajuice Communicator in Splunk Search 01-11-2011
0 1
0
1
jambajuice
I am experimenting with some searches that will need to do lookups on some fairly big tables (30 MB or more). I'm wo...
by jambajuice Communicator in Splunk Search 01-11-2011
3 1
3
1
htkhtk
What I am trying to do is to get a listing of the last 7 days (that logs were entered - not necessarily the last 7 ca...
by htkhtk Path Finder in Splunk Search 01-11-2011
0 3
0
3
ickymettle
Hi folks, I'm working on a search to return the number of events by hour over any specified time period. At the mom...
by ickymettle Explorer in Splunk Search 01-10-2011
4 4
4
4
Marinus
I'd like to compare the configuration of several nodes using a single search. Each node has multiple keys expressed a...
by Marinus Communicator in Splunk Search 01-10-2011
1 1
1
1
starks951
Folks... I am extracting two variables at search time and trying to report when the two variables are not the same. ...
by starks951 Explorer in Splunk Search 01-10-2011
1 4
1
4
ruisantos
Is there a way to limit the amount of summary events stored by sitop. I have scheduled search running every night wit...
by ruisantos Path Finder in Splunk Search 01-10-2011
0 1
0
1
milspec
Hi all, Similar This question is similar to http://answers.splunk.com/questions/10093/teaching-splunk-the-fields-i...
by milspec New Member in Splunk Search 01-10-2011
0 1
0
1
imarks004
Is there a specific logging format that I should set in the SplunkforSquid app to get the proper field extraction? I...
by imarks004 Path Finder in Splunk Search 01-10-2011
1 3
1
3
mw
I have events which include: .... relevant=False .... and I'd like to transform those at search time into a field ...
by mw Splunk Employee Splunk Employee in Splunk Search 01-09-2011
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...