Splunk Search

Splunk Search
Community Activity
pinzer
Hi all i need to do a search like this: sourcetype="webseal_access" OR sourcetype="wmi:wineventlog:security" | renam...
by pinzer Path Finder in Splunk Search 12-13-2010
0 2
0
2
hjwang
i would like to send an alert when newwork interface is down more than 3 min. That is to say i wanna group the field ...
by hjwang Contributor in Splunk Search 12-13-2010
0 1
0
1
mw
I have an event with a field like this: ids="ID-120-1, ID-141-5, ID-92-5, N/A" I'd like to extract the field and onl...
by mw Splunk Employee Splunk Employee in Splunk Search 12-13-2010
0 3
0
3
splun88
I am indexing W3C Extended IIS logs and have found that Splunk is extracting column headers from the logs, but due to...
by splun88 Engager in Splunk Search 12-11-2010
1 1
1
1
sanju005ind
How do I get a list of scheduled searches associated with user info.
by sanju005ind Communicator in Splunk Search 12-10-2010
3 4
3
4
kmattern
I have a CSV table that lists the following fields: date, time, location, received, authorized It looks like this ...
by kmattern Builder in Splunk Search 12-10-2010
0 1
0
1
fk319
I would like to use a different field than _time as my time base for timechart. I build a stats table, and in it I u...
by fk319 Builder in Splunk Search 12-10-2010
1 3
1
3
the_wolverine
I started running the fill_summary_index.py script and my session was interrupted. The summary backfill process neve...
by the_wolverine Champion in Splunk Search 12-10-2010
1 3
1
3
jambajuice
I am trying to create a lookup table from evenst similar to the following: results|192.168.2|192.168.2.183|microsoft...
by jambajuice Communicator in Splunk Search 12-10-2010
0 2
0
2
jrstear
How to plot running sums? Eg given events with fields "time host errors", I'd like to do | timechart accum(errors) ...
by jrstear Path Finder in Splunk Search 12-09-2010
0 2
0
2
mayler
The mac address format for all of my logs is xx:xx:xx:xx:xx:xx AUTHORIZATION-SUCCESS: user: airport; mac: e8:06:88:8...
by mayler Path Finder in Splunk Search 12-09-2010
1 2
1
2
dwaddle
I was working with a search similar to: my_nifty_search_terms | stats distinct_count(field) by date_hour and notic...
by SplunkTrust SplunkTrust in Splunk Search 12-09-2010
1 1
1
1
skippylou
I'm trying to rex out a chunk of events, then remove that field from the events prior to piping to the cluster comman...
by skippylou Communicator in Splunk Search 12-08-2010
2 2
2
2
rgcox1
Trying to emulate example given here, but totals always come up zero. Basic search returns over 1,000 events for a 4 ...
by rgcox1 Communicator in Splunk Search 12-08-2010
0 2
0
2
sanju005ind
I have file which has a set of all users and roles with the Splunk account.The file name is usermap.csv I am using t...
by sanju005ind Communicator in Splunk Search 12-08-2010
0 1
0
1
the_wolverine
I'm trying to find out what the oldest occurrence of an event was - as in, opposite of head. Is there such a command...
by the_wolverine Champion in Splunk Search 12-08-2010
1 6
1
6
tradecraft1914
I am trying to average calculate the time between web log entries. If an IP on the network visits the same URL multip...
by tradecraft1914 Explorer in Splunk Search 12-08-2010
1 1
1
1
bansi
I am stranded extracting "values" from below xml <SearchElements> <entry key="FirstName">%</entry> <ent...
by bansi Path Finder in Splunk Search 12-07-2010
0 3
0
3
Toups
I am working with the following input and wanted some advice on how/where to specify the field extractions: "\x00\x0...
by Toups Explorer in Splunk Search 12-07-2010
0 6
0
6
cpenkert
I am creating a dashboard with one panel displaying 404 errors. I am able to get this working fine with the followin...
by cpenkert Path Finder in Splunk Search 12-07-2010
0 2
0
2
bansi
The search result produces output of a column in following format Element[contractId=true,memberId=<null>,name=[Name...
by bansi Path Finder in Splunk Search 12-06-2010
0 3
0
3
bansi
How to extract values between Elements tag. <DataNode node-type="Contract"> <TransactionAttributes> ...
by bansi Path Finder in Splunk Search 12-06-2010
0 6
0
6
nocostk
I'm trying to configure a real-time dashboard using the Google Maps application. I'm able to get the application wor...
by nocostk Communicator in Splunk Search 12-06-2010
0 3
0
3
meno
I got stuck with extracting a multi value field from XML data: <Results> <Result> <Grade>Error</Grade> ...
by meno Path Finder in Splunk Search 12-05-2010
1 8
1
8
gnovak
Hi! I am not quite sure how to go about trying to do this task. I have 3 searches that run and gather data in splun...
by gnovak Builder in Splunk Search 12-03-2010
0 6
0
6
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...