Splunk Search

Splunk Search
Community Activity
Toups
I have searched the documentation and have not yet found how to omit or delete specific fields from an input. The in...
by Toups Explorer in Splunk Search 12-03-2010
1 3
1
3
castle1126
I had previously posted this question earlier: http://answers.splunk.com/questions/9264/am-i-bumping-into-limits-issu...
by castle1126 Communicator in Splunk Search 12-03-2010
0 2
0
2
maverick
I would like to create a report table where the first column is the time stamp, followed by columns for pid, process,...
by maverick Splunk Employee Splunk Employee in Splunk Search 12-03-2010
1 1
1
1
drewbfl
Looking to have the ip's replaced with the hostnames. Receiving the error, "The lookup table 'hosts' does not exist. ...
by drewbfl Path Finder in Splunk Search 12-03-2010
3 6
3
6
Mikey_C
Hello, So xpath feature is great, but I have this issue. We deal with XML messaging from our customers and would li...
by Mikey_C Engager in Splunk Search 12-02-2010
1 3
1
3
Genti
i have events that look like this: CEF:0|Symantec|Endpoint Protection|11|999|"C:\\Program Files\\Symantec\\Symantec ...
by Genti Splunk Employee Splunk Employee in Splunk Search 12-02-2010
0 3
0
3
laurensv
I'm currently sending BlueCoat logs in W3C ELFF format to Splunk. I've also installed the latest Splunk for Blue Coat...
by laurensv Path Finder in Splunk Search 12-02-2010
0 9
0
9
jdagenais
We have a multi line message that looks like this: 11/30/10 16:28:34 Verifying pricing env CLOSE,FX_CLOSE,XLA_ENV,IN...
by jdagenais Explorer in Splunk Search 12-02-2010
1 4
1
4
jdagenais
Hello, Is it possible to start a search (or report, chart, etc) which will display the last 15 minutes of events, an...
by jdagenais Explorer in Splunk Search 12-02-2010
2 1
2
1
castle1126
Hi, I have come across an issue similar to this link on Answers: (http://answers.splunk.com/questions/3092/cant-get-...
by castle1126 Communicator in Splunk Search 12-01-2010
0 8
0
8
bansi
We use Log4J log file which is fed as input to Splunk. Each entry in the XML file is XML object with timestamp. Our ...
by bansi Path Finder in Splunk Search 12-01-2010
0 2
0
2
Hazel
Hello I have written a dnslookup2 as follows, it simply just takes the ip to return the host: external_lookup.py ho...
by Hazel Communicator in Splunk Search 12-01-2010
1 3
1
3
tedder
This should be easy. I'm building a query: index=asdf "search string" | rex field=_raw mode=sed "s/.*foo(.*?)bar/\1/...
by tedder Communicator in Splunk Search 11-30-2010
1 2
1
2
tchien
I log into the web interface using a particular id, and i'm only concerned about a particular index, which is not the...
by tchien Engager in Splunk Search 11-30-2010
1 2
1
2
jdagenais
We are adding more search and report in the "Search & Reports" menu, and I would like to add sub menus such as: Sear...
by jdagenais Explorer in Splunk Search 11-30-2010
2 2
2
2
fedevietti
Deal Splunkers, I'm doing a serach like this to valorize a SingleValue indicator with range: <my search> | eval sec...
by fedevietti New Member in Splunk Search 11-30-2010
0 1
0
1
Tim
Has anyone had issues using InputCsv? I created a CSV files using the 'outputcsv x' on a small event set. I verified ...
by Tim Explorer in Splunk Search 11-29-2010
0 2
0
2
jamesklassen
I have data that is not being recognized. A PowerShell script outputs data (that I copied to a file for testing) that...
by jamesklassen Path Finder in Splunk Search 11-29-2010
0 3
0
3
ysouchon
Hello, I know quite good Splunk, at least the basic concepts. I have recently created a dashboard with few panels ba...
by ysouchon Explorer in Splunk Search 11-27-2010
0 1
0
1
laurensv
Hello, I have a simple request  For a certain syslog source, I need to extract the 3rd word beginning from the end ...
by laurensv Path Finder in Splunk Search 11-26-2010
0 6
0
6
pinzer
sourcetype="sophos" pmx_action="keep" fur!="none" | bucket _time span=24h | timechart span="1d" count Hi all, i ne...
by pinzer Path Finder in Splunk Search 11-25-2010
0 3
0
3
Shane
What is the proper format to put hosts in the tags.conf file?
by Shane Explorer in Splunk Search 11-23-2010
0 14
0
14
nbcohen
I have created a search something like this: index="mydata" |stats count, first(supportGroup) as supportGroup by hos...
by nbcohen Explorer in Splunk Search 11-23-2010
0 2
0
2
grahampoulter
Events are going missing from our search results. The "scanned events" total during the search is correct, but the "...
by grahampoulter Path Finder in Splunk Search 11-23-2010
2 4
2
4
Kendrick33
I am performing some math functions in splunk.I am doing a search that will calculate the percentage of each data typ...
by Kendrick33 Explorer in Splunk Search 11-23-2010
1 3
1
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...