Splunk Search

Splunk Search
Community Activity
richard_whiffen
I have some data sources in splunk that are XML formated. The initial request: <query id=12345-54321> <Request_1 in...
by richard_whiffen Explorer in Splunk Search 01-06-2011
0 1
0
1
stevensa
I am trying to report a statistic over the last X Business Days (7 or 30) by multiple hosts. The result chart should...
by stevensa Explorer in Splunk Search 01-06-2011
3 10
3
10
johnboldt
The following search which spans an hour returns 10,000 events which are all included in the final time bucket (ie 10...
by johnboldt Explorer in Splunk Search 01-06-2011
0 2
0
2
jdurham1
Hello - I am sending the results of a saved search/query to an email destination but the results seem to get cut off...
by jdurham1 New Member in Splunk Search 01-06-2011
0 2
0
2
sranga
Hi We recently upgraded our Splunk instance from 4.0.10 to 4.1.4. After the upgrade we are seeing the following er...
by sranga Path Finder in Splunk Search 01-06-2011
0 7
0
7
RNB
I started seeing this error yesterday, and the Splunk>answers responses so far don't seem to fit a pattern I am seein...
by RNB Path Finder in Splunk Search 01-06-2011
0 4
0
4
nocostk
I'm extracting a partial line from a multi-line event. When I test the extract out everything returns as it should. ...
by nocostk Communicator in Splunk Search 01-06-2011
1 4
1
4
MasterOogway
I have a set of router and switch syslog events that I am trying to define 'error' Fields for but I don't see the REX...
by MasterOogway Communicator in Splunk Search 01-05-2011
0 2
0
2
rroberts
Need a comprehensive list of possible DEST_KEY values.
by rroberts Splunk Employee Splunk Employee in Splunk Search 01-05-2011
1 1
1
1
john_loch
Hi all, Can anyone tell me whether it's possible to chart 2 series on different Y axis ? I have a need to represent...
by john_loch Explorer in Splunk Search 01-04-2011
4 2
4
2
ddholstadz
I get this error which I suspect is from reading in a file whith no timestamps in it? Error in 'IndexScopedSearch':...
by ddholstadz Explorer in Splunk Search 01-04-2011
1 1
1
1
Lowell
Is it possible to get your current timezone with an eval search command? Background: I'm trying build a search th...
by Lowell Super Champion in Splunk Search 01-04-2011
3 14
3
14
msarro
I am trying to set up a fairly simple search: index="sandbox" sourcetype="as-cdr" |stats count(eval(Calling_Number=*...
by msarro Builder in Splunk Search 01-04-2011
1 3
1
3
bsonposh
I want to be able to do a search like "UserName=Bleh sourcetype=ns_log" but it doesn't seem to work. Does the API use...
by bsonposh Communicator in Splunk Search 01-04-2011
1 1
1
1
berndg
Hi, i'm currently trying to "optimize" a dashboard by reusing a base search for different panels. This is the dashb...
by berndg Engager in Splunk Search 01-04-2011
1 2
1
2
nuuki
Hi, I'm new to Splunk but getting a lot of value from it. I've gotten a reasonable way using trial and error and a l...
by nuuki New Member in Splunk Search 01-04-2011
0 3
0
3
ndoshi
The transaction search command will automatically compute the duration from the first event to the last event within ...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 01-03-2011
3 9
3
9
Lowell
Is it possible to tell splunk what the default permissions should be when an object is created from the Splunk UI? T...
by Lowell Super Champion in Splunk Search 01-03-2011
1 1
1
1
fisk12
Hello I have begin try to build up splunk to use as an event handler. Ssh seemed to be a good place to start and lear...
by fisk12 Path Finder in Splunk Search 01-03-2011
0 3
0
3
jackyc
Hi there, I am constructing a series of searches for a dashboard for annual audit. Because it is necessary to parse ...
by jackyc Explorer in Splunk Search 01-03-2011
1 4
1
4
tawollen
I tried looking for something like this in answers and splunk docs and may not be using the right keywords. Is ther...
by tawollen Path Finder in Splunk Search 12-30-2010
1 4
1
4
infrauser
Hi Folks, I'd appreciate any advice on a good way to add site specific information to events. I have a distributed ...
by infrauser Explorer in Splunk Search 12-30-2010
0 7
0
7
axsolis
Hi, I am think there is a simple solution to this but I am not having much luck finding it. I have a portion of the...
by axsolis Path Finder in Splunk Search 12-30-2010
1 2
1
2
Blu3fish
Is it possible to edit a saved search after its initial creation in order to change the chart type (via the cli or ui...
by Blu3fish Path Finder in Splunk Search 12-30-2010
2 4
2
4
freeti00
but due to a number of reasons I need to run very large job via monthly cron initiated script. How do I avoid the nee...
by freeti00 Explorer in Splunk Search 12-29-2010
0 2
0
2
Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...