Splunk Search

Splunk Search
Community Activity
the_wolverine
I'm trying to find out what the oldest occurrence of an event was - as in, opposite of head. Is there such a command...
by the_wolverine Champion in Splunk Search 12-08-2010
1 6
1
6
tradecraft1914
I am trying to average calculate the time between web log entries. If an IP on the network visits the same URL multip...
by tradecraft1914 Explorer in Splunk Search 12-08-2010
1 1
1
1
bansi
I am stranded extracting "values" from below xml <SearchElements> <entry key="FirstName">%</entry> <ent...
by bansi Path Finder in Splunk Search 12-07-2010
0 3
0
3
Toups
I am working with the following input and wanted some advice on how/where to specify the field extractions: "\x00\x0...
by Toups Explorer in Splunk Search 12-07-2010
0 6
0
6
cpenkert
I am creating a dashboard with one panel displaying 404 errors. I am able to get this working fine with the followin...
by cpenkert Path Finder in Splunk Search 12-07-2010
0 2
0
2
bansi
The search result produces output of a column in following format Element[contractId=true,memberId=<null>,name=[Name...
by bansi Path Finder in Splunk Search 12-06-2010
0 3
0
3
bansi
How to extract values between Elements tag. <DataNode node-type="Contract"> <TransactionAttributes> ...
by bansi Path Finder in Splunk Search 12-06-2010
0 6
0
6
nocostk
I'm trying to configure a real-time dashboard using the Google Maps application. I'm able to get the application wor...
by nocostk Communicator in Splunk Search 12-06-2010
0 3
0
3
meno
I got stuck with extracting a multi value field from XML data: <Results> <Result> <Grade>Error</Grade> ...
by meno Path Finder in Splunk Search 12-05-2010
1 8
1
8
gnovak
Hi! I am not quite sure how to go about trying to do this task. I have 3 searches that run and gather data in splun...
by gnovak Builder in Splunk Search 12-03-2010
0 6
0
6
Toups
I have searched the documentation and have not yet found how to omit or delete specific fields from an input. The in...
by Toups Explorer in Splunk Search 12-03-2010
1 3
1
3
castle1126
I had previously posted this question earlier: http://answers.splunk.com/questions/9264/am-i-bumping-into-limits-issu...
by castle1126 Communicator in Splunk Search 12-03-2010
0 2
0
2
maverick
I would like to create a report table where the first column is the time stamp, followed by columns for pid, process,...
by maverick Splunk Employee Splunk Employee in Splunk Search 12-03-2010
1 1
1
1
drewbfl
Looking to have the ip's replaced with the hostnames. Receiving the error, "The lookup table 'hosts' does not exist. ...
by drewbfl Path Finder in Splunk Search 12-03-2010
3 6
3
6
Mikey_C
Hello, So xpath feature is great, but I have this issue. We deal with XML messaging from our customers and would li...
by Mikey_C Engager in Splunk Search 12-02-2010
1 3
1
3
Genti
i have events that look like this: CEF:0|Symantec|Endpoint Protection|11|999|"C:\\Program Files\\Symantec\\Symantec ...
by Genti Splunk Employee Splunk Employee in Splunk Search 12-02-2010
0 3
0
3
laurensv
I'm currently sending BlueCoat logs in W3C ELFF format to Splunk. I've also installed the latest Splunk for Blue Coat...
by laurensv Path Finder in Splunk Search 12-02-2010
0 9
0
9
jdagenais
We have a multi line message that looks like this: 11/30/10 16:28:34 Verifying pricing env CLOSE,FX_CLOSE,XLA_ENV,IN...
by jdagenais Explorer in Splunk Search 12-02-2010
1 4
1
4
jdagenais
Hello, Is it possible to start a search (or report, chart, etc) which will display the last 15 minutes of events, an...
by jdagenais Explorer in Splunk Search 12-02-2010
2 1
2
1
castle1126
Hi, I have come across an issue similar to this link on Answers: (http://answers.splunk.com/questions/3092/cant-get-...
by castle1126 Communicator in Splunk Search 12-01-2010
0 8
0
8
bansi
We use Log4J log file which is fed as input to Splunk. Each entry in the XML file is XML object with timestamp. Our ...
by bansi Path Finder in Splunk Search 12-01-2010
0 2
0
2
Hazel
Hello I have written a dnslookup2 as follows, it simply just takes the ip to return the host: external_lookup.py ho...
by Hazel Communicator in Splunk Search 12-01-2010
1 3
1
3
tedder
This should be easy. I'm building a query: index=asdf "search string" | rex field=_raw mode=sed "s/.*foo(.*?)bar/\1/...
by tedder Communicator in Splunk Search 11-30-2010
1 2
1
2
tchien
I log into the web interface using a particular id, and i'm only concerned about a particular index, which is not the...
by tchien Engager in Splunk Search 11-30-2010
1 2
1
2
jdagenais
We are adding more search and report in the "Search & Reports" menu, and I would like to add sub menus such as: Sear...
by jdagenais Explorer in Splunk Search 11-30-2010
2 2
2
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...