Splunk Search

Splunk Search
Community Activity
ruisantos
Is there a way to limit the amount of summary events stored by sitop. I have scheduled search running every night wit...
by ruisantos Path Finder in Splunk Search 01-10-2011
0 1
0
1
milspec
Hi all, Similar This question is similar to http://answers.splunk.com/questions/10093/teaching-splunk-the-fields-i...
by milspec New Member in Splunk Search 01-10-2011
0 1
0
1
imarks004
Is there a specific logging format that I should set in the SplunkforSquid app to get the proper field extraction? I...
by imarks004 Path Finder in Splunk Search 01-10-2011
1 3
1
3
mw
I have events which include: .... relevant=False .... and I'd like to transform those at search time into a field ...
by mw Splunk Employee Splunk Employee in Splunk Search 01-09-2011
0 2
0
2
slaterok
I'm looking for spiders, which I can identify by abusive rates using transactions. For example: SPLUNK_SEARCH='sourc...
by slaterok New Member in Splunk Search 01-09-2011
0 1
0
1
mw
I'm having a tough time conceptualizing this, and was hoping someone could get my brain kickstarted. I have multiple...
by mw Splunk Employee Splunk Employee in Splunk Search 01-08-2011
0 2
0
2
dpadams
I've got log data that includes JSON text that's sent up using POST to a Web server. A raw regex pattern to match the...
by dpadams Communicator in Splunk Search 01-07-2011
0 1
0
1
meydvr
How to not list field picker fields in alphabetic order? The field picker order looks to be alphabetic. Based on the...
by meydvr Engager in Splunk Search 01-07-2011
1 1
1
1
MasterOogway
When I run the following subsearch over an hours time it takes many minutes, if it completes at all. When run over Re...
by MasterOogway Communicator in Splunk Search 01-07-2011
1 11
1
11
kmattern
How come I can't create tags? It keeps telling me that I'm a new user but I'm not. And why does a title have to be a...
by kmattern Builder in Splunk Search 01-07-2011
3 4
3
4
carmackd
Is it possible for a field generated by an automatic lookup to share the same name as a field generated by an extract...
by carmackd Communicator in Splunk Search 01-07-2011
1 2
1
2
richard_whiffen
I have some data sources in splunk that are XML formated. The initial request: <query id=12345-54321> <Request_1 in...
by richard_whiffen Explorer in Splunk Search 01-06-2011
0 1
0
1
stevensa
I am trying to report a statistic over the last X Business Days (7 or 30) by multiple hosts. The result chart should...
by stevensa Explorer in Splunk Search 01-06-2011
3 10
3
10
johnboldt
The following search which spans an hour returns 10,000 events which are all included in the final time bucket (ie 10...
by johnboldt Explorer in Splunk Search 01-06-2011
0 2
0
2
jdurham1
Hello - I am sending the results of a saved search/query to an email destination but the results seem to get cut off...
by jdurham1 New Member in Splunk Search 01-06-2011
0 2
0
2
sranga
Hi We recently upgraded our Splunk instance from 4.0.10 to 4.1.4. After the upgrade we are seeing the following er...
by sranga Path Finder in Splunk Search 01-06-2011
0 7
0
7
RNB
I started seeing this error yesterday, and the Splunk>answers responses so far don't seem to fit a pattern I am seein...
by RNB Path Finder in Splunk Search 01-06-2011
0 4
0
4
nocostk
I'm extracting a partial line from a multi-line event. When I test the extract out everything returns as it should. ...
by nocostk Communicator in Splunk Search 01-06-2011
1 4
1
4
MasterOogway
I have a set of router and switch syslog events that I am trying to define 'error' Fields for but I don't see the REX...
by MasterOogway Communicator in Splunk Search 01-05-2011
0 2
0
2
rroberts
Need a comprehensive list of possible DEST_KEY values.
by rroberts Splunk Employee Splunk Employee in Splunk Search 01-05-2011
1 1
1
1
john_loch
Hi all, Can anyone tell me whether it's possible to chart 2 series on different Y axis ? I have a need to represent...
by john_loch Explorer in Splunk Search 01-04-2011
4 2
4
2
ddholstadz
I get this error which I suspect is from reading in a file whith no timestamps in it? Error in 'IndexScopedSearch':...
by ddholstadz Explorer in Splunk Search 01-04-2011
1 1
1
1
Lowell
Is it possible to get your current timezone with an eval search command? Background: I'm trying build a search th...
by Lowell Super Champion in Splunk Search 01-04-2011
3 14
3
14
msarro
I am trying to set up a fairly simple search: index="sandbox" sourcetype="as-cdr" |stats count(eval(Calling_Number=*...
by msarro Builder in Splunk Search 01-04-2011
1 3
1
3
bsonposh
I want to be able to do a search like "UserName=Bleh sourcetype=ns_log" but it doesn't seem to work. Does the API use...
by bsonposh Communicator in Splunk Search 01-04-2011
1 1
1
1
Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...
Top Solution Authors