Splunk Search

Splunk Search
Community Activity
fedevietti
Dear All, I'm doing a search with a summarize count at the end. The search is the following: (eventtype="searchVPN"...
by fedevietti New Member in Splunk Search 11-04-2010
0 2
0
2
blurblebot
This is killing me. I'm trying to sum the bytes crossing my boundary in each direction. For TCP sessions, I have a ...
by blurblebot Communicator in Splunk Search 11-04-2010
1 7
1
7
flora123
Hello ALL! x=-241 eval final_x=tostring(x,"commas") It shows [-,241], but it should be [-241]. How could I show t...
by flora123 Path Finder in Splunk Search 11-04-2010
2 4
2
4
gnovak
Hello, I've read through some of the other questions on here to try and find an answer to my question, but i'm still...
by gnovak Builder in Splunk Search 11-03-2010
1 4
1
4
mpatnode
Why do I get this message? Assuming implicit lookup table with filename sidtodn.csv It seemed to me that I was f...
by mpatnode Path Finder in Splunk Search 11-03-2010
0 2
0
2
jkoepsell
Hello, When performing a search, can Splunk perform a DB2 database lookup of uncollected user data, associate it wit...
by jkoepsell Engager in Splunk Search 11-03-2010
1 1
1
1
parallaxed
Since the rewrite of the tailing processor in 4.1, on the whole it seems much better than previous incarnations, but ...
by parallaxed Path Finder in Splunk Search 11-03-2010
0 5
0
5
rsimmons
The Search Inspector indicated that the cursorTime in the year 2038. What does this mean? example from search job in...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 1
1
1
ndoshi
I would like to relate 2 different sourcetypes with a common value for a field. The fields are named differently in e...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 2
1
2
Steve_G_
Trying to understand exactly how directory recursion works in inputs.conf. Specifically, how does /foo/.../.../.log...
by Steve_G_ Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 1
1
1
tmeader
I've currently got a summary search setup going against DNS query data that I use to produce a reporting chart of the...
by tmeader Contributor in Splunk Search 11-01-2010
0 5
0
5
grio
sourcetype=A earliest=10/21/2010:09:0:0 latest=10/21/2010:09:02:0 OR sourcetype=listener earliest=10/21/2010:08:59:0 ...
by grio Engager in Splunk Search 10-31-2010
0 2
0
2
rbbelen
running a this query: splunk search "0e47015c-052f-4235-a25c-cbf3662371ee", returns this... [10/5/10 8:45:01:521 CDT...
by rbbelen New Member in Splunk Search 10-31-2010
0 4
0
4
dgarstang
As an admin that's used to searching logs with /bin/less, ? and /, I find the Splunk web interface pretty confusing. ...
by dgarstang Engager in Splunk Search 10-31-2010
1 1
1
1
jhedgpeth
I'm really frustrated and need a sanity check on what I'm doing. I've got an indexer which is deploying apps to seve...
by jhedgpeth Path Finder in Splunk Search 10-31-2010
0 4
0
4
NK_1
I would like to do a "stats distinct_count(accountID)" However, some code modules log "accountID=xxxx", while others...
by NK_1 Path Finder in Splunk Search 10-29-2010
1 1
1
1
briang67
Hello, I have an app where I'm splunking a sales price of an item that fluctuates throughout the day. Is there a way...
by briang67 Communicator in Splunk Search 10-29-2010
0 3
0
3
cooperuk
I have imported a file which has more than one time and date field, splunk is using one of them, however I would like...
by cooperuk New Member in Splunk Search 10-29-2010
0 4
0
4
Ant1D
Hey, I have written the following code for a form: <form> <label>Combo box test</label> <!-- <...
by Ant1D Motivator in Splunk Search 10-29-2010
0 1
0
1
jhedgpeth
I'm trying to send certain events ("IdcServerThread" stuff) to nullQueue unless there's a specific pattern in it (the...
by jhedgpeth Path Finder in Splunk Search 10-28-2010
1 1
1
1
ajay_hbo
Hi I am trying to create an index on the command line as follows (splunk 4.1.4) ./bin/splunk add index indexname -dir...
by ajay_hbo Engager in Splunk Search 10-28-2010
1 2
1
2
jambajuice
What is the "stash" sourcetype used for in the application? We're getting two huge spikes of events from that source...
by jambajuice Communicator in Splunk Search 10-28-2010
0 3
0
3
simuvid
Hi all, I want to do following task with Splunk: I want to monitor and audit if a user or customer touches an Oracl...
by simuvid Splunk Employee Splunk Employee in Splunk Search 10-28-2010
0 3
0
3
the_wolverine
Seeing the following error in LWF splunkd.log every 5 minutes: 10-28-2010 08:37:37.048 WARN NetUtils - PollableDesc...
by the_wolverine Champion in Splunk Search 10-28-2010
0 1
0
1
hjwang
Hello,i would like to search the specific ip attack events within the specific time range for real time,e.g. if the a...
by hjwang Contributor in Splunk Search 10-28-2010
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...