| The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim... by tedder Communicator in Splunk Search 11-10-2010 0 4 | 0 | 4 | ||
| The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim... by tedder Communicator in Splunk Search 11-10-2010 0 1 | 0 | 1 | ||
| As a system administrator, sometime I only need to know a rough idea of how many times something occurred. For exampl... by frussell New Member in Splunk Search 11-09-2010 0 1 | 0 | 1 | ||
| I am a brand new Splunk user - could use a couple of pointers getting started on reporting... I have a dataset that ... by nbcohen Explorer in Splunk Search 11-09-2010 0 1 | 0 | 1 | ||
| I'm trying to get a monthly event count for all indexed data on a splunk server. I've searched on how to do it, but I... by goat Explorer in Splunk Search 11-09-2010 2 4 | 2 | 4 | ||
| I am trying to extract field and key/value parameters from a ruby on rails log file. What ways can I do this? My e... by Simeon Splunk Employee 1 1 | 1 | 1 | ||
| Hello, I need to monitor a handful of application directories and system32 for changes. I utilized FSChange with re... by kholleran Communicator in Splunk Search 11-08-2010 0 2 | 0 | 2 | ||
| When using subsearch, What is the scope of the outer search? Is the outer search executed against the result set of ... by wang Path Finder in Splunk Search 11-08-2010 0 1 | 0 | 1 | ||
| Hi all, i need to take the avg of Size by day. sourcetype="sophos" pmx_action="keep" fur!="none"| bucket _time span... by pinzer Path Finder in Splunk Search 11-08-2010 0 1 | 0 | 1 | ||
| Hi, I want to use the search results as an argument for another search (with different source), like this more or le... by afont New Member in Splunk Search 11-08-2010 0 3 | 0 | 3 | ||
| Hi I'm using 4.1 and I want to translate an ID, which came from a search result, into a Name from an importet csv fi... by RobertRi Communicator in Splunk Search 11-08-2010 0 3 | 0 | 3 | ||
| I am trying to build a timechart that includes the avg rate we pay our carrier per min over time. The issue is for me... by zscgeek Path Finder in Splunk Search 11-06-2010 1 8 | 1 | 8 | ||
| Currently working on a IIS log file with standard fields. I’m looking to first determine the unique Usernames contain... by jginnetty Explorer in Splunk Search 11-05-2010 1 4 | 1 | 4 | ||
| I have a need to automatically roll data completely out of an index so that it's no longer searchable after a number ... by cdavidy Explorer in Splunk Search 11-05-2010 1 4 | 1 | 4 | ||
| If I have an eventtype with a duration=X seconds field, I can chart the concurrency with eventtype=ABC | concurrency ... by David Splunk Employee 1 6 | 1 | 6 | ||
| I would like to calculate the availability(i.e. duration/total time * 100) of device. I get the uptime time duration ... by katalinali Path Finder in Splunk Search 11-04-2010 2 1 | 2 | 1 | ||
| Dear All, I'm doing a search with a summarize count at the end. The search is the following: (eventtype="searchVPN"... by fedevietti New Member in Splunk Search 11-04-2010 0 2 | 0 | 2 | ||
| This is killing me. I'm trying to sum the bytes crossing my boundary in each direction. For TCP sessions, I have a ... by blurblebot Communicator in Splunk Search 11-04-2010 1 7 | 1 | 7 | ||
| Hello ALL! x=-241 eval final_x=tostring(x,"commas") It shows [-,241], but it should be [-241]. How could I show t... by flora123 Path Finder in Splunk Search 11-04-2010 2 4 | 2 | 4 | ||
| Hello, I've read through some of the other questions on here to try and find an answer to my question, but i'm still... by gnovak Builder in Splunk Search 11-03-2010 1 4 | 1 | 4 | ||
| Why do I get this message? Assuming implicit lookup table with filename sidtodn.csv It seemed to me that I was f... by mpatnode Path Finder in Splunk Search 11-03-2010 0 2 | 0 | 2 | ||
| Hello, When performing a search, can Splunk perform a DB2 database lookup of uncollected user data, associate it wit... by jkoepsell Engager in Splunk Search 11-03-2010 1 1 | 1 | 1 | ||
| Since the rewrite of the tailing processor in 4.1, on the whole it seems much better than previous incarnations, but ... by parallaxed Path Finder in Splunk Search 11-03-2010 0 5 | 0 | 5 | ||
| The Search Inspector indicated that the cursorTime in the year 2038. What does this mean? example from search job in... by rsimmons Splunk Employee 1 1 | 1 | 1 | ||
| I would like to relate 2 different sourcetypes with a common value for a field. The fields are named differently in e... by ndoshi Splunk Employee 1 2 | 1 | 2 |