Splunk Search

Splunk Search
Community Activity
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 4
0
4
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 1
0
1
frussell
As a system administrator, sometime I only need to know a rough idea of how many times something occurred. For exampl...
by frussell New Member in Splunk Search 11-09-2010
0 1
0
1
nbcohen
I am a brand new Splunk user - could use a couple of pointers getting started on reporting... I have a dataset that ...
by nbcohen Explorer in Splunk Search 11-09-2010
0 1
0
1
goat
I'm trying to get a monthly event count for all indexed data on a splunk server. I've searched on how to do it, but I...
by goat Explorer in Splunk Search 11-09-2010
2 4
2
4
Simeon
I am trying to extract field and key/value parameters from a ruby on rails log file. What ways can I do this? My e...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-08-2010
1 1
1
1
kholleran
Hello, I need to monitor a handful of application directories and system32 for changes. I utilized FSChange with re...
by kholleran Communicator in Splunk Search 11-08-2010
0 2
0
2
wang
When using subsearch, What is the scope of the outer search? Is the outer search executed against the result set of ...
by wang Path Finder in Splunk Search 11-08-2010
0 1
0
1
pinzer
Hi all, i need to take the avg of Size by day. sourcetype="sophos" pmx_action="keep" fur!="none"| bucket _time span...
by pinzer Path Finder in Splunk Search 11-08-2010
0 1
0
1
afont
Hi, I want to use the search results as an argument for another search (with different source), like this more or le...
by afont New Member in Splunk Search 11-08-2010
0 3
0
3
RobertRi
Hi I'm using 4.1 and I want to translate an ID, which came from a search result, into a Name from an importet csv fi...
by RobertRi Communicator in Splunk Search 11-08-2010
0 3
0
3
zscgeek
I am trying to build a timechart that includes the avg rate we pay our carrier per min over time. The issue is for me...
by zscgeek Path Finder in Splunk Search 11-06-2010
1 8
1
8
jginnetty
Currently working on a IIS log file with standard fields. I’m looking to first determine the unique Usernames contain...
by jginnetty Explorer in Splunk Search 11-05-2010
1 4
1
4
cdavidy
I have a need to automatically roll data completely out of an index so that it's no longer searchable after a number ...
by cdavidy Explorer in Splunk Search 11-05-2010
1 4
1
4
David
If I have an eventtype with a duration=X seconds field, I can chart the concurrency with eventtype=ABC | concurrency ...
by David Splunk Employee Splunk Employee in Splunk Search 11-04-2010
1 6
1
6
katalinali
I would like to calculate the availability(i.e. duration/total time * 100) of device. I get the uptime time duration ...
by katalinali Path Finder in Splunk Search 11-04-2010
2 1
2
1
fedevietti
Dear All, I'm doing a search with a summarize count at the end. The search is the following: (eventtype="searchVPN"...
by fedevietti New Member in Splunk Search 11-04-2010
0 2
0
2
blurblebot
This is killing me. I'm trying to sum the bytes crossing my boundary in each direction. For TCP sessions, I have a ...
by blurblebot Communicator in Splunk Search 11-04-2010
1 7
1
7
flora123
Hello ALL! x=-241 eval final_x=tostring(x,"commas") It shows [-,241], but it should be [-241]. How could I show t...
by flora123 Path Finder in Splunk Search 11-04-2010
2 4
2
4
gnovak
Hello, I've read through some of the other questions on here to try and find an answer to my question, but i'm still...
by gnovak Builder in Splunk Search 11-03-2010
1 4
1
4
mpatnode
Why do I get this message? Assuming implicit lookup table with filename sidtodn.csv It seemed to me that I was f...
by mpatnode Path Finder in Splunk Search 11-03-2010
0 2
0
2
jkoepsell
Hello, When performing a search, can Splunk perform a DB2 database lookup of uncollected user data, associate it wit...
by jkoepsell Engager in Splunk Search 11-03-2010
1 1
1
1
parallaxed
Since the rewrite of the tailing processor in 4.1, on the whole it seems much better than previous incarnations, but ...
by parallaxed Path Finder in Splunk Search 11-03-2010
0 5
0
5
rsimmons
The Search Inspector indicated that the cursorTime in the year 2038. What does this mean? example from search job in...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 1
1
1
ndoshi
I would like to relate 2 different sourcetypes with a common value for a field. The fields are named differently in e...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 2
1
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...