Splunk Search

Splunk Search
Community Activity
JYTTEJ
I have log entries looking as follows: Nov 16 08:37:47 psdkxt05 MID=xxx005I;XID=;SID=;UID=;STM=2010-11-16 08:37:47,9...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 2
0
2
snowmizer
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by snowmizer Communicator in Splunk Search 11-18-2010
2 5
2
5
msarro
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by msarro Builder in Splunk Search 11-17-2010
2 11
2
11
skippylou
Couldn't see to find a question like this here, but maybe my search for it is no good. What I'd like to do is have a...
by skippylou Communicator in Splunk Search 11-17-2010
1 2
1
2
Marinus
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by Marinus Communicator in Splunk Search 11-17-2010
4 5
4
5
blurblebot
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by blurblebot Communicator in Splunk Search 11-17-2010
1 3
1
3
wmwilson01
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few ...
by wmwilson01 Engager in Splunk Search 11-17-2010
2 2
2
2
sanju005ind
I would like to find All Users that have not logged in for 90 days ans active scheduled searches associated with th...
by sanju005ind Communicator in Splunk Search 11-16-2010
0 1
0
1
flora123
Hi,all I want to use "substr" to get what I want. A=1420014 ... |eval A=if(substr(A, 1,2)="14",replace(A, "14", "0...
by flora123 Path Finder in Splunk Search 11-16-2010
1 2
1
2
sanju005ind
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac. I am ab...
by sanju005ind Communicator in Splunk Search 11-15-2010
0 3
0
3
fedevietti
Dear All, I'm doing a search as the following: sourcetype="sophos" pmx_action="keep" fur!="none"| bucket span=24h _...
by fedevietti New Member in Splunk Search 11-13-2010
0 3
0
3
patrickbass
I want to search my firewall log for tcp denials from the outside on port 22. So far, I have this: "deny tcp source...
by patrickbass New Member in Splunk Search 11-13-2010
0 1
0
1
nbcohen
Appreciate the answer to my original question, but it leads me to a couple of additional issues: 0) As I write this,...
by nbcohen Explorer in Splunk Search 11-12-2010
0 2
0
2
Simeon
I have an extracted field called ruby_completed_call, that extracts the completion time from a ruby log: Processing ...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-11-2010
1 2
1
2
wang
I have a log statement that looks list this: ipAddress=1.2.3.4,userId=42,productId=24 Currently I manually first sea...
by wang Path Finder in Splunk Search 11-11-2010
0 1
0
1
sfmandmdev
I have this query- index=myIndex logRecordTypeX=1 (logName="abc" OR logName="def" OR logName="ghi" OR logName="jkl"...
by sfmandmdev Path Finder in Splunk Search 11-10-2010
0 2
0
2
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 4
0
4
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 1
0
1
frussell
As a system administrator, sometime I only need to know a rough idea of how many times something occurred. For exampl...
by frussell New Member in Splunk Search 11-09-2010
0 1
0
1
nbcohen
I am a brand new Splunk user - could use a couple of pointers getting started on reporting... I have a dataset that ...
by nbcohen Explorer in Splunk Search 11-09-2010
0 1
0
1
goat
I'm trying to get a monthly event count for all indexed data on a splunk server. I've searched on how to do it, but I...
by goat Explorer in Splunk Search 11-09-2010
2 4
2
4
Simeon
I am trying to extract field and key/value parameters from a ruby on rails log file. What ways can I do this? My e...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-08-2010
1 1
1
1
kholleran
Hello, I need to monitor a handful of application directories and system32 for changes. I utilized FSChange with re...
by kholleran Communicator in Splunk Search 11-08-2010
0 2
0
2
wang
When using subsearch, What is the scope of the outer search? Is the outer search executed against the result set of ...
by wang Path Finder in Splunk Search 11-08-2010
0 1
0
1
pinzer
Hi all, i need to take the avg of Size by day. sourcetype="sophos" pmx_action="keep" fur!="none"| bucket _time span...
by pinzer Path Finder in Splunk Search 11-08-2010
0 1
0
1
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...