Splunk Search

Splunk Search
Community Activity
cdavidy
I have a need to automatically roll data completely out of an index so that it's no longer searchable after a number ...
by cdavidy Explorer in Splunk Search 11-05-2010
1 4
1
4
David
If I have an eventtype with a duration=X seconds field, I can chart the concurrency with eventtype=ABC | concurrency ...
by David Splunk Employee Splunk Employee in Splunk Search 11-04-2010
1 6
1
6
katalinali
I would like to calculate the availability(i.e. duration/total time * 100) of device. I get the uptime time duration ...
by katalinali Path Finder in Splunk Search 11-04-2010
2 1
2
1
fedevietti
Dear All, I'm doing a search with a summarize count at the end. The search is the following: (eventtype="searchVPN"...
by fedevietti New Member in Splunk Search 11-04-2010
0 2
0
2
blurblebot
This is killing me. I'm trying to sum the bytes crossing my boundary in each direction. For TCP sessions, I have a ...
by blurblebot Communicator in Splunk Search 11-04-2010
1 7
1
7
flora123
Hello ALL! x=-241 eval final_x=tostring(x,"commas") It shows [-,241], but it should be [-241]. How could I show t...
by flora123 Path Finder in Splunk Search 11-04-2010
2 4
2
4
gnovak
Hello, I've read through some of the other questions on here to try and find an answer to my question, but i'm still...
by gnovak Builder in Splunk Search 11-03-2010
1 4
1
4
mpatnode
Why do I get this message? Assuming implicit lookup table with filename sidtodn.csv It seemed to me that I was f...
by mpatnode Path Finder in Splunk Search 11-03-2010
0 2
0
2
jkoepsell
Hello, When performing a search, can Splunk perform a DB2 database lookup of uncollected user data, associate it wit...
by jkoepsell Engager in Splunk Search 11-03-2010
1 1
1
1
parallaxed
Since the rewrite of the tailing processor in 4.1, on the whole it seems much better than previous incarnations, but ...
by parallaxed Path Finder in Splunk Search 11-03-2010
0 5
0
5
rsimmons
The Search Inspector indicated that the cursorTime in the year 2038. What does this mean? example from search job in...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 1
1
1
ndoshi
I would like to relate 2 different sourcetypes with a common value for a field. The fields are named differently in e...
by ndoshi Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 2
1
2
Steve_G_
Trying to understand exactly how directory recursion works in inputs.conf. Specifically, how does /foo/.../.../.log...
by Steve_G_ Splunk Employee Splunk Employee in Splunk Search 11-02-2010
1 1
1
1
tmeader
I've currently got a summary search setup going against DNS query data that I use to produce a reporting chart of the...
by tmeader Contributor in Splunk Search 11-01-2010
0 5
0
5
grio
sourcetype=A earliest=10/21/2010:09:0:0 latest=10/21/2010:09:02:0 OR sourcetype=listener earliest=10/21/2010:08:59:0 ...
by grio Engager in Splunk Search 10-31-2010
0 2
0
2
rbbelen
running a this query: splunk search "0e47015c-052f-4235-a25c-cbf3662371ee", returns this... [10/5/10 8:45:01:521 CDT...
by rbbelen New Member in Splunk Search 10-31-2010
0 4
0
4
dgarstang
As an admin that's used to searching logs with /bin/less, ? and /, I find the Splunk web interface pretty confusing. ...
by dgarstang Engager in Splunk Search 10-31-2010
1 1
1
1
jhedgpeth
I'm really frustrated and need a sanity check on what I'm doing. I've got an indexer which is deploying apps to seve...
by jhedgpeth Path Finder in Splunk Search 10-31-2010
0 4
0
4
NK_1
I would like to do a "stats distinct_count(accountID)" However, some code modules log "accountID=xxxx", while others...
by NK_1 Path Finder in Splunk Search 10-29-2010
1 1
1
1
briang67
Hello, I have an app where I'm splunking a sales price of an item that fluctuates throughout the day. Is there a way...
by briang67 Communicator in Splunk Search 10-29-2010
0 3
0
3
cooperuk
I have imported a file which has more than one time and date field, splunk is using one of them, however I would like...
by cooperuk New Member in Splunk Search 10-29-2010
0 4
0
4
Ant1D
Hey, I have written the following code for a form: <form> <label>Combo box test</label> <!-- <...
by Ant1D Motivator in Splunk Search 10-29-2010
0 1
0
1
jhedgpeth
I'm trying to send certain events ("IdcServerThread" stuff) to nullQueue unless there's a specific pattern in it (the...
by jhedgpeth Path Finder in Splunk Search 10-28-2010
1 1
1
1
ajay_hbo
Hi I am trying to create an index on the command line as follows (splunk 4.1.4) ./bin/splunk add index indexname -dir...
by ajay_hbo Engager in Splunk Search 10-28-2010
1 2
1
2
jambajuice
What is the "stash" sourcetype used for in the application? We're getting two huge spikes of events from that source...
by jambajuice Communicator in Splunk Search 10-28-2010
0 3
0
3
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...
Top Solution Authors