Thread Info | |||||
---|---|---|---|---|---|
For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table",...
by
William
Path Finder
in
Splunk Search
04-06-2010
|
0
|
3
| |||
We've got log events that read like the following:
Mar 14 12:26:38 mailsrv.example.com MM: [Jilter Processor 21 - ...
by
smisplunk
Path Finder
in
Splunk Search
05-06-2010
|
1
|
7
| |||
Hi All,
I need a sanity check. This extraction seemed to work in 4.0, Can someone help? mac_address and source_ip ...
by
dcroteau
Splunk Employee
in
Splunk Search
05-14-2010
|
0
|
4
| |||
Running this search:
http://host1.com:8000/en-US/app/search/flashtimeline?q=search%20* | regex_raw%3D%22%25SYS-5-C...
by
Jaci
Splunk Employee
in
Splunk Search
05-25-2010
|
3
|
2
| |||
I am trying to setup a scheduled search that runs every morning and looks for users logged on between 2200 the previo...
by
Mike_Spellane
New Member
in
Splunk Search
05-27-2010
|
0
|
2
| |||
I am having trouble getting my form search to bring back anything. The xml is accepted by splunk but the search won't...
by
riderofyamaha
Explorer
in
Splunk Search
05-27-2010
|
0
|
2
| |||
I need help with a query to find the forwarders which stopped reporting for more than 2 weeks.
by
sanju005ind
Communicator
in
Splunk Search
05-26-2010
|
0
|
4
| |||
I've been able to get AmMap to work with scheduled searches. Is there a way to get it to work in realtime? I thought ...
by
jjernigan
Engager
in
Splunk Search
05-26-2010
|
2
|
1
| |||
I'm running Splunk 4.1.2. It seems that when Splunk sends out URL that correspond to searches (say when it triggers a...
by
mfrost8
Builder
in
Splunk Search
05-27-2010
|
1
|
2
| |||
can I get transaction to show hostname or sourcetype for each event within? I'd like to be able to pass a transaction...
by
bfaber
Communicator
in
Splunk Search
04-29-2010
|
0
|
5
| |||
In inputs.conf and props.conf, the wildcards ... and * are supported for use in the spec headers. What do they transl...
by
hulahoop
Splunk Employee
in
Splunk Search
02-19-2010
|
2
|
3
| |||
While the following extraction below works, I wanted to see if I could extract both custom fields EAR_FILE and DOMAIN...
by
Rob_Jordan
Explorer
in
Splunk Search
05-26-2010
|
2
|
2
| |||
When searching for lost forwarders a host with an all caps name is returned as lost when the same host with a lower c...
by
rgcox1
Communicator
in
Splunk Search
05-13-2010
|
0
|
3
| |||
If I have data like this:
src=1.1.1.1 dst=2.2.2.2
can I create a mvfield of ip's? like:
ips=1.1.1.1,2.2.2.2...
by
bfaber
Communicator
in
Splunk Search
05-25-2010
|
1
|
2
| |||
If I have data that looks like
(date) srcip=x.x.x.x dstip=y.y.y.y
How can I create a single list of all unique...
by
bfaber
Communicator
in
Splunk Search
05-25-2010
|
1
|
6
| |||
Is there a way to report on the position of an event relative to the rest of the events in the result set?
For exa...
by
maverick
Splunk Employee
in
Splunk Search
05-22-2010
|
0
|
2
| |||
How can I use lookups for a source CSV file that is not under the Splunk code tree?
I am using Splunk 4.0.10. CSV ...
by
nbharadwaj
Path Finder
in
Splunk Search
05-24-2010
|
1
|
1
| |||
We were on 3.4.6 and I think subsearches worked fine. We upgraded to 4.0.10 and they broke. So I upgraded to 4.1.1, a...
by
Genti
Splunk Employee
in
Splunk Search
05-21-2010
|
1
|
4
| |||
Hi all,
I've got a problem with the execution of this command from a Windows ".bat" script:
splunk.exe search "...
by
logicasrl
Explorer
in
Splunk Search
05-18-2010
|
0
|
8
| |||
Hi,
I've created the following field extraction and field transform in their respective files - props.conf and tra...
by
sidafydd
New Member
in
Splunk Search
05-21-2010
|
0
|
3
| |||
Hi All,
I am using splunk to analyse squid logs and my goal is to identify how many minutes of the day a client ip...
by
sflisher
Explorer
in
Splunk Search
05-20-2010
|
0
|
4
| |||
I have a data source where all events get logged in hour intervals. There could be several hundred thousand events pe...
by
stephanbuys
Path Finder
in
Splunk Search
05-11-2010
|
0
|
3
| |||
I have a macro that accepts 5 arguments. I was hoping to get the arguments into the macro from a previous search resu...
by
jwestberg
Splunk Employee
in
Splunk Search
05-21-2010
|
0
|
1
| |||
I have created regular expressions (regex) to extract fields and want to know what syntax style Splunk supports.
by
Simeon
Splunk Employee
in
Splunk Search
05-20-2010
|
1
|
2
| |||
Hi, my first question here so sorry if I use some stange terminology, I'll try and be as concise as I can!
To star...
by
Skippy
Explorer
in
Splunk Search
05-10-2010
|
2
|
2
|