Splunk Search

Splunk Search
Community Activity
seanlon11
I am trying to create a table (and then a report) of all exceptions/errors that occur for a given sourcetype. The p...
by seanlon11 Path Finder in Splunk Search 11-19-2010
0 2
0
2
David
I have a set of data that has one event for ever second, with a field for the number of simultaneous phone calls goin...
by David Splunk Employee Splunk Employee in Splunk Search 11-19-2010
1 2
1
2
fisk12
I have syslog from a server sending me logs from /var/log/secure (ssh). But splunk can't seem to read out some stuff ...
by fisk12 Path Finder in Splunk Search 11-19-2010
0 3
0
3
Anvita
How to use rex in searchTemplate while form creation? When i try to use following search using rex, it gives me "Inva...
by Anvita Explorer in Splunk Search 11-19-2010
1 2
1
2
grio
Hi,all index=C (sourcetype=A earliest=-3d latest=-2d) OR earliest=-3d latest=now sourcetype=B |transaction keepevict...
by grio Engager in Splunk Search 11-19-2010
0 2
0
2
msarro
I'm trying to get a time prefix working for the following event: 00:13:11:ee:b7:5e~00:13:11:ee:b7:5d~123.net~123.net...
by msarro Builder in Splunk Search 11-18-2010
1 1
1
1
flora123
Hi , I have three sourcetype. It's a complicated question. I'll try my best to let you understand what I mean. sour...
by flora123 Path Finder in Splunk Search 11-18-2010
1 1
1
1
Eldad
Hi, I am trying to figure out how to achieve something and would appreciate any help from your experience. I have a...
by Eldad Explorer in Splunk Search 11-18-2010
1 1
1
1
msarro
Hey everyone! I am working on files right now that contain numerous timestamps. The timestamps are presented in this ...
by msarro Builder in Splunk Search 11-18-2010
0 2
0
2
JYTTEJ
I need to calculate average response time (ELT) by service (SVC) if number of trx by service is >5 within the last 4 ...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 3
0
3
Ant1D
Hey, I want to switch off what seems to be a default function in Splunk. I am trying to drill down on the following...
by Ant1D Motivator in Splunk Search 11-18-2010
0 2
0
2
bojanz
Hi, I'm working on a problem where Splunk is not displaying (sometimes) all indexed events. The problematic index h...
by bojanz Communicator in Splunk Search 11-18-2010
0 2
0
2
axsolis
I am trying to create a field that contains information about the type of host based on the host field. For example,...
by axsolis Path Finder in Splunk Search 11-18-2010
1 4
1
4
JYTTEJ
I have log entries looking as follows: Nov 16 08:37:47 psdkxt05 MID=xxx005I;XID=;SID=;UID=;STM=2010-11-16 08:37:47,9...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 2
0
2
snowmizer
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by snowmizer Communicator in Splunk Search 11-18-2010
2 5
2
5
msarro
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by msarro Builder in Splunk Search 11-17-2010
2 11
2
11
skippylou
Couldn't see to find a question like this here, but maybe my search for it is no good. What I'd like to do is have a...
by skippylou Communicator in Splunk Search 11-17-2010
1 2
1
2
Marinus
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by Marinus Communicator in Splunk Search 11-17-2010
4 5
4
5
blurblebot
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by blurblebot Communicator in Splunk Search 11-17-2010
1 3
1
3
wmwilson01
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few ...
by wmwilson01 Engager in Splunk Search 11-17-2010
2 2
2
2
sanju005ind
I would like to find All Users that have not logged in for 90 days ans active scheduled searches associated with th...
by sanju005ind Communicator in Splunk Search 11-16-2010
0 1
0
1
flora123
Hi,all I want to use "substr" to get what I want. A=1420014 ... |eval A=if(substr(A, 1,2)="14",replace(A, "14", "0...
by flora123 Path Finder in Splunk Search 11-16-2010
1 2
1
2
sanju005ind
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac. I am ab...
by sanju005ind Communicator in Splunk Search 11-15-2010
0 3
0
3
fedevietti
Dear All, I'm doing a search as the following: sourcetype="sophos" pmx_action="keep" fur!="none"| bucket span=24h _...
by fedevietti New Member in Splunk Search 11-13-2010
0 3
0
3
patrickbass
I want to search my firewall log for tcp denials from the outside on port 22. So far, I have this: "deny tcp source...
by patrickbass New Member in Splunk Search 11-13-2010
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors