Splunk Search

Splunk Search
Community Activity
Anvita
How to use rex in searchTemplate while form creation? When i try to use following search using rex, it gives me "Inva...
by Anvita Explorer in Splunk Search 11-19-2010
1 2
1
2
grio
Hi,all index=C (sourcetype=A earliest=-3d latest=-2d) OR earliest=-3d latest=now sourcetype=B |transaction keepevict...
by grio Engager in Splunk Search 11-19-2010
0 2
0
2
msarro
I'm trying to get a time prefix working for the following event: 00:13:11:ee:b7:5e~00:13:11:ee:b7:5d~123.net~123.net...
by msarro Builder in Splunk Search 11-18-2010
1 1
1
1
flora123
Hi , I have three sourcetype. It's a complicated question. I'll try my best to let you understand what I mean. sour...
by flora123 Path Finder in Splunk Search 11-18-2010
1 1
1
1
Eldad
Hi, I am trying to figure out how to achieve something and would appreciate any help from your experience. I have a...
by Eldad Explorer in Splunk Search 11-18-2010
1 1
1
1
msarro
Hey everyone! I am working on files right now that contain numerous timestamps. The timestamps are presented in this ...
by msarro Builder in Splunk Search 11-18-2010
0 2
0
2
JYTTEJ
I need to calculate average response time (ELT) by service (SVC) if number of trx by service is >5 within the last 4 ...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 3
0
3
Ant1D
Hey, I want to switch off what seems to be a default function in Splunk. I am trying to drill down on the following...
by Ant1D Motivator in Splunk Search 11-18-2010
0 2
0
2
bojanz
Hi, I'm working on a problem where Splunk is not displaying (sometimes) all indexed events. The problematic index h...
by bojanz Communicator in Splunk Search 11-18-2010
0 2
0
2
axsolis
I am trying to create a field that contains information about the type of host based on the host field. For example,...
by axsolis Path Finder in Splunk Search 11-18-2010
1 4
1
4
JYTTEJ
I have log entries looking as follows: Nov 16 08:37:47 psdkxt05 MID=xxx005I;XID=;SID=;UID=;STM=2010-11-16 08:37:47,9...
by JYTTEJ Communicator in Splunk Search 11-18-2010
0 2
0
2
snowmizer
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by snowmizer Communicator in Splunk Search 11-18-2010
2 5
2
5
msarro
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by msarro Builder in Splunk Search 11-17-2010
2 11
2
11
skippylou
Couldn't see to find a question like this here, but maybe my search for it is no good. What I'd like to do is have a...
by skippylou Communicator in Splunk Search 11-17-2010
1 2
1
2
Marinus
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by Marinus Communicator in Splunk Search 11-17-2010
4 5
4
5
blurblebot
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by blurblebot Communicator in Splunk Search 11-17-2010
1 3
1
3
wmwilson01
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few ...
by wmwilson01 Engager in Splunk Search 11-17-2010
2 2
2
2
sanju005ind
I would like to find All Users that have not logged in for 90 days ans active scheduled searches associated with th...
by sanju005ind Communicator in Splunk Search 11-16-2010
0 1
0
1
flora123
Hi,all I want to use "substr" to get what I want. A=1420014 ... |eval A=if(substr(A, 1,2)="14",replace(A, "14", "0...
by flora123 Path Finder in Splunk Search 11-16-2010
1 2
1
2
sanju005ind
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac. I am ab...
by sanju005ind Communicator in Splunk Search 11-15-2010
0 3
0
3
fedevietti
Dear All, I'm doing a search as the following: sourcetype="sophos" pmx_action="keep" fur!="none"| bucket span=24h _...
by fedevietti New Member in Splunk Search 11-13-2010
0 3
0
3
patrickbass
I want to search my firewall log for tcp denials from the outside on port 22. So far, I have this: "deny tcp source...
by patrickbass New Member in Splunk Search 11-13-2010
0 1
0
1
nbcohen
Appreciate the answer to my original question, but it leads me to a couple of additional issues: 0) As I write this,...
by nbcohen Explorer in Splunk Search 11-12-2010
0 2
0
2
Simeon
I have an extracted field called ruby_completed_call, that extracts the completion time from a ruby log: Processing ...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-11-2010
1 2
1
2
wang
I have a log statement that looks list this: ipAddress=1.2.3.4,userId=42,productId=24 Currently I manually first sea...
by wang Path Finder in Splunk Search 11-11-2010
0 1
0
1
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...