Splunk Search

Splunk Search
Community Activity
snowmizer
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by snowmizer Communicator in Splunk Search 11-18-2010
2 5
2
5
msarro
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by msarro Builder in Splunk Search 11-17-2010
2 11
2
11
skippylou
Couldn't see to find a question like this here, but maybe my search for it is no good. What I'd like to do is have a...
by skippylou Communicator in Splunk Search 11-17-2010
1 2
1
2
Marinus
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by Marinus Communicator in Splunk Search 11-17-2010
4 5
4
5
blurblebot
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by blurblebot Communicator in Splunk Search 11-17-2010
1 3
1
3
wmwilson01
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few ...
by wmwilson01 Engager in Splunk Search 11-17-2010
2 2
2
2
sanju005ind
I would like to find All Users that have not logged in for 90 days ans active scheduled searches associated with th...
by sanju005ind Communicator in Splunk Search 11-16-2010
0 1
0
1
flora123
Hi,all I want to use "substr" to get what I want. A=1420014 ... |eval A=if(substr(A, 1,2)="14",replace(A, "14", "0...
by flora123 Path Finder in Splunk Search 11-16-2010
1 2
1
2
sanju005ind
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac. I am ab...
by sanju005ind Communicator in Splunk Search 11-15-2010
0 3
0
3
fedevietti
Dear All, I'm doing a search as the following: sourcetype="sophos" pmx_action="keep" fur!="none"| bucket span=24h _...
by fedevietti New Member in Splunk Search 11-13-2010
0 3
0
3
patrickbass
I want to search my firewall log for tcp denials from the outside on port 22. So far, I have this: "deny tcp source...
by patrickbass New Member in Splunk Search 11-13-2010
0 1
0
1
nbcohen
Appreciate the answer to my original question, but it leads me to a couple of additional issues: 0) As I write this,...
by nbcohen Explorer in Splunk Search 11-12-2010
0 2
0
2
Simeon
I have an extracted field called ruby_completed_call, that extracts the completion time from a ruby log: Processing ...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-11-2010
1 2
1
2
wang
I have a log statement that looks list this: ipAddress=1.2.3.4,userId=42,productId=24 Currently I manually first sea...
by wang Path Finder in Splunk Search 11-11-2010
0 1
0
1
sfmandmdev
I have this query- index=myIndex logRecordTypeX=1 (logName="abc" OR logName="def" OR logName="ghi" OR logName="jkl"...
by sfmandmdev Path Finder in Splunk Search 11-10-2010
0 2
0
2
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 4
0
4
tedder
The following tells me how many events I'm indexing every 5 minutes. index="_internal" group="thruput" | bucket _tim...
by tedder Communicator in Splunk Search 11-10-2010
0 1
0
1
frussell
As a system administrator, sometime I only need to know a rough idea of how many times something occurred. For exampl...
by frussell New Member in Splunk Search 11-09-2010
0 1
0
1
nbcohen
I am a brand new Splunk user - could use a couple of pointers getting started on reporting... I have a dataset that ...
by nbcohen Explorer in Splunk Search 11-09-2010
0 1
0
1
goat
I'm trying to get a monthly event count for all indexed data on a splunk server. I've searched on how to do it, but I...
by goat Explorer in Splunk Search 11-09-2010
2 4
2
4
Simeon
I am trying to extract field and key/value parameters from a ruby on rails log file. What ways can I do this? My e...
by Simeon Splunk Employee Splunk Employee in Splunk Search 11-08-2010
1 1
1
1
kholleran
Hello, I need to monitor a handful of application directories and system32 for changes. I utilized FSChange with re...
by kholleran Communicator in Splunk Search 11-08-2010
0 2
0
2
wang
When using subsearch, What is the scope of the outer search? Is the outer search executed against the result set of ...
by wang Path Finder in Splunk Search 11-08-2010
0 1
0
1
pinzer
Hi all, i need to take the avg of Size by day. sourcetype="sophos" pmx_action="keep" fur!="none"| bucket _time span...
by pinzer Path Finder in Splunk Search 11-08-2010
0 1
0
1
afont
Hi, I want to use the search results as an argument for another search (with different source), like this more or le...
by afont New Member in Splunk Search 11-08-2010
0 3
0
3
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors