Splunk Search

Splunk Search
Community Activity
sideview
I have a situation where I have two multi-valued fields in my data, and i want to call mvexpand on ONE of the fields ...
by SplunkTrust SplunkTrust in Splunk Search 10-15-2010
2 1
2
1
Simeon
I am running the dedup command for my ip_address field and I want to know the value returned by the command. Is it t...
by Simeon Splunk Employee Splunk Employee in Splunk Search 10-15-2010
2 1
2
1
thinman
Hi, I have three files having similar information, namely: First Names, Second Names, Identification number, so I ne...
by thinman Explorer in Splunk Search 10-14-2010
0 3
0
3
pinzer
Hi all, i need to take the events from this search sourcetype="wmi:wineventlog:security" that have the field Sourc...
by pinzer Path Finder in Splunk Search 10-14-2010
0 1
0
1
Keith_Holme
I would like to execute an .exe or .bat file on a windows box and use the stdout as the results in a search. How can ...
by Keith_Holme Engager in Splunk Search 10-14-2010
0 2
0
2
melonman
Hi there, I have a chart that takes 15+ sec to draw area graph after loading completed. Loading data can be tuned by...
by melonman Motivator in Splunk Search 10-14-2010
0 3
0
3
feniix
Hello, I am building a small splunk app and I have a dashboard that has many tables with inline searches like this: ...
by feniix New Member in Splunk Search 10-14-2010
0 1
0
1
mjohanne
I am trying to transform the source field from using Unix path separator (/) to Windows path separator (\). For exam...
by mjohanne Explorer in Splunk Search 10-13-2010
1 4
1
4
gnovak
I've read over documentation with inputs.conf and was wondering if I have the correct solution to this issue. On man...
by gnovak Builder in Splunk Search 10-13-2010
2 11
2
11
jsanio
Splunkers... I have dug thru the Answers Area for quite some time, and have not found what I am looking for. I am thi...
by jsanio New Member in Splunk Search 10-13-2010
0 2
0
2
piebob
if i create a custom search command as described in http://www.splunk.com/base/Documentation/latest/SearchReference/...
by piebob Splunk Employee Splunk Employee in Splunk Search 10-13-2010
4 4
4
4
wollinet
I'm trying to write a custom event renderer for an event type. I want to change the event display to a single field o...
by wollinet Path Finder in Splunk Search 10-13-2010
1 2
1
2
mjtung
How do I properly count fields which repeat in each event? Here is a sample event: 2885136 2010-10-04 03:55:35.997 ...
by mjtung Explorer in Splunk Search 10-12-2010
1 5
1
5
wys2010
Here is a question from our customer. It is how many Events can splunk eat per second. I read the manual book which ...
by wys2010 New Member in Splunk Search 10-12-2010
0 3
0
3
hjwang
I'v just replaced the default theme of search apps with the desert theme downloading from the splunk web site, but i ...
by hjwang Contributor in Splunk Search 10-12-2010
0 1
0
1
alange
I have a logfile with two different date formats for entries. Unfortunately, the dates written to the logfile are "u...
by alange Explorer in Splunk Search 10-11-2010
1 1
1
1
cramasta
Hi, So I have a flat log file that i am indexing that has two timestamps in the same format. I don't care which one ...
by cramasta Builder in Splunk Search 10-11-2010
1 1
1
1
steveirogers
How can I export the results of a search? I run a search and I get 922 events. I would like to export (or produce a...
by steveirogers Communicator in Splunk Search 10-11-2010
1 2
1
2
kholleran
Hello, I have this search string: source="WinEventLog:Security" EventCode="4625" OR EventCode="539" OR (EventCode>=...
by kholleran Communicator in Splunk Search 10-11-2010
0 2
0
2
Infinity8
Please help I am trying to make a search for a string in the past five minutes and if there are over 100 I want an em...
by Infinity8 New Member in Splunk Search 10-11-2010
0 2
0
2
cfortune
Sorry for spamming this board (or so it feels like) but I have one more question before the weekend. This may not be ...
by cfortune Explorer in Splunk Search 10-11-2010
0 4
0
4
pinzer
stats count by _time Hi all, I've a query where i count by _time but if in a day there aren't events it is not sho...
by pinzer Path Finder in Splunk Search 10-11-2010
0 1
0
1
rickschultz
I could be doing something wrong, but I can't seem to get subsearches to behave like I expect. I can get something l...
by rickschultz New Member in Splunk Search 10-08-2010
0 3
0
3
rhuss
I am new to both Splunk and REGEX. I am trying to filter out syslog data from a single src address. I have the fol...
by rhuss Engager in Splunk Search 10-08-2010
1 2
1
2
blurblebot
How can I take an event with a given key(a)/value(b) pair and find the temporally nearest event with key(c)/value(d)?...
by blurblebot Communicator in Splunk Search 10-08-2010
1 2
1
2
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...