Splunk Search

Splunk Search
Community Activity
gallantalex
Hi I am having a problem searching an xml formated event. So basically I have an event that looks like this: <?xml v...
by gallantalex Path Finder in Splunk Search 10-19-2010
1 6
1
6
bitbuck3t
I have created a directory to store log files that I pull from a remote machine. I use a cronjob to pull every x min...
by bitbuck3t New Member in Splunk Search 10-19-2010
0 2
0
2
dmlee
as Title , I have many events older than 1970/1/1 , Splunk doesn't index those events (I have modified max_days_ago=1...
by dmlee Communicator in Splunk Search 10-19-2010
2 3
2
3
wildbill4
I'm trying to setup Fieldalias and not getting desire results. Here is what I have put into the props.conf file. ...
by wildbill4 Path Finder in Splunk Search 10-19-2010
1 5
1
5
cramasta
Hi, I have the following | chart eval(sum(Failed)/sum(TotalEvents)*100) AS PercentFailed I would like to round the...
by cramasta Builder in Splunk Search 10-18-2010
3 2
3
2
Starlette
I am monitoring a dir with rotating logs, ( fi /depot/logs/ ) how can I control the source name, and avoid zillions o...
by Starlette Contributor in Splunk Search 10-18-2010
1 6
1
6
pj
I have an odd issue occurring. Essentially I have a high volume log source which is getting picked up by a Splunk for...
by pj Contributor in Splunk Search 10-18-2010
0 4
0
4
pinzer
Hi all , i'm working on this query: sourcetype="webseal_access" OR sourcetype="wmi:wineventlog:security" | rename So...
by pinzer Path Finder in Splunk Search 10-18-2010
0 1
0
1
leo_wang
As title. I want to design a search page that showing the search results ( like flashtimeline ) and one or two stati...
by leo_wang Path Finder in Splunk Search 10-15-2010
1 1
1
1
sideview
I have a situation where I have two multi-valued fields in my data, and i want to call mvexpand on ONE of the fields ...
by SplunkTrust SplunkTrust in Splunk Search 10-15-2010
2 1
2
1
Simeon
I am running the dedup command for my ip_address field and I want to know the value returned by the command. Is it t...
by Simeon Splunk Employee Splunk Employee in Splunk Search 10-15-2010
2 1
2
1
thinman
Hi, I have three files having similar information, namely: First Names, Second Names, Identification number, so I ne...
by thinman Explorer in Splunk Search 10-14-2010
0 3
0
3
pinzer
Hi all, i need to take the events from this search sourcetype="wmi:wineventlog:security" that have the field Sourc...
by pinzer Path Finder in Splunk Search 10-14-2010
0 1
0
1
Keith_Holme
I would like to execute an .exe or .bat file on a windows box and use the stdout as the results in a search. How can ...
by Keith_Holme Engager in Splunk Search 10-14-2010
0 2
0
2
melonman
Hi there, I have a chart that takes 15+ sec to draw area graph after loading completed. Loading data can be tuned by...
by melonman Motivator in Splunk Search 10-14-2010
0 3
0
3
feniix
Hello, I am building a small splunk app and I have a dashboard that has many tables with inline searches like this: ...
by feniix New Member in Splunk Search 10-14-2010
0 1
0
1
mjohanne
I am trying to transform the source field from using Unix path separator (/) to Windows path separator (\). For exam...
by mjohanne Explorer in Splunk Search 10-13-2010
1 4
1
4
gnovak
I've read over documentation with inputs.conf and was wondering if I have the correct solution to this issue. On man...
by gnovak Builder in Splunk Search 10-13-2010
2 11
2
11
jsanio
Splunkers... I have dug thru the Answers Area for quite some time, and have not found what I am looking for. I am thi...
by jsanio New Member in Splunk Search 10-13-2010
0 2
0
2
piebob
if i create a custom search command as described in http://www.splunk.com/base/Documentation/latest/SearchReference/...
by piebob Splunk Employee Splunk Employee in Splunk Search 10-13-2010
4 4
4
4
wollinet
I'm trying to write a custom event renderer for an event type. I want to change the event display to a single field o...
by wollinet Path Finder in Splunk Search 10-13-2010
1 2
1
2
mjtung
How do I properly count fields which repeat in each event? Here is a sample event: 2885136 2010-10-04 03:55:35.997 ...
by mjtung Explorer in Splunk Search 10-12-2010
1 5
1
5
wys2010
Here is a question from our customer. It is how many Events can splunk eat per second. I read the manual book which ...
by wys2010 New Member in Splunk Search 10-12-2010
0 3
0
3
hjwang
I'v just replaced the default theme of search apps with the desert theme downloading from the splunk web site, but i ...
by hjwang Contributor in Splunk Search 10-12-2010
0 1
0
1
alange
I have a logfile with two different date formats for entries. Unfortunately, the dates written to the logfile are "u...
by alange Explorer in Splunk Search 10-11-2010
1 1
1
1
Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...