Splunk Search

Splunk Search
Community Activity
Kyle_Brandt
In Windows I have the following in the Inputs.conf: [monitor://C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQ...
by Kyle_Brandt Path Finder in Splunk Search 10-01-2010
0 5
0
5
ericrobinson
I have a search that pipes to another search, and this search is highlighting the results. I do not want the highligh...
by ericrobinson Path Finder in Splunk Search 09-30-2010
10 4
10
4
sideview
I have a dataset where the rows in my search results all have a 'value' field, and there's another field that specif...
by SplunkTrust SplunkTrust in Splunk Search 09-30-2010
5 4
5
4
Brian_Osburn
In order to identify web content that hasn't been pulled in a while, I thought I would use Splunk since a) my Apache ...
by Brian_Osburn Builder in Splunk Search 09-30-2010
3 4
3
4
mattcg
We're trying to set up a dynamic sourcetype extraction at index time. The reason for this is that we have about 40-50...
by mattcg Explorer in Splunk Search 09-30-2010
2 2
2
2
donnylie
I don’t have any background in Telco world, I’m so blank about it, Telco people asked this many times, is it possib...
by donnylie Explorer in Splunk Search 09-30-2010
0 1
0
1
thepocketwade
I just ran a search that returned approximately 1 million results. Only after it completed (which took a bit longer ...
by thepocketwade Path Finder in Splunk Search 09-30-2010
3 2
3
2
adamw
We seem to be having an issue with the postfix_syslog sourcetype (that came as a default sourcetype in Splunk) and it...
by adamw Communicator in Splunk Search 09-30-2010
0 5
0
5
htkhtk
I have jboss logs that print a message size everytime jboss restarts. The message size is different everytime jboss s...
by htkhtk Path Finder in Splunk Search 09-30-2010
0 4
0
4
JohnB
If I do a search for something such as: uri="/this/or/that.html" over, say, an hour. Once the search completes (fina...
by JohnB Explorer in Splunk Search 09-30-2010
0 3
0
3
pmr
Hello, How do i use multikv to extract fields that have % or / in them ? I'm unable to extract if it has those chara...
by pmr Explorer in Splunk Search 09-30-2010
1 2
1
2
klumpba
I have a Splunk app that parses some Snort files and assigns some fields to the content. The app works fine from the...
by klumpba Engager in Splunk Search 09-29-2010
4 3
4
3
hexx
When I use the "diff" search command to compare events that contain several hundred lines, I notice that differences ...
by hexx Splunk Employee Splunk Employee in Splunk Search 09-29-2010
4 2
4
2
leo_wang
I have read the this page about the concept of "Intention" : http://www.splunk.com/base/Splexicon:Intention It say...
by leo_wang Path Finder in Splunk Search 09-29-2010
1 5
1
5
cmeo
I have the following query which almost does what I want: sourcetype="cisco_wsa_squid" | lookup teamlookup cs_userna...
by cmeo Contributor in Splunk Search 09-29-2010
0 4
0
4
clyde772
For the AMMAP application for the map, I followed the instruction and installed MAXMIND and the AMMAP app, but I can'...
by clyde772 Communicator in Splunk Search 09-28-2010
0 6
0
6
Branden
I have a chart in a dashboard that shows a graph of paging space usage across all of our hosts. Or at least that's wh...
by Branden Builder in Splunk Search 09-28-2010
2 2
2
2
pshankland
Hi, I have just installed Splunk as want to get some reports out of a Barracuda Spam firewall we have installed that...
by pshankland New Member in Splunk Search 09-28-2010
0 4
0
4
Nicholas_Key
[1] I would like to know if I can tar an index from a Splunk instance and then untar it into other Splunk instance? ...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 09-28-2010
0 2
0
2
sajbutler
Every 5 minutes, one of our systems dumps out data on connected users. There is one line per connected user as follow...
by sajbutler Path Finder in Splunk Search 09-28-2010
0 7
0
7
mctester
If I do this: index="foo" sourcetype="bar" | sort _time | streamstats dc(userid) as dcusers | delta dcusers as delta...
by mctester Communicator in Splunk Search 09-28-2010
1 3
1
3
cmeo
Is there any way to get popup or lite mode AccountBar WITH the logo clickable? This would be very useful for turning ...
by cmeo Contributor in Splunk Search 09-27-2010
0 1
0
1
pinzer
Hi all, i need to change the color of a bar of the column chart if the value is higher than a number. How can i do th...
by pinzer Path Finder in Splunk Search 09-26-2010
2 1
2
1
kholleran
Hello, I currently am doing a search that uses a unix time as a field. What I want to do, is do something like this...
by kholleran Communicator in Splunk Search 09-26-2010
0 2
0
2
timbCFCA
Within each record in a query I have two fields, c_ip and cs_bytes which is numeric. How can I get the top 10 c_ip v...
by timbCFCA Path Finder in Splunk Search 09-24-2010
1 1
1
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...