Splunk Search

Splunk Search
Community Activity
pinzer
Dear All, I'm doing a search with a set UNION, like this: | SET UNION [SEARCH FOO | FIELDS fields IP, count] [ SEA...
by pinzer Path Finder in Splunk Search 10-04-2010
0 5
0
5
cafissimo
Hello, please, I would like to know if the SEDCMD command is able to change metadata values like host, source and sou...
by cafissimo Communicator in Splunk Search 10-04-2010
1 1
1
1
melonman
Hi there, I need to re-index some data. In inputs.conf, host_segment parameter is configured as follows: host_segm...
by melonman Motivator in Splunk Search 10-02-2010
1 8
1
8
carmackd
Can someone please help me with a regex to extract the host name from a filename. I've got two different file naming...
by carmackd Communicator in Splunk Search 10-01-2010
0 2
0
2
aanetserv
I'm doing a search for invalid logons for our vpn logs. But I want the search results to return when the invalid atte...
by aanetserv New Member in Splunk Search 10-01-2010
0 2
0
2
l0r3zz
I want to gobble in CSV files containing numeric data. Each file will have between 500 and 150,000 fields. (Yes that'...
by l0r3zz New Member in Splunk Search 10-01-2010
0 8
0
8
cudgel
I have the following search which I would like to use to populate a summary index for reporting (run every 30 minutes...
by cudgel Path Finder in Splunk Search 10-01-2010
1 4
1
4
Ant1D
Hey, The answer to this question will be very useful to know  I have an advanced dashboard with a few charts (1 co...
by Ant1D Motivator in Splunk Search 10-01-2010
2 4
2
4
Kyle_Brandt
In Windows I have the following in the Inputs.conf: [monitor://C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQ...
by Kyle_Brandt Path Finder in Splunk Search 10-01-2010
0 5
0
5
ericrobinson
I have a search that pipes to another search, and this search is highlighting the results. I do not want the highligh...
by ericrobinson Path Finder in Splunk Search 09-30-2010
10 4
10
4
sideview
I have a dataset where the rows in my search results all have a 'value' field, and there's another field that specif...
by SplunkTrust SplunkTrust in Splunk Search 09-30-2010
5 4
5
4
Brian_Osburn
In order to identify web content that hasn't been pulled in a while, I thought I would use Splunk since a) my Apache ...
by Brian_Osburn Builder in Splunk Search 09-30-2010
3 4
3
4
mattcg
We're trying to set up a dynamic sourcetype extraction at index time. The reason for this is that we have about 40-50...
by mattcg Explorer in Splunk Search 09-30-2010
2 2
2
2
donnylie
I don’t have any background in Telco world, I’m so blank about it, Telco people asked this many times, is it possib...
by donnylie Explorer in Splunk Search 09-30-2010
0 1
0
1
thepocketwade
I just ran a search that returned approximately 1 million results. Only after it completed (which took a bit longer ...
by thepocketwade Path Finder in Splunk Search 09-30-2010
3 2
3
2
adamw
We seem to be having an issue with the postfix_syslog sourcetype (that came as a default sourcetype in Splunk) and it...
by adamw Communicator in Splunk Search 09-30-2010
0 5
0
5
htkhtk
I have jboss logs that print a message size everytime jboss restarts. The message size is different everytime jboss s...
by htkhtk Path Finder in Splunk Search 09-30-2010
0 4
0
4
JohnB
If I do a search for something such as: uri="/this/or/that.html" over, say, an hour. Once the search completes (fina...
by JohnB Explorer in Splunk Search 09-30-2010
0 3
0
3
pmr
Hello, How do i use multikv to extract fields that have % or / in them ? I'm unable to extract if it has those chara...
by pmr Explorer in Splunk Search 09-30-2010
1 2
1
2
klumpba
I have a Splunk app that parses some Snort files and assigns some fields to the content. The app works fine from the...
by klumpba Engager in Splunk Search 09-29-2010
4 3
4
3
hexx
When I use the "diff" search command to compare events that contain several hundred lines, I notice that differences ...
by hexx Splunk Employee Splunk Employee in Splunk Search 09-29-2010
4 2
4
2
leo_wang
I have read the this page about the concept of "Intention" : http://www.splunk.com/base/Splexicon:Intention It say...
by leo_wang Path Finder in Splunk Search 09-29-2010
1 5
1
5
cmeo
I have the following query which almost does what I want: sourcetype="cisco_wsa_squid" | lookup teamlookup cs_userna...
by cmeo Contributor in Splunk Search 09-29-2010
0 4
0
4
clyde772
For the AMMAP application for the map, I followed the instruction and installed MAXMIND and the AMMAP app, but I can'...
by clyde772 Communicator in Splunk Search 09-28-2010
0 6
0
6
Branden
I have a chart in a dashboard that shows a graph of paging space usage across all of our hosts. Or at least that's wh...
by Branden Builder in Splunk Search 09-28-2010
2 2
2
2
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...