| Dear All, I'm doing a search with a set UNION, like this: | SET UNION [SEARCH FOO | FIELDS fields IP, count] [ SEA... by pinzer Path Finder in Splunk Search 10-04-2010 0 5 | 0 | 5 | ||
| Hello, please, I would like to know if the SEDCMD command is able to change metadata values like host, source and sou... by cafissimo Communicator in Splunk Search 10-04-2010 1 1 | 1 | 1 | ||
| Hi there, I need to re-index some data. In inputs.conf, host_segment parameter is configured as follows: host_segm... by melonman Motivator in Splunk Search 10-02-2010 1 8 | 1 | 8 | ||
| Can someone please help me with a regex to extract the host name from a filename. I've got two different file naming... by carmackd Communicator in Splunk Search 10-01-2010 0 2 | 0 | 2 | ||
| I'm doing a search for invalid logons for our vpn logs. But I want the search results to return when the invalid atte... by aanetserv New Member in Splunk Search 10-01-2010 0 2 | 0 | 2 | ||
| I want to gobble in CSV files containing numeric data. Each file will have between 500 and 150,000 fields. (Yes that'... by l0r3zz New Member in Splunk Search 10-01-2010 0 8 | 0 | 8 | ||
| I have the following search which I would like to use to populate a summary index for reporting (run every 30 minutes... by cudgel Path Finder in Splunk Search 10-01-2010 1 4 | 1 | 4 | ||
| Hey, The answer to this question will be very useful to know I have an advanced dashboard with a few charts (1 co... by Ant1D Motivator in Splunk Search 10-01-2010 2 4 | 2 | 4 | ||
| In Windows I have the following in the Inputs.conf: [monitor://C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQ... by Kyle_Brandt Path Finder in Splunk Search 10-01-2010 0 5 | 0 | 5 | ||
| I have a search that pipes to another search, and this search is highlighting the results. I do not want the highligh... by ericrobinson Path Finder in Splunk Search 09-30-2010 10 4 | 10 | 4 | ||
| I have a dataset where the rows in my search results all have a 'value' field, and there's another field that specif... by sideview SplunkTrust 5 4 | 5 | 4 | ||
| In order to identify web content that hasn't been pulled in a while, I thought I would use Splunk since a) my Apache ... by Brian_Osburn Builder in Splunk Search 09-30-2010 3 4 | 3 | 4 | ||
| We're trying to set up a dynamic sourcetype extraction at index time. The reason for this is that we have about 40-50... by mattcg Explorer in Splunk Search 09-30-2010 2 2 | 2 | 2 | ||
| I don’t have any background in Telco world, I’m so blank about it, Telco people asked this many times, is it possib... by donnylie Explorer in Splunk Search 09-30-2010 0 1 | 0 | 1 | ||
| I just ran a search that returned approximately 1 million results. Only after it completed (which took a bit longer ... by thepocketwade Path Finder in Splunk Search 09-30-2010 3 2 | 3 | 2 | ||
| We seem to be having an issue with the postfix_syslog sourcetype (that came as a default sourcetype in Splunk) and it... by adamw Communicator in Splunk Search 09-30-2010 0 5 | 0 | 5 | ||
| I have jboss logs that print a message size everytime jboss restarts. The message size is different everytime jboss s... by htkhtk Path Finder in Splunk Search 09-30-2010 0 4 | 0 | 4 | ||
| If I do a search for something such as: uri="/this/or/that.html" over, say, an hour. Once the search completes (fina... by JohnB Explorer in Splunk Search 09-30-2010 0 3 | 0 | 3 | ||
| Hello, How do i use multikv to extract fields that have % or / in them ? I'm unable to extract if it has those chara... by pmr Explorer in Splunk Search 09-30-2010 1 2 | 1 | 2 | ||
| I have a Splunk app that parses some Snort files and assigns some fields to the content. The app works fine from the... by klumpba Engager in Splunk Search 09-29-2010 4 3 | 4 | 3 | ||
| When I use the "diff" search command to compare events that contain several hundred lines, I notice that differences ... by hexx Splunk Employee 4 2 | 4 | 2 | ||
| I have read the this page about the concept of "Intention" : http://www.splunk.com/base/Splexicon:Intention It say... by leo_wang Path Finder in Splunk Search 09-29-2010 1 5 | 1 | 5 | ||
| I have the following query which almost does what I want: sourcetype="cisco_wsa_squid" | lookup teamlookup cs_userna... by cmeo Contributor in Splunk Search 09-29-2010 0 4 | 0 | 4 | ||
| For the AMMAP application for the map, I followed the instruction and installed MAXMIND and the AMMAP app, but I can'... by clyde772 Communicator in Splunk Search 09-28-2010 0 6 | 0 | 6 | ||
| I have a chart in a dashboard that shows a graph of paging space usage across all of our hosts. Or at least that's wh... by Branden Builder in Splunk Search 09-28-2010 2 2 | 2 | 2 |