Splunk Search

Splunk Search
Community Activity
hexx
When I use the "diff" search command to compare events that contain several hundred lines, I notice that differences ...
by hexx Splunk Employee Splunk Employee in Splunk Search 09-29-2010
4 2
4
2
leo_wang
I have read the this page about the concept of "Intention" : http://www.splunk.com/base/Splexicon:Intention It say...
by leo_wang Path Finder in Splunk Search 09-29-2010
1 5
1
5
cmeo
I have the following query which almost does what I want: sourcetype="cisco_wsa_squid" | lookup teamlookup cs_userna...
by cmeo Contributor in Splunk Search 09-29-2010
0 4
0
4
clyde772
For the AMMAP application for the map, I followed the instruction and installed MAXMIND and the AMMAP app, but I can'...
by clyde772 Communicator in Splunk Search 09-28-2010
0 6
0
6
Branden
I have a chart in a dashboard that shows a graph of paging space usage across all of our hosts. Or at least that's wh...
by Branden Builder in Splunk Search 09-28-2010
2 2
2
2
pshankland
Hi, I have just installed Splunk as want to get some reports out of a Barracuda Spam firewall we have installed that...
by pshankland New Member in Splunk Search 09-28-2010
0 4
0
4
Nicholas_Key
[1] I would like to know if I can tar an index from a Splunk instance and then untar it into other Splunk instance? ...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 09-28-2010
0 2
0
2
sajbutler
Every 5 minutes, one of our systems dumps out data on connected users. There is one line per connected user as follow...
by sajbutler Path Finder in Splunk Search 09-28-2010
0 7
0
7
mctester
If I do this: index="foo" sourcetype="bar" | sort _time | streamstats dc(userid) as dcusers | delta dcusers as delta...
by mctester Communicator in Splunk Search 09-28-2010
1 3
1
3
cmeo
Is there any way to get popup or lite mode AccountBar WITH the logo clickable? This would be very useful for turning ...
by cmeo Contributor in Splunk Search 09-27-2010
0 1
0
1
pinzer
Hi all, i need to change the color of a bar of the column chart if the value is higher than a number. How can i do th...
by pinzer Path Finder in Splunk Search 09-26-2010
2 1
2
1
kholleran
Hello, I currently am doing a search that uses a unix time as a field. What I want to do, is do something like this...
by kholleran Communicator in Splunk Search 09-26-2010
0 2
0
2
timbCFCA
Within each record in a query I have two fields, c_ip and cs_bytes which is numeric. How can I get the top 10 c_ip v...
by timbCFCA Path Finder in Splunk Search 09-24-2010
1 1
1
1
kholleran
Hello, I have a couple issues. First off, my Splunk server blue screened (yay for Windows!) and now I have a source...
by kholleran Communicator in Splunk Search 09-24-2010
0 3
0
3
gljiva
Hi, I'm getting a big rounding error when evaluating floating expressions. Here is the search that is evaluating the ...
by gljiva Path Finder in Splunk Search 09-24-2010
0 1
0
1
materaj
Dear ziegfried, Firstly, I really like your Google Maps App. but I have question about input. When I search with geo...
by materaj New Member in Splunk Search 09-24-2010
0 3
0
3
Caio_Santos
I have one event viewer log and I'm tryng to capture the data fields, since Splunk cannot recognize the timstamp by i...
by Caio_Santos Path Finder in Splunk Search 09-24-2010
1 2
1
2
barryv
Hi, Splunk noob question: I defined and saved 3 searches: a. Users visiting my page. b. Users attempting to do acti...
by barryv Explorer in Splunk Search 09-23-2010
0 2
0
2
staze
I'd like to generate a report of N top search queries from my apache weblogs. Log entry for a search looks like: 1...
by staze Path Finder in Splunk Search 09-23-2010
0 5
0
5
starks951
Splunkers... I am looking at a VPN logs from a Cisco ASA and trying to calculate the amount of time per day per user ...
by starks951 Explorer in Splunk Search 09-23-2010
0 4
0
4
leo_wang
Hello, I want to design an Form Seach which has a SearchBar on it to let user input their search keyords. And in thi...
by leo_wang Path Finder in Splunk Search 09-23-2010
1 2
1
2
pinzer
Hi all, how can i limit this search query to the top 5 rows? eventtype="searchDC" Type="Audit Success" CategoryStrin...
by pinzer Path Finder in Splunk Search 09-23-2010
0 2
0
2
muebel
I have been digging into the advanced xml stuff lately, and have come across a hurdle with simply figuring out the co...
by SplunkTrust SplunkTrust in Splunk Search 09-23-2010
1 2
1
2
twinspop
This seems like it would be easy. Maybe it is, and I'm being thick today.  Log lines look like ... server1 qs_queu...
by twinspop Influencer in Splunk Search 09-23-2010
1 2
1
2
hoffmandirt
The "monitor a file or directory" data input option is no longer working. When I add a new file this way, the source ...
by hoffmandirt Explorer in Splunk Search 09-22-2010
0 1
0
1
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...