Splunk Search

Splunk Search
Community Activity
adamw
So I have an application that auto-rotates its config files every time it is changed, and uses the following structur...
by adamw Communicator in Splunk Search 09-02-2010
0 1
0
1
sptelars
I would like to add the total amount of time an cs_id spends on the web daily. Ironport provides logs where the time...
by sptelars New Member in Splunk Search 09-02-2010
0 1
0
1
Lowell
Is there any weird issues with using multiple searchmatch() expressions within a single eval command? I have a trans...
by Lowell Super Champion in Splunk Search 09-02-2010
4 2
4
2
Lowell
Is there anyway of emulating a nested subsearch? I know its sometimes possible to rewrite a search to factor-out a s...
by Lowell Super Champion in Splunk Search 09-02-2010
0 5
0
5
the_wolverine
I've got certain events that I want to send to collect. I see the addtime option (defaults to true). What does it d...
by the_wolverine Champion in Splunk Search 09-01-2010
0 2
0
2
pde
I have a small DTrace app that monitors ARP requests and replies, producing output like this: 2010 Sep 1 03:10:08 ...
by pde Path Finder in Splunk Search 09-01-2010
0 2
0
2
vtrujillo
Hi everyone. I'm trying to use the date_hour and date_minute fields (which reads perfectly the hours and minutes of ...
by vtrujillo Explorer in Splunk Search 09-01-2010
0 2
0
2
Jaci
Search fails to correctly return all matching events when performing outer joins. The search below illustrates the pr...
by Jaci Splunk Employee Splunk Employee in Splunk Search 09-01-2010
1 3
1
3
hulahoop
Splunk understands old school BSD-style syslog events effortlessly. For RFC 5424-style events, multiple data structu...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 09-01-2010
0 3
0
3
sriram_sathyamo
In a chart, I need to set major unit to be one week (i.e adjacant tick marks need to be one week apart). How do I do ...
by sriram_sathyamo New Member in Splunk Search 09-01-2010
0 1
0
1
sranga
Hi I was wondering if there is a limit on the count of simultaneous queries/searches/jobs executed in a Splunk ins...
by sranga Path Finder in Splunk Search 08-31-2010
0 2
0
2
Branden
I have the following output: DEV#: 0 DEVICE NAME: vpath0 TYPE: 2107900 POLICY: Optimized SERIAL: 123bac ...
by Branden Builder in Splunk Search 08-31-2010
0 11
0
11
pinzer
Hi all, i need to do a query about the number of login failed and succeeded in a time period. I'm auditing linux and ...
by pinzer Path Finder in Splunk Search 08-31-2010
0 2
0
2
Marinus
I'm building a custom search command that performs some visualizations on a dataset outside of Splunk. It has to pars...
by Marinus Communicator in Splunk Search 08-31-2010
0 6
0
6
Pete_Bassill
How would I go about running a search that compares the output to two searches and reports the difference between the...
by Pete_Bassill Path Finder in Splunk Search 08-31-2010
1 3
1
3
Branden
I have a script that sends something like the following to stdout: DEV#: 0 DEVICE NAME: vpath0 TYPE: 210790...
by Branden Builder in Splunk Search 08-30-2010
1 5
1
5
sondradotcom
Okay, my summary index looks like this: sourcetype="blah" | sistats count by email I'd like to run a query agai...
by sondradotcom Path Finder in Splunk Search 08-30-2010
1 1
1
1
landzaat
Is there a way to show events only if they do not contain a specified field. E.g. 40% of my selected events contain a...
by landzaat Explorer in Splunk Search 08-30-2010
12 1
12
1
DyJohnnY
Hi, We now have a setup in which we use splunk like this. Forwarders deployed on windows Domain Controllers, that re...
by DyJohnnY Explorer in Splunk Search 08-30-2010
1 4
1
4
MikeyG
I have a search time field extraction for CISCO system messages named MsgClassID. I uploaded from Manager a CISCOevt_...
by MikeyG Explorer in Splunk Search 08-28-2010
0 1
0
1
sondradotcom
I'm trying to figure out how to calculate a percent of total such that: search string | stats count percent by email...
by sondradotcom Path Finder in Splunk Search 08-28-2010
3 3
3
3
gfriedmann
We index data from about 2000 different hosts. logs are relayed in via a TCP syslog source. Whenever a user goes to ...
by gfriedmann Communicator in Splunk Search 08-28-2010
0 2
0
2
BunnyHop
I've tried to filter native event logs being indexed using the [WinEventLog...] sourcetype. Here are the config: pr...
by BunnyHop Contributor in Splunk Search 08-28-2010
1 5
1
5
dominiquevocat
Hi, i have a couple of logfiles where there is one important "field" that splunk does not recognize because it is no...
by SplunkTrust SplunkTrust in Splunk Search 08-27-2010
1 3
1
3
bilsch
I am working on a variation on a transaction query as described here: http://answers.splunk.com/questions/5619/calcul...
by bilsch Engager in Splunk Search 08-27-2010
1 2
1
2
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...