Splunk Search

Splunk Search
Community Activity
rdsdnet
I’d like to run a search once a day and append those search results to the previous day’s results. This way I can gra...
by rdsdnet Engager in Splunk Search 08-17-2010
1 1
1
1
ml96
Splunk appeasrs to be failing to index the server.log for our ATG Joss instances. On the Splunk indexer the following...
by ml96 New Member in Splunk Search 08-17-2010
0 3
0
3
kholleran
Hello, Right now I have a search that says: source="syslog" minutesago="20" | APPEND [search host="SERVER" Event="S...
by kholleran Communicator in Splunk Search 08-17-2010
1 1
1
1
minalenan
Hi, I'm trying to search for some keywords that appear in multiple lines. I tried using regular expression in multi ...
by minalenan New Member in Splunk Search 08-17-2010
0 10
0
10
Yancy
I'm reviewing debug logs that have some Enter/Exit values for each step of a process. Currently I can calculate the ...
by Yancy Path Finder in Splunk Search 08-16-2010
1 4
1
4
sdwilkerson
We have a csv input which is a daily dump from a ticket DB for the current month. The DB output looks something like...
by sdwilkerson Contributor in Splunk Search 08-16-2010
1 12
1
12
CerielTjuh
Hi there, I have a saved search that I want to run every day at noon, I am sending the results trough mail and want ...
by CerielTjuh Path Finder in Splunk Search 08-16-2010
4 7
4
7
msupino
I have multiple LightForwarded, in different domains, who have similar host names (machines inside one domain are the...
by msupino Explorer in Splunk Search 08-16-2010
1 13
1
13
pde23
How can I get a count of events per second in a realtime search? I can do something like this to get a rolling coun...
by pde23 Explorer in Splunk Search 08-16-2010
0 3
0
3
the_wolverine
I'm trying to run a metadata search on type=hosts and am being capped in the UI to 10,000 results. I've already incr...
by the_wolverine Champion in Splunk Search 08-16-2010
1 5
1
5
thartmann
We have a situation where we'd like to construct a search based on a time/date from a remote Time zone. So for examp...
by thartmann Path Finder in Splunk Search 08-16-2010
1 4
1
4
GratefulDude
I'm having a bit of trouble finishing up a report I'm trying to give a report of how long users were logged into a s...
by GratefulDude Explorer in Splunk Search 08-15-2010
0 1
0
1
RalphyBoy
I am testing splunk. When I do what I consider a very simple search I get the wrong results. Let me say this: our fil...
by RalphyBoy New Member in Splunk Search 08-13-2010
0 6
0
6
Stan
When parsing some customized log, the format it's like below [timestamps] field name [value] [00:46:38] - Remain Qu...
by Stan New Member in Splunk Search 08-13-2010
0 4
0
4
vadud3
* | rex "(?<fpc>fpc\d+) (?<ichip>ICHIP\(\d+\)):Packet drop in Ichip pktwr,rate: %\S+: \d+, total: (?<err>\d+)" How ...
by vadud3 Path Finder in Splunk Search 08-12-2010
0 3
0
3
carmackd
I have a log file that looks like this: Wed Aug 11 14:27:48 GMT 2010 | Inactive Users Last 7 Days---> | 123456789 | ...
by carmackd Communicator in Splunk Search 08-11-2010
0 2
0
2
kbecker
What is the best way to determine transactions per second are occurring in our application logs. I attempted using "...
by kbecker Communicator in Splunk Search 08-11-2010
0 2
0
2
Justin_Grant
I have two searches. One search returns a field (using stats count) representing the number of users logging into a w...
by Justin_Grant Contributor in Splunk Search 08-10-2010
1 1
1
1
Peter
Is it possible to use regular expressions for the whitelist/blacklist filters in serverclass.conf? For example: whit...
by Peter Path Finder in Splunk Search 08-10-2010
1 3
1
3
imrago
On splunkA I am monitoring an xml log file. It is forwarded to SplunkB in a separate index. Where should I define the...
by imrago Contributor in Splunk Search 08-10-2010
0 1
0
1
whywhywhy
I have a search that is looking pipes through a rex. rex fields=_raw "\D(?<big_num>\d{15,16})\D" I want the UI to ...
by whywhywhy Engager in Splunk Search 08-09-2010
1 2
1
2
vcarbona
Here's my CLI search: SPLUNK_URI=https://splunk_search_head:8089 /opt/splunk/bin/splunk search '|savedsearch "mysav...
by vcarbona Path Finder in Splunk Search 08-08-2010
2 4
2
4
serialmonkey
I get lots of data from various systems via syslog. One of my systems sends me data that looks like this HEADERTEXT:...
by serialmonkey Path Finder in Splunk Search 08-07-2010
1 5
1
5
sranga
Hi We have a few charts that display summary-indexed data. The charts take a couple of form inputs including _time...
by sranga Path Finder in Splunk Search 08-06-2010
0 7
0
7
twinspop
(Love this forum. Didn't even know about the concurrency command before this morning.  My search: SYSCODE=ezLMWeb*...
by twinspop Influencer in Splunk Search 08-06-2010
0 3
0
3
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...