Thread Info | |||||
---|---|---|---|---|---|
Hi,
question about restoration of indexed data. I know how to restore(or search old) indexes data by putting neces...
by
melonman
Motivator
in
Splunk Search
06-08-2010
|
1
|
1
| |||
It looks like the Job Manager currently does not allow me to track CLI searches. Is there some way I can get a jobid ...
by
the_wolverine
Champion
in
Splunk Search
06-29-2010
|
2
|
2
| |||
Hello,
I found that when I use subsearch or join command to join data,
I can't make splunk to return the compl...
by
kalitbri
Explorer
in
Splunk Search
06-21-2010
|
0
|
3
| |||
Greetings.
I am trying to use an expression in the search string that will not display certain IP addresses. I hav...
by
bbear
Explorer
in
Splunk Search
06-29-2010
|
1
|
4
| |||
Hello,
I am trying to extract fields from an event which looks like this (I have multiple events)
total time (m...
by
hiwell
Explorer
in
Splunk Search
06-22-2010
|
0
|
3
| |||
Hey guys,
We are monitoring 2 specific CSV Log files on one indexer. I setup the appropriate custom field extract...
by
balbano
Contributor
in
Splunk Search
06-01-2010
|
0
|
6
| |||
Basically I have a line of data that looks like this:
Jun 28 14:15:10 sc4-app04.mcafeesecure.com portal: ACCESS Cl...
by
mcafeesecure
Explorer
in
Splunk Search
06-28-2010
|
3
|
3
| |||
An auditor is requesting that we furnish them with a list of all servers logging to splunk and the index they are bei...
by
Michael_Wilde
Splunk Employee
in
Splunk Search
06-28-2010
|
1
|
2
| |||
I have splunk indexing a local file that is being continuously written to and I need the first word in each event to ...
by
mawwx3
Explorer
in
Splunk Search
06-28-2010
|
0
|
4
| |||
Search string "mismatch".
The single event is about 2-3K lines or more. In the lines of text there are 5 lines wit...
by
zliu
Splunk Employee
in
Splunk Search
05-28-2010
|
1
|
6
| |||
I need a regex that can process all security events with eventid 540 that don't contain $, SYSTEM, or ANONYMOUS LOGON...
by
chowell
Explorer
in
Splunk Search
06-28-2010
|
0
|
2
| |||
I am scheduling this search(Daily Indexed Volume):
index=_internal source=*metrics.log splunk_server="*" | eval MB...
by
apro
Path Finder
in
Splunk Search
06-28-2010
|
0
|
2
| |||
I have a scenario where I would like to do a two-layered lookup. I'm essentially doing an IP address lookup against a...
by
Lowell
Super Champion
in
Splunk Search
06-25-2010
|
6
|
4
| |||
Below are the first 7 lines of a file that I want to index. The additional lines all look like line 7. Can I have it ...
by
nate1
Explorer
in
Splunk Search
06-25-2010
|
1
|
2
| |||
Can I use eventtype=myevent with |metadata?
example: | metadata type=hosts | eventtype=group_A
I know tags wor...
by
thall79
Communicator
in
Splunk Search
06-24-2010
|
0
|
1
| |||
I have what I think should be a simple search, but I'm not quite able to come up with a way to do it. Ultimately I gu...
by
mfrost8
Builder
in
Splunk Search
06-24-2010
|
1
|
3
| |||
I'm trying to correlate start and stop events and having a much harder time than what the documentation implies in or...
by
ericdp
Explorer
in
Splunk Search
06-22-2010
|
1
|
5
| |||
When we are browsing log files for problems, we often don't know exactly what we're looking for. But in a short perio...
by
r31floyd
Engager
in
Splunk Search
06-24-2010
|
0
|
4
| |||
index="whatever" INFECTION | top limit="15" misc by src
When I attempt this search, the limit qualifier seems to ...
by
the_wolverine
Champion
in
Splunk Search
06-22-2010
|
0
|
4
| |||
Hello,
I would like to filter a search result, of irrelevant data, to display less information so its easier to sp...
by
Carmageddon
New Member
in
Splunk Search
06-22-2010
|
0
|
10
| |||
I have 4 servers in a distributed environment. I use server a to login and do the search.
When I use the search | ...
by
sanju005ind
Communicator
in
Splunk Search
06-23-2010
|
0
|
2
| |||
I have taken iplocation.py as a skeleton for a simple custom search command that adds another column to the search re...
by
enielson
Explorer
in
Splunk Search
06-23-2010
|
4
|
2
| |||
Is there a way to have REST look up the latest results from a scheduled search and return them, not re-running the se...
by
Jason
Motivator
in
Splunk Search
06-23-2010
|
2
|
1
| |||
I moved my Splunk instance to another machine and I'm getting the following error message: 2010-06-15 16:20:24,739 ER...
by
rsimmons
Splunk Employee
in
Splunk Search
06-23-2010
|
0
|
1
| |||
I find the document about auto finalize in this page http://zh-hant.splunk.com/base/Documentation/latest/Developer/RE...
by
Jaci
Splunk Employee
in
Splunk Search
06-15-2010
|
1
|
2
|