Splunk Search

Splunk Search
Community Activity
msupino
I have multiple LightForwarded, in different domains, who have similar host names (machines inside one domain are the...
by msupino Explorer in Splunk Search 08-16-2010
1 13
1
13
pde23
How can I get a count of events per second in a realtime search? I can do something like this to get a rolling coun...
by pde23 Explorer in Splunk Search 08-16-2010
0 3
0
3
the_wolverine
I'm trying to run a metadata search on type=hosts and am being capped in the UI to 10,000 results. I've already incr...
by the_wolverine Champion in Splunk Search 08-16-2010
1 5
1
5
thartmann
We have a situation where we'd like to construct a search based on a time/date from a remote Time zone. So for examp...
by thartmann Path Finder in Splunk Search 08-16-2010
1 4
1
4
GratefulDude
I'm having a bit of trouble finishing up a report I'm trying to give a report of how long users were logged into a s...
by GratefulDude Explorer in Splunk Search 08-15-2010
0 1
0
1
RalphyBoy
I am testing splunk. When I do what I consider a very simple search I get the wrong results. Let me say this: our fil...
by RalphyBoy New Member in Splunk Search 08-13-2010
0 6
0
6
Stan
When parsing some customized log, the format it's like below [timestamps] field name [value] [00:46:38] - Remain Qu...
by Stan New Member in Splunk Search 08-13-2010
0 4
0
4
vadud3
* | rex "(?<fpc>fpc\d+) (?<ichip>ICHIP\(\d+\)):Packet drop in Ichip pktwr,rate: %\S+: \d+, total: (?<err>\d+)" How ...
by vadud3 Path Finder in Splunk Search 08-12-2010
0 3
0
3
carmackd
I have a log file that looks like this: Wed Aug 11 14:27:48 GMT 2010 | Inactive Users Last 7 Days---> | 123456789 | ...
by carmackd Communicator in Splunk Search 08-11-2010
0 2
0
2
kbecker
What is the best way to determine transactions per second are occurring in our application logs. I attempted using "...
by kbecker Communicator in Splunk Search 08-11-2010
0 2
0
2
Justin_Grant
I have two searches. One search returns a field (using stats count) representing the number of users logging into a w...
by Justin_Grant Contributor in Splunk Search 08-10-2010
1 1
1
1
Peter
Is it possible to use regular expressions for the whitelist/blacklist filters in serverclass.conf? For example: whit...
by Peter Path Finder in Splunk Search 08-10-2010
1 3
1
3
imrago
On splunkA I am monitoring an xml log file. It is forwarded to SplunkB in a separate index. Where should I define the...
by imrago Contributor in Splunk Search 08-10-2010
0 1
0
1
whywhywhy
I have a search that is looking pipes through a rex. rex fields=_raw "\D(?<big_num>\d{15,16})\D" I want the UI to ...
by whywhywhy Engager in Splunk Search 08-09-2010
1 2
1
2
vcarbona
Here's my CLI search: SPLUNK_URI=https://splunk_search_head:8089 /opt/splunk/bin/splunk search '|savedsearch "mysav...
by vcarbona Path Finder in Splunk Search 08-08-2010
2 4
2
4
serialmonkey
I get lots of data from various systems via syslog. One of my systems sends me data that looks like this HEADERTEXT:...
by serialmonkey Path Finder in Splunk Search 08-07-2010
1 5
1
5
sranga
Hi We have a few charts that display summary-indexed data. The charts take a couple of form inputs including _time...
by sranga Path Finder in Splunk Search 08-06-2010
0 7
0
7
twinspop
(Love this forum. Didn't even know about the concurrency command before this morning.  My search: SYSCODE=ezLMWeb*...
by twinspop Influencer in Splunk Search 08-06-2010
0 3
0
3
bfaber
There is probably a better way to do this, but I am trying to catalog what rules are (and are not) used using the fir...
by bfaber Communicator in Splunk Search 08-06-2010
0 5
0
5
goat
I am currently running a search for license bandwidth : index=_internal source=*metrics.log group=per_index_thruput ...
by goat Explorer in Splunk Search 08-05-2010
1 4
1
4
kseshadri
Running splunk on windows2003. I am getting the events but it seems my regex is not working right on the event. Sam...
by kseshadri New Member in Splunk Search 08-02-2010
0 1
0
1
kholleran
Hello, I have a search that looks for a particular set of data. if the data comes from a particular source address,...
by kholleran Communicator in Splunk Search 08-02-2010
1 1
1
1
cafissimo
Hello, I have a log file with a very long record (about 255 chars) and I would like to know if and how is it possible...
by cafissimo Communicator in Splunk Search 08-02-2010
0 1
0
1
kholleran
Hello, I am asking a lot of questions today (obviously new to Splunk and in implementation...). We do NOT use AD fo...
by kholleran Communicator in Splunk Search 08-02-2010
2 2
2
2
rgcox1
I'm trying to develop a regex to separate merged events from a log. Here's my stanza in props.conf: [source=c:\temp\...
by rgcox1 Communicator in Splunk Search 07-30-2010
0 2
0
2
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors