| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        I have a scenario where I would like to do a two-layered lookup. I'm essentially doing an IP address lookup against a...
        
       
         
           by 
           
                
                    
                        Lowell
                    
                
           
             
             
               Super Champion
             
           
           in
           Splunk Search
           
           
              
               06-25-2010
             
           
         
        
      | 
   
		
		6
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Below are the first 7 lines of a file that I want to index. The additional lines all look like line 7. Can I have it ...
        
       
         
           by 
           
                
                    
                        nate1
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-25-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Can I use eventtype=myevent with |metadata?  
  example: | metadata type=hosts | eventtype=group_A 
  I know tags wor...
        
       
         
           by 
           
                
                    
                        thall79
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               06-24-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I have what I think should be a simple search, but I'm not quite able to come up with a way to do it. Ultimately I gu...
        
       
         
           by 
           
                
                    
                        mfrost8
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               06-24-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I'm trying to correlate start and stop events and having a much harder time than what the documentation implies in or...
        
       
         
           by 
           
                
                    
                        ericdp
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-22-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        When we are browsing log files for problems, we often don't know exactly what we're looking for. But in a short perio...
        
       
         
           by 
           
                
                    
                        r31floyd
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               06-24-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        index="whatever" INFECTION | top limit="15" misc by src  
  When I attempt this search, the limit qualifier seems to ...
        
       
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Splunk Search
           
           
              
               06-22-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hello, 
  I would like to filter a search result, of irrelevant data, to display less information so its easier to sp...
        
       
         
           by 
           
                
                    
                        Carmageddon
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               06-22-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  10
	 
 | |||
| 
      
        I have 4 servers in a distributed environment. I use server a to login and do the search. 
  When I use the search | ...
        
       
         
           by 
           
                
                    
                        sanju005ind
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               06-23-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have taken iplocation.py as a skeleton for a simple custom search command that adds another column to the search re...
        
       
         
           by 
           
                
                    
                        enielson
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-23-2010
             
           
         
        
      | 
   
		
		4
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Is there a way to have REST look up the latest results from a scheduled search and return them, not re-running the se...
        
       
         
           by 
           
                
                    
                        Jason
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               06-23-2010
             
           
         
        
      | 
   
		
		2
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I moved my Splunk instance to another machine and I'm getting the following error message: 2010-06-15 16:20:24,739 ER...
        
       
         
           by 
           
                
                    
                        rsimmons
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               06-23-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I find the document about auto finalize in this page http://zh-hant.splunk.com/base/Documentation/latest/Developer/RE...
        
       
         
           by 
           
                
                    
                        Jaci
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               06-15-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        If I have an event with more than one IP addres in it, how can I write a regex that will capture all of the IP's? 
  ...
        
       
         
           by 
           
                
                    
                        Derek
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               06-23-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Good morning, 
  I'm developing for a customer a very simple search.  
  tag=mysourcetype tag=myeventtype startdaysag...
        
       
         
           by 
           
                
                    
                        nik_splunk
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-25-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        What are the pros and cons to using an external lookup script vs a custom search command when the purpose is simply t...
        
       
         
           by 
           
                
                    
                        Lowell
                    
                
           
             
             
               Super Champion
             
           
           in
           Splunk Search
           
           
              
               06-22-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I'm trying to calculate the amount of time between two events and I'm having a lot of trouble. Because of some requir...
        
       
         
           by 
           
                
                    
                        ericdp
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-15-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        Given servers A and B, how do you search both A AND B from server A, but disallow B from searching against A?
        
       
         
           by 
           
                
                    
                        amrit
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               01-21-2010
             
           
         
        
      | 
   
		
		3
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        So, I have a big set of web stats for a given time in a search. Basically, I want it broken down by uri_path and for ...
        
       
         
           by 
           
                
                    
                        kdankmyer
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               06-18-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I am trying to compare the results of two searches that share a common timeframe and index, with a negation. The comm...
        
       
         
           by 
           
                
                    
                        Tisiphone_1
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-18-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        In a view like the flashtimeline, there is a selector to choose between the results of the search and the log events ...
        
       
         
           by 
           
                
                    
                        smisplunk
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-21-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        I have a search where I have been using "latesttime=-2d@d" to specify the time range, like so: 
  ... latesttime=-2d@...
        
       
         
           by 
           
                
                    
                        jwestberg
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               06-17-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I am doing a search which gives me two fields and say parent1 and child1...n so with parent and child I have 1 to n r...
        
       
         
           by 
           
                
                    
                        manuarora
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               06-17-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hello there, 
  Is it possible to chart a multivalued field against another multivalued field of the same size? 
  Fo...
        
       
         
           by 
           
                
                    
                        ifeldshteyn
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               06-04-2010
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        We have many hosts running backups every night and report back if they are successful or not. I would like to simplif...
        
       
         
           by 
           
                
                    
                        Jaci
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               06-07-2010
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  2
	 
 |