| I've been breaking my head over this very simple field extraction. My extraction (see eg., below) has problems beca... by pjmenon Explorer in Splunk Search 07-01-2010 0 21 | 0 | 21 | ||
| Is the wildcard search star * supported by logs in splunk? Im trying to see if splunk is seeing changes being made in... by riderofyamaha Explorer in Splunk Search 07-01-2010 0 3 | 0 | 3 | ||
| Hi, question about restoration of indexed data. I know how to restore(or search old) indexes data by putting necessa... by melonman Motivator in Splunk Search 06-30-2010 1 1 | 1 | 1 | ||
| It looks like the Job Manager currently does not allow me to track CLI searches. Is there some way I can get a jobid... by the_wolverine Champion in Splunk Search 06-29-2010 2 2 | 2 | 2 | ||
| Hello, I found that when I use subsearch or join command to join data, I can't make splunk to return the complete ... by kalitbri Explorer in Splunk Search 06-29-2010 0 3 | 0 | 3 | ||
| Greetings. I am trying to use an expression in the search string that will not display certain IP addresses. I have ... by bbear Explorer in Splunk Search 06-29-2010 1 4 | 1 | 4 | ||
| Hello, I am trying to extract fields from an event which looks like this (I have multiple events) total time (ms): ... by hiwell Explorer in Splunk Search 06-29-2010 0 3 | 0 | 3 | ||
| Hey guys, We are monitoring 2 specific CSV Log files on one indexer. I setup the appropriate custom field extractio... by balbano Contributor in Splunk Search 06-29-2010 0 6 | 0 | 6 | ||
| Basically I have a line of data that looks like this: Jun 28 14:15:10 sc4-app04.mcafeesecure.com portal: ACCESS Clic... by mcafeesecure Explorer in Splunk Search 06-29-2010 3 3 | 3 | 3 | ||
| An auditor is requesting that we furnish them with a list of all servers logging to splunk and the index they are bei... by Michael_Wilde Splunk Employee 1 2 | 1 | 2 | ||
| I have splunk indexing a local file that is being continuously written to and I need the first word in each event to ... by mawwx3 Explorer in Splunk Search 06-28-2010 0 4 | 0 | 4 | ||
| Search string "mismatch". The single event is about 2-3K lines or more. In the lines of text there are 5 lines with ... by zliu Splunk Employee 1 6 | 1 | 6 | ||
| I need a regex that can process all security events with eventid 540 that don't contain $, SYSTEM, or ANONYMOUS LOGON... by chowell Explorer in Splunk Search 06-28-2010 0 2 | 0 | 2 | ||
| I am scheduling this search(Daily Indexed Volume): index=_internal source=*metrics.log splunk_server="*" | eval MB=k... by apro Path Finder in Splunk Search 06-28-2010 0 2 | 0 | 2 | ||
| I have a scenario where I would like to do a two-layered lookup. I'm essentially doing an IP address lookup against ... by Lowell Super Champion in Splunk Search 06-25-2010 6 4 | 6 | 4 | ||
| Below are the first 7 lines of a file that I want to index. The additional lines all look like line 7. Can I have it ... by nate1 Explorer in Splunk Search 06-25-2010 1 2 | 1 | 2 | ||
| Can I use eventtype=myevent with |metadata? example: | metadata type=hosts | eventtype=group_A I know tags work, ... by thall79 Communicator in Splunk Search 06-25-2010 0 1 | 0 | 1 | ||
| I have what I think should be a simple search, but I'm not quite able to come up with a way to do it. Ultimately I g... by mfrost8 Builder in Splunk Search 06-25-2010 1 3 | 1 | 3 | ||
| I'm trying to correlate start and stop events and having a much harder time than what the documentation implies in or... by ericdp Explorer in Splunk Search 06-25-2010 1 5 | 1 | 5 | ||
| When we are browsing log files for problems, we often don't know exactly what we're looking for. But in a short peri... by r31floyd Engager in Splunk Search 06-25-2010 0 4 | 0 | 4 | ||
| index="whatever" INFECTION | top limit="15" misc by src When I attempt this search, the limit qualifier seems to be... by the_wolverine Champion in Splunk Search 06-24-2010 0 4 | 0 | 4 | ||
| Hello, I would like to filter a search result, of irrelevant data, to display less information so its easier to spot... by Carmageddon New Member in Splunk Search 06-24-2010 0 10 | 0 | 10 | ||
| I have 4 servers in a distributed environment. I use server a to login and do the search. When I use the search | me... by sanju005ind Communicator in Splunk Search 06-24-2010 0 2 | 0 | 2 | ||
| I have taken iplocation.py as a skeleton for a simple custom search command that adds another column to the search re... by enielson Explorer in Splunk Search 06-23-2010 4 2 | 4 | 2 | ||
| Is there a way to have REST look up the latest results from a scheduled search and return them, not re-running the se... by Jason Motivator in Splunk Search 06-23-2010 2 1 | 2 | 1 |