Splunk Search

Splunk Search
Community Activity
serialmonkey
I get lots of data from various systems via syslog. One of my systems sends me data that looks like this HEADERTEXT:...
by serialmonkey Path Finder in Splunk Search 08-07-2010
1 5
1
5
sranga
Hi We have a few charts that display summary-indexed data. The charts take a couple of form inputs including _time...
by sranga Path Finder in Splunk Search 08-06-2010
0 7
0
7
twinspop
(Love this forum. Didn't even know about the concurrency command before this morning.  My search: SYSCODE=ezLMWeb*...
by twinspop Influencer in Splunk Search 08-06-2010
0 3
0
3
bfaber
There is probably a better way to do this, but I am trying to catalog what rules are (and are not) used using the fir...
by bfaber Communicator in Splunk Search 08-06-2010
0 5
0
5
goat
I am currently running a search for license bandwidth : index=_internal source=*metrics.log group=per_index_thruput ...
by goat Explorer in Splunk Search 08-05-2010
1 4
1
4
kseshadri
Running splunk on windows2003. I am getting the events but it seems my regex is not working right on the event. Sam...
by kseshadri New Member in Splunk Search 08-02-2010
0 1
0
1
kholleran
Hello, I have a search that looks for a particular set of data. if the data comes from a particular source address,...
by kholleran Communicator in Splunk Search 08-02-2010
1 1
1
1
cafissimo
Hello, I have a log file with a very long record (about 255 chars) and I would like to know if and how is it possible...
by cafissimo Communicator in Splunk Search 08-02-2010
0 1
0
1
kholleran
Hello, I am asking a lot of questions today (obviously new to Splunk and in implementation...). We do NOT use AD fo...
by kholleran Communicator in Splunk Search 08-02-2010
2 2
2
2
rgcox1
I'm trying to develop a regex to separate merged events from a log. Here's my stanza in props.conf: [source=c:\temp\...
by rgcox1 Communicator in Splunk Search 07-30-2010
0 2
0
2
rroberts
Is there a search to check bundles delivered from search head to peers?
by rroberts Splunk Employee Splunk Employee in Splunk Search 07-30-2010
2 2
2
2
jonathanjw
For starters this app is amazing. I am trying to search a ton of log files for a certain error and its definitely do...
by jonathanjw New Member in Splunk Search 07-30-2010
0 1
0
1
ankitghai
Below are the two files tcodesNew.csv paste.plurk.com/show/284992 chlogNew.csv paste.plurk.com/show/284990 I am tryi...
by ankitghai New Member in Splunk Search 07-30-2010
0 1
0
1
swackhap
Can Splunk index SQL LDF and MDF files?
by swackhap Explorer in Splunk Search 07-30-2010
0 2
0
2
morningwood
Unfortunately our proxy data does not have user information. However I do have access to AV data that is able to map ...
by morningwood Explorer in Splunk Search 07-29-2010
0 2
0
2
kholleran
I have a best practice time question for veteran Splunkers out there. Right now I have a a failed login search that ...
by kholleran Communicator in Splunk Search 07-29-2010
2 1
2
1
skippylou
Trying to figure out how to aggregate with top when there are two field choices. Here's an example of what I am tryi...
by skippylou Communicator in Splunk Search 07-28-2010
0 2
0
2
splunker30039
I have a field 'vpn_duration' which is taken from the 'Duration:' value in an ASA syslog disconnect message. The mes...
by splunker30039 Path Finder in Splunk Search 07-28-2010
0 2
0
2
castle1126
Hi, I'm running my environment with one main indexer and one search head. I have an index on the main indexer where...
by castle1126 Communicator in Splunk Search 07-28-2010
1 1
1
1
kholleran
Hello, I am running a search that returns all the failed logins across all servers that occurred in the last 15 minu...
by kholleran Communicator in Splunk Search 07-27-2010
0 3
0
3
Genti
I think it is taking splunk some time to capture new events. Is there a way to be able to tell exactly how long it ta...
by Genti Splunk Employee Splunk Employee in Splunk Search 07-27-2010
4 1
4
1
maverick
I have approximately sixty Splunk forwarders sending the Windows events to my central Splunk indexer. Fours of them a...
by maverick Splunk Employee Splunk Employee in Splunk Search 07-27-2010
0 3
0
3
Jason
I recently upgraded a Splunk environment from 3.4.x and the previous documentation included recommendations to disabl...
by Jason Motivator in Splunk Search 07-26-2010
2 1
2
1
EricPartington
THis might be a bit difficult, but i want to try anyways... I am trying to aggrgate source and destination IP address...
by EricPartington Communicator in Splunk Search 07-26-2010
0 2
0
2
andrejus7
Hello, Sorry, I am new to Splunk and having problems. I have loaded IIS logs (total 21 files) to splunk and wanted ...
by andrejus7 New Member in Splunk Search 07-23-2010
0 1
0
1
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors