Splunk Search

Splunk Search
Community Activity
vadud3
* | rex "(?<fpc>fpc\d+) (?<ichip>ICHIP\(\d+\)):Packet drop in Ichip pktwr,rate: %\S+: \d+, total: (?<err>\d+)" How ...
by vadud3 Path Finder in Splunk Search 08-12-2010
0 3
0
3
carmackd
I have a log file that looks like this: Wed Aug 11 14:27:48 GMT 2010 | Inactive Users Last 7 Days---> | 123456789 | ...
by carmackd Communicator in Splunk Search 08-11-2010
0 2
0
2
kbecker
What is the best way to determine transactions per second are occurring in our application logs. I attempted using "...
by kbecker Communicator in Splunk Search 08-11-2010
0 2
0
2
Justin_Grant
I have two searches. One search returns a field (using stats count) representing the number of users logging into a w...
by Justin_Grant Contributor in Splunk Search 08-10-2010
1 1
1
1
Peter
Is it possible to use regular expressions for the whitelist/blacklist filters in serverclass.conf? For example: whit...
by Peter Path Finder in Splunk Search 08-10-2010
1 3
1
3
imrago
On splunkA I am monitoring an xml log file. It is forwarded to SplunkB in a separate index. Where should I define the...
by imrago Contributor in Splunk Search 08-10-2010
0 1
0
1
whywhywhy
I have a search that is looking pipes through a rex. rex fields=_raw "\D(?<big_num>\d{15,16})\D" I want the UI to ...
by whywhywhy Engager in Splunk Search 08-09-2010
1 2
1
2
vcarbona
Here's my CLI search: SPLUNK_URI=https://splunk_search_head:8089 /opt/splunk/bin/splunk search '|savedsearch "mysav...
by vcarbona Path Finder in Splunk Search 08-08-2010
2 4
2
4
serialmonkey
I get lots of data from various systems via syslog. One of my systems sends me data that looks like this HEADERTEXT:...
by serialmonkey Path Finder in Splunk Search 08-07-2010
1 5
1
5
sranga
Hi We have a few charts that display summary-indexed data. The charts take a couple of form inputs including _time...
by sranga Path Finder in Splunk Search 08-06-2010
0 7
0
7
twinspop
(Love this forum. Didn't even know about the concurrency command before this morning.  My search: SYSCODE=ezLMWeb*...
by twinspop Influencer in Splunk Search 08-06-2010
0 3
0
3
bfaber
There is probably a better way to do this, but I am trying to catalog what rules are (and are not) used using the fir...
by bfaber Communicator in Splunk Search 08-06-2010
0 5
0
5
goat
I am currently running a search for license bandwidth : index=_internal source=*metrics.log group=per_index_thruput ...
by goat Explorer in Splunk Search 08-05-2010
1 4
1
4
kseshadri
Running splunk on windows2003. I am getting the events but it seems my regex is not working right on the event. Sam...
by kseshadri New Member in Splunk Search 08-02-2010
0 1
0
1
kholleran
Hello, I have a search that looks for a particular set of data. if the data comes from a particular source address,...
by kholleran Communicator in Splunk Search 08-02-2010
1 1
1
1
cafissimo
Hello, I have a log file with a very long record (about 255 chars) and I would like to know if and how is it possible...
by cafissimo Communicator in Splunk Search 08-02-2010
0 1
0
1
kholleran
Hello, I am asking a lot of questions today (obviously new to Splunk and in implementation...). We do NOT use AD fo...
by kholleran Communicator in Splunk Search 08-02-2010
2 2
2
2
rgcox1
I'm trying to develop a regex to separate merged events from a log. Here's my stanza in props.conf: [source=c:\temp\...
by rgcox1 Communicator in Splunk Search 07-30-2010
0 2
0
2
rroberts
Is there a search to check bundles delivered from search head to peers?
by rroberts Splunk Employee Splunk Employee in Splunk Search 07-30-2010
2 2
2
2
jonathanjw
For starters this app is amazing. I am trying to search a ton of log files for a certain error and its definitely do...
by jonathanjw New Member in Splunk Search 07-30-2010
0 1
0
1
ankitghai
Below are the two files tcodesNew.csv paste.plurk.com/show/284992 chlogNew.csv paste.plurk.com/show/284990 I am tryi...
by ankitghai New Member in Splunk Search 07-30-2010
0 1
0
1
swackhap
Can Splunk index SQL LDF and MDF files?
by swackhap Explorer in Splunk Search 07-30-2010
0 2
0
2
morningwood
Unfortunately our proxy data does not have user information. However I do have access to AV data that is able to map ...
by morningwood Explorer in Splunk Search 07-29-2010
0 2
0
2
kholleran
I have a best practice time question for veteran Splunkers out there. Right now I have a a failed login search that ...
by kholleran Communicator in Splunk Search 07-29-2010
2 1
2
1
skippylou
Trying to figure out how to aggregate with top when there are two field choices. Here's an example of what I am tryi...
by skippylou Communicator in Splunk Search 07-28-2010
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...