Splunk Search

Splunk Search
Community Activity
riderofyamaha
I want my table to show a column with what time a username connected to the network and another column showing when t...
by riderofyamaha Explorer in Splunk Search 07-19-2010
0 6
0
6
ljeffery
Im fairly new to splunk (and linux for that matter) but I am trying to find a Web Page or Manual or whaeter that will...
by ljeffery New Member in Splunk Search 07-19-2010
0 1
0
1
mcwomble
Hi, I would like to rewrite bogus field values that are negative to 0. For example I would like to run the followin...
by mcwomble Path Finder in Splunk Search 07-17-2010
0 1
0
1
muebel
I just set up a new splunk forwarder on a linux host. One of the inputs is a monitor of the /var/log/messages file. ...
by SplunkTrust SplunkTrust in Splunk Search 07-16-2010
1 3
1
3
meatago
I'm running Splunk 4.1.3 on Windows 2008 R2 x64 and had a poweroutage. The splunkd service will not restart. Crash ...
by meatago Explorer in Splunk Search 07-16-2010
0 1
0
1
the_wolverine
I have a REGEX configured (in transforms.conf) that works with my single line events, but appears to be failing on al...
by the_wolverine Champion in Splunk Search 07-16-2010
1 3
1
3
maverick
Which search below is better or optimal from a performance perspective and why? sourcetype="mysoucetype" AND field1=...
by maverick Splunk Employee Splunk Employee in Splunk Search 07-16-2010
4 3
4
3
Paolo_Prigione
I've noticed that on Splunk 4.1.3 the timechart and chart commands, when used with "limit=0", the "count" aggregation...
by Paolo_Prigione Builder in Splunk Search 07-15-2010
0 2
0
2
npt05001
I have a field in some events that contains a time as a string. The times are in the format "2010-07-15-13", which t...
by npt05001 Engager in Splunk Search 07-15-2010
0 2
0
2
remy06
I've tried to delete events for a particular source,say source="tcp:1234" | delete The operation was successful.How...
by remy06 Contributor in Splunk Search 07-15-2010
2 4
2
4
isnoop
I am building a search to find the average amount of time an action takes: sourcetype="timelog" | stats avg(reque...
by isnoop New Member in Splunk Search 07-15-2010
0 1
0
1
Simeon
I run a metadata search that populates a summary page to link to all of my tags. The goal of the summary page is to ...
by Simeon Splunk Employee Splunk Employee in Splunk Search 07-14-2010
1 1
1
1
Oren
We have a log line that looks like: Jul 14 15:47:34 127.0.0.1 1 [000004ff000216970000489c] Serv foo.com 158578_40df3...
by Oren Explorer in Splunk Search 07-14-2010
0 1
0
1
sony_1688
hello, my problem is: when I type the query in the search bar, such as: source="number.txt" it will so like that:...
by sony_1688 New Member in Splunk Search 07-13-2010
0 5
0
5
mohmed935
I get a lookup error "does not exist" after i upgraded to 4.1 almost in all apps, also my browser goes not responding...
by mohmed935 Engager in Splunk Search 07-13-2010
0 1
0
1
Brian_Osburn
I have an Apache Access log which I'm searching for any .cgi or .pl file hit with the latest date it's been hit. Som...
by Brian_Osburn Builder in Splunk Search 07-12-2010
2 2
2
2
muebel
I have a saved search that I modified in the Splunkweb Manager. I look at the same search in the savedsearch.conf fi...
by SplunkTrust SplunkTrust in Splunk Search 07-12-2010
1 5
1
5
imrago
I would like to create an alert if the number on events is different in two subsearches. subsearch1 = "index=index1 ...
by imrago Contributor in Splunk Search 07-12-2010
1 1
1
1
sureshchinta
I have setup alerts based on a scheduled search in the logs. The application writes a log messages every minute while...
by sureshchinta Explorer in Splunk Search 07-12-2010
1 1
1
1
benny8021
I could renamed the field of timechart. For example: Changed count to 'YYY' . But,I couldn't renamed the '_time' fiel...
by benny8021 New Member in Splunk Search 07-10-2010
0 1
0
1
b1nki3
I'm seeing this in my splunkd.log: 07-09-2010 12:53:21.299 WARN DateParserVerbose - Time parsed (Fri Jul 9 12:53:1...
by b1nki3 Explorer in Splunk Search 07-09-2010
0 2
0
2
b1nki3
I remember being able to include a standard text file, perhaps a .csv, in the 3.x branch. The search would then itera...
by b1nki3 Explorer in Splunk Search 07-09-2010
1 3
1
3
Lowell
Is there a kind of conditional search command that can be used to stop or prematurely terminate a search based on a g...
by Lowell Super Champion in Splunk Search 07-08-2010
2 2
2
2
jambajuice
We are required to produce monthly audits of access to files that are covered by SOX. There are 8 groups of folders ...
by jambajuice Communicator in Splunk Search 07-08-2010
0 1
0
1
alextsui
Hi. How would I run a search command in command line. The problem is that I would also like to set an alert condition...
by alextsui Path Finder in Splunk Search 07-08-2010
3 3
3
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...