Splunk Search

Splunk Search
Community Activity
sanju005ind
I have 4 servers in a distributed environment. I use server a to login and do the search. When I use the search | me...
by sanju005ind Communicator in Splunk Search 06-24-2010
0 2
0
2
enielson
I have taken iplocation.py as a skeleton for a simple custom search command that adds another column to the search re...
by enielson Explorer in Splunk Search 06-23-2010
4 2
4
2
Jason
Is there a way to have REST look up the latest results from a scheduled search and return them, not re-running the se...
by Jason Motivator in Splunk Search 06-23-2010
2 1
2
1
rsimmons
I moved my Splunk instance to another machine and I'm getting the following error message: 2010-06-15 16:20:24,739 ER...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 06-23-2010
0 1
0
1
Jaci
I find the document about auto finalize in this page http://zh-hant.splunk.com/base/Documentation/latest/Developer/RE...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-23-2010
1 2
1
2
Derek
If I have an event with more than one IP addres in it, how can I write a regex that will capture all of the IP's? Ex...
by Derek Path Finder in Splunk Search 06-23-2010
0 1
0
1
nik_splunk
Good morning, I'm developing for a customer a very simple search. tag=mysourcetype tag=myeventtype startdaysago=7 ...
by nik_splunk Path Finder in Splunk Search 06-23-2010
0 5
0
5
Lowell
What are the pros and cons to using an external lookup script vs a custom search command when the purpose is simply t...
by Lowell Super Champion in Splunk Search 06-22-2010
1 1
1
1
ericdp
I'm trying to calculate the amount of time between two events and I'm having a lot of trouble. Because of some requi...
by ericdp Explorer in Splunk Search 06-22-2010
0 2
0
2
amrit
Given servers A and B, how do you search both A AND B from server A, but disallow B from searching against A?
by amrit Splunk Employee Splunk Employee in Splunk Search 06-22-2010
3 3
3
3
kdankmyer
So, I have a big set of web stats for a given time in a search. Basically, I want it broken down by uri_path and for ...
by kdankmyer Engager in Splunk Search 06-21-2010
1 3
1
3
Tisiphone_1
I am trying to compare the results of two searches that share a common timeframe and index, with a negation. The comm...
by Tisiphone_1 Explorer in Splunk Search 06-19-2010
0 2
0
2
smisplunk
In a view like the flashtimeline, there is a selector to choose between the results of the search and the log events ...
by smisplunk Path Finder in Splunk Search 06-18-2010
0 6
0
6
jwestberg
I have a search where I have been using "latesttime=-2d@d" to specify the time range, like so: ... latesttime=-2d@d ...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 06-18-2010
1 5
1
5
manuarora
I am doing a search which gives me two fields and say parent1 and child1...n so with parent and child I have 1 to n r...
by manuarora Explorer in Splunk Search 06-18-2010
1 6
1
6
ifeldshteyn
Hello there, Is it possible to chart a multivalued field against another multivalued field of the same size? For ex...
by ifeldshteyn Communicator in Splunk Search 06-18-2010
0 3
0
3
Jaci
We have many hosts running backups every night and report back if they are successful or not. I would like to simpli...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-17-2010
1 2
1
2
Lowell
I have a summary index search that does some simple stats (count) by host and sourcetype for WMI events. The problem...
by Lowell Super Champion in Splunk Search 06-17-2010
0 1
0
1
balt
Hello folks, I am having a difficult time extracting fields properly from the sudo.log file on several of our servers...
by balt New Member in Splunk Search 06-17-2010
0 2
0
2
jrodman
After upgrading, when accessing field extraction page in manager in 4.1, it doesn't work. This appears in splunkd.lo...
by jrodman Splunk Employee Splunk Employee in Splunk Search 06-17-2010
1 1
1
1
Starlette
For example DATA test1, test2, test3 so just add the DELIMS = "," in transforms and REPORT-test entry in pro...
by Starlette Contributor in Splunk Search 06-17-2010
0 2
0
2
bnolen
Hi all, I have logs in the following format 2010-06-17 02:04:55 user1 ip.add.ress.here GET /mysite/mypage.html 2010...
by bnolen Path Finder in Splunk Search 06-17-2010
2 1
2
1
sranga
Hi I am seeing some weirdness with one of the saved-searches that we have. One of these searches is of the form: ...
by sranga Path Finder in Splunk Search 06-16-2010
0 4
0
4
bbear
I have Splunk set up to monitor syslog on udp 514. Splunk is receiving event logs from several servers. When search...
by bbear Explorer in Splunk Search 06-16-2010
2 5
2
5
pjmenon
I am evaluating SPLUNK for my client. Reading previous questions tells me I can do this, but want to confirm. have 2...
by pjmenon Explorer in Splunk Search 06-16-2010
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...