Splunk Search

Splunk Search
Community Activity
Brian_Osburn
I have an Apache Access log which I'm searching for any .cgi or .pl file hit with the latest date it's been hit. Som...
by Brian_Osburn Builder in Splunk Search 07-12-2010
2 2
2
2
muebel
I have a saved search that I modified in the Splunkweb Manager. I look at the same search in the savedsearch.conf fi...
by SplunkTrust SplunkTrust in Splunk Search 07-12-2010
1 5
1
5
imrago
I would like to create an alert if the number on events is different in two subsearches. subsearch1 = "index=index1 ...
by imrago Contributor in Splunk Search 07-12-2010
1 1
1
1
sureshchinta
I have setup alerts based on a scheduled search in the logs. The application writes a log messages every minute while...
by sureshchinta Explorer in Splunk Search 07-12-2010
1 1
1
1
benny8021
I could renamed the field of timechart. For example: Changed count to 'YYY' . But,I couldn't renamed the '_time' fiel...
by benny8021 New Member in Splunk Search 07-10-2010
0 1
0
1
b1nki3
I'm seeing this in my splunkd.log: 07-09-2010 12:53:21.299 WARN DateParserVerbose - Time parsed (Fri Jul 9 12:53:1...
by b1nki3 Explorer in Splunk Search 07-09-2010
0 2
0
2
b1nki3
I remember being able to include a standard text file, perhaps a .csv, in the 3.x branch. The search would then itera...
by b1nki3 Explorer in Splunk Search 07-09-2010
1 3
1
3
Lowell
Is there a kind of conditional search command that can be used to stop or prematurely terminate a search based on a g...
by Lowell Super Champion in Splunk Search 07-08-2010
2 2
2
2
jambajuice
We are required to produce monthly audits of access to files that are covered by SOX. There are 8 groups of folders ...
by jambajuice Communicator in Splunk Search 07-08-2010
0 1
0
1
alextsui
Hi. How would I run a search command in command line. The problem is that I would also like to set an alert condition...
by alextsui Path Finder in Splunk Search 07-08-2010
3 3
3
3
klkumar10
I have the following content in the log file ==== ONLN|2010-07-06 13:53:52.000|test.tester.com|1068|db_server_name|...
by klkumar10 Explorer in Splunk Search 07-08-2010
0 5
0
5
muebel
I am indexing results from facter which logs information about each host. I can get the most up to date list of thes...
by SplunkTrust SplunkTrust in Splunk Search 07-07-2010
0 4
0
4
srw46
Hello, I am trying to compare two fields with a simple operator but it does not seem to perform as expected. I am s...
by srw46 Path Finder in Splunk Search 07-07-2010
1 2
1
2
jwestberg
In a datasource that uses single quotes as the event delimiter, like so: field1='value1' field2='value2' field3='' ...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 07-07-2010
2 10
2
10
treena
Hi, We've created two transactions to correlate logs spanning several components. We needed to define alias terms ...
by treena Explorer in Splunk Search 07-06-2010
5 6
5
6
Lowell
I'm running into some really slow performance searching on WMI sources. In this case I'm just trying to get some gen...
by Lowell Super Champion in Splunk Search 07-06-2010
1 3
1
3
Derek
Does anyone have a good way (or am I missing the something obvious?) of calculating for a defined time range the aver...
by Derek Path Finder in Splunk Search 07-06-2010
0 2
0
2
maverick
Since it does not appear that you can pass a number into the random() function, I'm curious to know what is being use...
by maverick Splunk Employee Splunk Employee in Splunk Search 07-06-2010
3 3
3
3
Derek
I have an event that is coming from a Windows forwarder. When you view the event in the log file on the server it loo...
by Derek Path Finder in Splunk Search 07-03-2010
0 2
0
2
Derek
Ok. Not having a spectacular regex day... I have this: Recipients: joe.smith@mig.mydomain.com, jane.smith@mig.mydom...
by Derek Path Finder in Splunk Search 07-02-2010
1 2
1
2
jtwcarboy
I have saved searches and all of a sudden with no changes they are returning this error to the python.log file. ERRO...
by jtwcarboy New Member in Splunk Search 07-02-2010
0 7
0
7
Krishna_R
I'm unable to list the transactions that have events matching with startWith clause but no events for endsWith clause...
by Krishna_R Path Finder in Splunk Search 07-01-2010
1 9
1
9
pjmenon
I've been breaking my head over this very simple field extraction. My extraction (see eg., below) has problems beca...
by pjmenon Explorer in Splunk Search 07-01-2010
0 21
0
21
riderofyamaha
Is the wildcard search star * supported by logs in splunk? Im trying to see if splunk is seeing changes being made in...
by riderofyamaha Explorer in Splunk Search 07-01-2010
0 3
0
3
melonman
Hi, question about restoration of indexed data. I know how to restore(or search old) indexes data by putting necessa...
by melonman Motivator in Splunk Search 06-30-2010
1 1
1
1
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors