Splunk Search

Splunk Search
Community Activity
the_wolverine
I have a REGEX configured (in transforms.conf) that works with my single line events, but appears to be failing on al...
by the_wolverine Champion in Splunk Search 07-16-2010
1 3
1
3
maverick
Which search below is better or optimal from a performance perspective and why? sourcetype="mysoucetype" AND field1=...
by maverick Splunk Employee Splunk Employee in Splunk Search 07-16-2010
4 3
4
3
Paolo_Prigione
I've noticed that on Splunk 4.1.3 the timechart and chart commands, when used with "limit=0", the "count" aggregation...
by Paolo_Prigione Builder in Splunk Search 07-15-2010
0 2
0
2
npt05001
I have a field in some events that contains a time as a string. The times are in the format "2010-07-15-13", which t...
by npt05001 Engager in Splunk Search 07-15-2010
0 2
0
2
remy06
I've tried to delete events for a particular source,say source="tcp:1234" | delete The operation was successful.How...
by remy06 Contributor in Splunk Search 07-15-2010
2 4
2
4
isnoop
I am building a search to find the average amount of time an action takes: sourcetype="timelog" | stats avg(reque...
by isnoop New Member in Splunk Search 07-15-2010
0 1
0
1
Simeon
I run a metadata search that populates a summary page to link to all of my tags. The goal of the summary page is to ...
by Simeon Splunk Employee Splunk Employee in Splunk Search 07-14-2010
1 1
1
1
Oren
We have a log line that looks like: Jul 14 15:47:34 127.0.0.1 1 [000004ff000216970000489c] Serv foo.com 158578_40df3...
by Oren Explorer in Splunk Search 07-14-2010
0 1
0
1
sony_1688
hello, my problem is: when I type the query in the search bar, such as: source="number.txt" it will so like that:...
by sony_1688 New Member in Splunk Search 07-13-2010
0 5
0
5
mohmed935
I get a lookup error "does not exist" after i upgraded to 4.1 almost in all apps, also my browser goes not responding...
by mohmed935 Engager in Splunk Search 07-13-2010
0 1
0
1
Brian_Osburn
I have an Apache Access log which I'm searching for any .cgi or .pl file hit with the latest date it's been hit. Som...
by Brian_Osburn Builder in Splunk Search 07-12-2010
2 2
2
2
muebel
I have a saved search that I modified in the Splunkweb Manager. I look at the same search in the savedsearch.conf fi...
by SplunkTrust SplunkTrust in Splunk Search 07-12-2010
1 5
1
5
imrago
I would like to create an alert if the number on events is different in two subsearches. subsearch1 = "index=index1 ...
by imrago Contributor in Splunk Search 07-12-2010
1 1
1
1
sureshchinta
I have setup alerts based on a scheduled search in the logs. The application writes a log messages every minute while...
by sureshchinta Explorer in Splunk Search 07-12-2010
1 1
1
1
benny8021
I could renamed the field of timechart. For example: Changed count to 'YYY' . But,I couldn't renamed the '_time' fiel...
by benny8021 New Member in Splunk Search 07-10-2010
0 1
0
1
b1nki3
I'm seeing this in my splunkd.log: 07-09-2010 12:53:21.299 WARN DateParserVerbose - Time parsed (Fri Jul 9 12:53:1...
by b1nki3 Explorer in Splunk Search 07-09-2010
0 2
0
2
b1nki3
I remember being able to include a standard text file, perhaps a .csv, in the 3.x branch. The search would then itera...
by b1nki3 Explorer in Splunk Search 07-09-2010
1 3
1
3
Lowell
Is there a kind of conditional search command that can be used to stop or prematurely terminate a search based on a g...
by Lowell Super Champion in Splunk Search 07-08-2010
2 2
2
2
jambajuice
We are required to produce monthly audits of access to files that are covered by SOX. There are 8 groups of folders ...
by jambajuice Communicator in Splunk Search 07-08-2010
0 1
0
1
alextsui
Hi. How would I run a search command in command line. The problem is that I would also like to set an alert condition...
by alextsui Path Finder in Splunk Search 07-08-2010
3 3
3
3
klkumar10
I have the following content in the log file ==== ONLN|2010-07-06 13:53:52.000|test.tester.com|1068|db_server_name|...
by klkumar10 Explorer in Splunk Search 07-08-2010
0 5
0
5
muebel
I am indexing results from facter which logs information about each host. I can get the most up to date list of thes...
by SplunkTrust SplunkTrust in Splunk Search 07-07-2010
0 4
0
4
srw46
Hello, I am trying to compare two fields with a simple operator but it does not seem to perform as expected. I am s...
by srw46 Path Finder in Splunk Search 07-07-2010
1 2
1
2
jwestberg
In a datasource that uses single quotes as the event delimiter, like so: field1='value1' field2='value2' field3='' ...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 07-07-2010
2 10
2
10
treena
Hi, We've created two transactions to correlate logs spanning several components. We needed to define alias terms ...
by treena Explorer in Splunk Search 07-06-2010
5 6
5
6
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors