Splunk Search

Splunk Search
Community Activity
twinspop
Trying to get a transaction search to work. The transaction is logged in 2 different log sources, with the matching f...
by twinspop Influencer in Splunk Search 06-15-2010
0 2
0
2
Lowell
Anyone familiar with the following message? I found this in search.log. WARN MetaDataCache - not all cwpairs we...
by Lowell Super Champion in Splunk Search 06-15-2010
0 1
0
1
Hazel
Hello, We currently have a Splunk setup as follows UAT: Three indexers (NY, LDN, SGP), each collect data from forwa...
by Hazel Communicator in Splunk Search 06-15-2010
0 5
0
5
hans
If I have one event such as: 2010-06-10 15:01:16,882 .main INFO :: x=1 x=12 x=154 x=123 x=123 will it be able t...
by hans Splunk Employee Splunk Employee in Splunk Search 06-14-2010
0 5
0
5
GratefulDude
I would like to create a report that counts the number of times I see an error log in one file with a count of events...
by GratefulDude Explorer in Splunk Search 06-14-2010
0 3
0
3
Lowell
Does anyone know what this message means? 06-14-2010 15:45:14.859 WARN SearchResults - Corrupt csv header, 2 col...
by Lowell Super Champion in Splunk Search 06-14-2010
0 1
0
1
GratefulDude
I have application logs that will create a log when a user makes a request like: 2010-02-17 16:13:28.515 host1:11...
by GratefulDude Explorer in Splunk Search 06-14-2010
2 6
2
6
aoates
We’re looking for a way to support a number of identical named environments, such as UIT1, UIT2, etc. Each environm...
by aoates Splunk Employee Splunk Employee in Splunk Search 06-14-2010
2 4
2
4
pmelchiori
Hi, I need to export using CLI the Splunk search results. I've created a Windows Custom Search, now I want to export ...
by pmelchiori Explorer in Splunk Search 06-14-2010
0 3
0
3
kalitbri
How to calculate (total or YTD/year-to-date) accumulated count based on region (or other group) in a search request? ...
by kalitbri Explorer in Splunk Search 06-14-2010
0 3
0
3
Tisiphone_1
When I use 'top' to create a top n list of fields, and I add two fields, using by, so: top field1 by field2 if eit...
by Tisiphone_1 Explorer in Splunk Search 06-12-2010
1 2
1
2
sanju005ind
I am using the following query to get the output of all my forwardars/hosts |metadata type=hosts | eval age = now()...
by sanju005ind Communicator in Splunk Search 06-12-2010
1 4
1
4
jwestberg
I have a search that searches in a time span set by a TimeRangePicker. I would like for the drilldown search that I p...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 06-12-2010
0 1
0
1
stephanbuys
How does the unexpectedness score actually get computed? How does the anolamies command play out if I have n events? ...
by stephanbuys Path Finder in Splunk Search 06-11-2010
2 1
2
1
novaMark
I have a dashboard I've put together that runs one hiddensearch with three wildcard search parameters (time, virus na...
by novaMark New Member in Splunk Search 06-11-2010
0 9
0
9
mfan1995
can I install splunk in a Solaris 10 non-global zone?
by mfan1995 Engager in Splunk Search 06-11-2010
1 3
1
3
lmorris99
I run search, hit the arrow, pick extract fields, give it samples, test it, and save it under the name "filesize". B...
by lmorris99 New Member in Splunk Search 06-11-2010
0 3
0
3
Krishna_R
Hi, I'm a Splunk newbie and I'm trying to write some queries for our logs using 'transaction'. Our logs have multip...
by Krishna_R Path Finder in Splunk Search 06-10-2010
1 8
1
8
sdagostino
Is there a way in Splunk to add a description (type of device ie Nortel 8600) or replace the Host IP address with the...
by sdagostino Engager in Splunk Search 06-10-2010
1 1
1
1
aoates
what options are available to make it clear to Splunk that particular log streams come from named environments and ap...
by aoates Splunk Employee Splunk Employee in Splunk Search 06-10-2010
1 1
1
1
zliu
"The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration 'ntsyslog:security'." Th...
by zliu Splunk Employee Splunk Employee in Splunk Search 06-10-2010
0 1
0
1
pbenner
I need to enrich my event data (web logs) with several other fields based on a value of one of the events fields. I p...
by pbenner Explorer in Splunk Search 06-09-2010
0 1
0
1
mctester
If I write a custom command, where does it need to be located if I have a distributed search setup? On the local splu...
by mctester Communicator in Splunk Search 06-09-2010
0 1
0
1
kbains
Can you have both span=x and bins=y in timechart? If both are specified, which one wins?
by kbains Splunk Employee Splunk Employee in Splunk Search 06-08-2010
0 4
0
4
cmeredith
I'm new to Splunk and I have a question about how to query the information I need. I'm indexing IIS web server logs....
by cmeredith Engager in Splunk Search 06-07-2010
2 2
2
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...