Splunk Search

Splunk Search
Community Activity
mcafeesecure
Basically I have a line of data that looks like this: Jun 28 14:15:10 sc4-app04.mcafeesecure.com portal: ACCESS Clic...
by mcafeesecure Explorer in Splunk Search 06-29-2010
3 3
3
3
Michael_Wilde
An auditor is requesting that we furnish them with a list of all servers logging to splunk and the index they are bei...
by Michael_Wilde Splunk Employee Splunk Employee in Splunk Search 06-29-2010
1 2
1
2
mawwx3
I have splunk indexing a local file that is being continuously written to and I need the first word in each event to ...
by mawwx3 Explorer in Splunk Search 06-28-2010
0 4
0
4
zliu
Search string "mismatch". The single event is about 2-3K lines or more. In the lines of text there are 5 lines with ...
by zliu Splunk Employee Splunk Employee in Splunk Search 06-28-2010
1 6
1
6
chowell
I need a regex that can process all security events with eventid 540 that don't contain $, SYSTEM, or ANONYMOUS LOGON...
by chowell Explorer in Splunk Search 06-28-2010
0 2
0
2
apro
I am scheduling this search(Daily Indexed Volume): index=_internal source=*metrics.log splunk_server="*" | eval MB=k...
by apro Path Finder in Splunk Search 06-28-2010
0 2
0
2
Lowell
I have a scenario where I would like to do a two-layered lookup. I'm essentially doing an IP address lookup against ...
by Lowell Super Champion in Splunk Search 06-25-2010
6 4
6
4
nate1
Below are the first 7 lines of a file that I want to index. The additional lines all look like line 7. Can I have it ...
by nate1 Explorer in Splunk Search 06-25-2010
1 2
1
2
thall79
Can I use eventtype=myevent with |metadata? example: | metadata type=hosts | eventtype=group_A I know tags work, ...
by thall79 Communicator in Splunk Search 06-25-2010
0 1
0
1
mfrost8
I have what I think should be a simple search, but I'm not quite able to come up with a way to do it. Ultimately I g...
by mfrost8 Builder in Splunk Search 06-25-2010
1 3
1
3
ericdp
I'm trying to correlate start and stop events and having a much harder time than what the documentation implies in or...
by ericdp Explorer in Splunk Search 06-25-2010
1 5
1
5
r31floyd
When we are browsing log files for problems, we often don't know exactly what we're looking for. But in a short peri...
by r31floyd Engager in Splunk Search 06-25-2010
0 4
0
4
the_wolverine
index="whatever" INFECTION | top limit="15" misc by src When I attempt this search, the limit qualifier seems to be...
by the_wolverine Champion in Splunk Search 06-24-2010
0 4
0
4
Carmageddon
Hello, I would like to filter a search result, of irrelevant data, to display less information so its easier to spot...
by Carmageddon New Member in Splunk Search 06-24-2010
0 10
0
10
sanju005ind
I have 4 servers in a distributed environment. I use server a to login and do the search. When I use the search | me...
by sanju005ind Communicator in Splunk Search 06-24-2010
0 2
0
2
enielson
I have taken iplocation.py as a skeleton for a simple custom search command that adds another column to the search re...
by enielson Explorer in Splunk Search 06-23-2010
4 2
4
2
Jason
Is there a way to have REST look up the latest results from a scheduled search and return them, not re-running the se...
by Jason Motivator in Splunk Search 06-23-2010
2 1
2
1
rsimmons
I moved my Splunk instance to another machine and I'm getting the following error message: 2010-06-15 16:20:24,739 ER...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 06-23-2010
0 1
0
1
Jaci
I find the document about auto finalize in this page http://zh-hant.splunk.com/base/Documentation/latest/Developer/RE...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-23-2010
1 2
1
2
Derek
If I have an event with more than one IP addres in it, how can I write a regex that will capture all of the IP's? Ex...
by Derek Path Finder in Splunk Search 06-23-2010
0 1
0
1
nik_splunk
Good morning, I'm developing for a customer a very simple search. tag=mysourcetype tag=myeventtype startdaysago=7 ...
by nik_splunk Path Finder in Splunk Search 06-23-2010
0 5
0
5
Lowell
What are the pros and cons to using an external lookup script vs a custom search command when the purpose is simply t...
by Lowell Super Champion in Splunk Search 06-22-2010
1 1
1
1
ericdp
I'm trying to calculate the amount of time between two events and I'm having a lot of trouble. Because of some requi...
by ericdp Explorer in Splunk Search 06-22-2010
0 2
0
2
amrit
Given servers A and B, how do you search both A AND B from server A, but disallow B from searching against A?
by amrit Splunk Employee Splunk Employee in Splunk Search 06-22-2010
3 3
3
3
kdankmyer
So, I have a big set of web stats for a given time in a search. Basically, I want it broken down by uri_path and for ...
by kdankmyer Engager in Splunk Search 06-21-2010
1 3
1
3
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...