Splunk Search

Splunk Search
Community Activity
maverick
Since it does not appear that you can pass a number into the random() function, I'm curious to know what is being use...
by maverick Splunk Employee Splunk Employee in Splunk Search 07-06-2010
3 3
3
3
Derek
I have an event that is coming from a Windows forwarder. When you view the event in the log file on the server it loo...
by Derek Path Finder in Splunk Search 07-03-2010
0 2
0
2
Derek
Ok. Not having a spectacular regex day... I have this: Recipients: joe.smith@mig.mydomain.com, jane.smith@mig.mydom...
by Derek Path Finder in Splunk Search 07-02-2010
1 2
1
2
jtwcarboy
I have saved searches and all of a sudden with no changes they are returning this error to the python.log file. ERRO...
by jtwcarboy New Member in Splunk Search 07-02-2010
0 7
0
7
Krishna_R
I'm unable to list the transactions that have events matching with startWith clause but no events for endsWith clause...
by Krishna_R Path Finder in Splunk Search 07-01-2010
1 9
1
9
pjmenon
I've been breaking my head over this very simple field extraction. My extraction (see eg., below) has problems beca...
by pjmenon Explorer in Splunk Search 07-01-2010
0 21
0
21
riderofyamaha
Is the wildcard search star * supported by logs in splunk? Im trying to see if splunk is seeing changes being made in...
by riderofyamaha Explorer in Splunk Search 07-01-2010
0 3
0
3
melonman
Hi, question about restoration of indexed data. I know how to restore(or search old) indexes data by putting necessa...
by melonman Motivator in Splunk Search 06-30-2010
1 1
1
1
the_wolverine
It looks like the Job Manager currently does not allow me to track CLI searches. Is there some way I can get a jobid...
by the_wolverine Champion in Splunk Search 06-29-2010
2 2
2
2
kalitbri
Hello, I found that when I use subsearch or join command to join data, I can't make splunk to return the complete ...
by kalitbri Explorer in Splunk Search 06-29-2010
0 3
0
3
bbear
Greetings. I am trying to use an expression in the search string that will not display certain IP addresses. I have ...
by bbear Explorer in Splunk Search 06-29-2010
1 4
1
4
hiwell
Hello, I am trying to extract fields from an event which looks like this (I have multiple events) total time (ms): ...
by hiwell Explorer in Splunk Search 06-29-2010
0 3
0
3
balbano
Hey guys, We are monitoring 2 specific CSV Log files on one indexer. I setup the appropriate custom field extractio...
by balbano Contributor in Splunk Search 06-29-2010
0 6
0
6
mcafeesecure
Basically I have a line of data that looks like this: Jun 28 14:15:10 sc4-app04.mcafeesecure.com portal: ACCESS Clic...
by mcafeesecure Explorer in Splunk Search 06-29-2010
3 3
3
3
Michael_Wilde
An auditor is requesting that we furnish them with a list of all servers logging to splunk and the index they are bei...
by Michael_Wilde Splunk Employee Splunk Employee in Splunk Search 06-29-2010
1 2
1
2
mawwx3
I have splunk indexing a local file that is being continuously written to and I need the first word in each event to ...
by mawwx3 Explorer in Splunk Search 06-28-2010
0 4
0
4
zliu
Search string "mismatch". The single event is about 2-3K lines or more. In the lines of text there are 5 lines with ...
by zliu Splunk Employee Splunk Employee in Splunk Search 06-28-2010
1 6
1
6
chowell
I need a regex that can process all security events with eventid 540 that don't contain $, SYSTEM, or ANONYMOUS LOGON...
by chowell Explorer in Splunk Search 06-28-2010
0 2
0
2
apro
I am scheduling this search(Daily Indexed Volume): index=_internal source=*metrics.log splunk_server="*" | eval MB=k...
by apro Path Finder in Splunk Search 06-28-2010
0 2
0
2
Lowell
I have a scenario where I would like to do a two-layered lookup. I'm essentially doing an IP address lookup against ...
by Lowell Super Champion in Splunk Search 06-25-2010
6 4
6
4
nate1
Below are the first 7 lines of a file that I want to index. The additional lines all look like line 7. Can I have it ...
by nate1 Explorer in Splunk Search 06-25-2010
1 2
1
2
thall79
Can I use eventtype=myevent with |metadata? example: | metadata type=hosts | eventtype=group_A I know tags work, ...
by thall79 Communicator in Splunk Search 06-25-2010
0 1
0
1
mfrost8
I have what I think should be a simple search, but I'm not quite able to come up with a way to do it. Ultimately I g...
by mfrost8 Builder in Splunk Search 06-25-2010
1 3
1
3
ericdp
I'm trying to correlate start and stop events and having a much harder time than what the documentation implies in or...
by ericdp Explorer in Splunk Search 06-25-2010
1 5
1
5
r31floyd
When we are browsing log files for problems, we often don't know exactly what we're looking for. But in a short peri...
by r31floyd Engager in Splunk Search 06-25-2010
0 4
0
4
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...