Splunk Search

Splunk Search
Community Activity
Derek
If I have an event with more than one IP addres in it, how can I write a regex that will capture all of the IP's? Ex...
by Derek Path Finder in Splunk Search 06-23-2010
0 1
0
1
nik_splunk
Good morning, I'm developing for a customer a very simple search. tag=mysourcetype tag=myeventtype startdaysago=7 ...
by nik_splunk Path Finder in Splunk Search 06-23-2010
0 5
0
5
Lowell
What are the pros and cons to using an external lookup script vs a custom search command when the purpose is simply t...
by Lowell Super Champion in Splunk Search 06-22-2010
1 1
1
1
ericdp
I'm trying to calculate the amount of time between two events and I'm having a lot of trouble. Because of some requi...
by ericdp Explorer in Splunk Search 06-22-2010
0 2
0
2
amrit
Given servers A and B, how do you search both A AND B from server A, but disallow B from searching against A?
by amrit Splunk Employee Splunk Employee in Splunk Search 06-22-2010
3 3
3
3
kdankmyer
So, I have a big set of web stats for a given time in a search. Basically, I want it broken down by uri_path and for ...
by kdankmyer Engager in Splunk Search 06-21-2010
1 3
1
3
Tisiphone_1
I am trying to compare the results of two searches that share a common timeframe and index, with a negation. The comm...
by Tisiphone_1 Explorer in Splunk Search 06-19-2010
0 2
0
2
smisplunk
In a view like the flashtimeline, there is a selector to choose between the results of the search and the log events ...
by smisplunk Path Finder in Splunk Search 06-18-2010
0 6
0
6
jwestberg
I have a search where I have been using "latesttime=-2d@d" to specify the time range, like so: ... latesttime=-2d@d ...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 06-18-2010
1 5
1
5
manuarora
I am doing a search which gives me two fields and say parent1 and child1...n so with parent and child I have 1 to n r...
by manuarora Explorer in Splunk Search 06-18-2010
1 6
1
6
ifeldshteyn
Hello there, Is it possible to chart a multivalued field against another multivalued field of the same size? For ex...
by ifeldshteyn Communicator in Splunk Search 06-18-2010
0 3
0
3
Jaci
We have many hosts running backups every night and report back if they are successful or not. I would like to simpli...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-17-2010
1 2
1
2
Lowell
I have a summary index search that does some simple stats (count) by host and sourcetype for WMI events. The problem...
by Lowell Super Champion in Splunk Search 06-17-2010
0 1
0
1
balt
Hello folks, I am having a difficult time extracting fields properly from the sudo.log file on several of our servers...
by balt New Member in Splunk Search 06-17-2010
0 2
0
2
jrodman
After upgrading, when accessing field extraction page in manager in 4.1, it doesn't work. This appears in splunkd.lo...
by jrodman Splunk Employee Splunk Employee in Splunk Search 06-17-2010
1 1
1
1
Starlette
For example DATA test1, test2, test3 so just add the DELIMS = "," in transforms and REPORT-test entry in pro...
by Starlette Contributor in Splunk Search 06-17-2010
0 2
0
2
bnolen
Hi all, I have logs in the following format 2010-06-17 02:04:55 user1 ip.add.ress.here GET /mysite/mypage.html 2010...
by bnolen Path Finder in Splunk Search 06-17-2010
2 1
2
1
sranga
Hi I am seeing some weirdness with one of the saved-searches that we have. One of these searches is of the form: ...
by sranga Path Finder in Splunk Search 06-16-2010
0 4
0
4
bbear
I have Splunk set up to monitor syslog on udp 514. Splunk is receiving event logs from several servers. When search...
by bbear Explorer in Splunk Search 06-16-2010
2 5
2
5
pjmenon
I am evaluating SPLUNK for my client. Reading previous questions tells me I can do this, but want to confirm. have 2...
by pjmenon Explorer in Splunk Search 06-16-2010
0 3
0
3
mtxpert
I tried for an hour but couldn't find the answer. I need to search my syslogs from a specific host for entries that d...
by mtxpert Engager in Splunk Search 06-15-2010
1 1
1
1
twinspop
Trying to get a transaction search to work. The transaction is logged in 2 different log sources, with the matching f...
by twinspop Influencer in Splunk Search 06-15-2010
0 2
0
2
Lowell
Anyone familiar with the following message? I found this in search.log. WARN MetaDataCache - not all cwpairs we...
by Lowell Super Champion in Splunk Search 06-15-2010
0 1
0
1
Hazel
Hello, We currently have a Splunk setup as follows UAT: Three indexers (NY, LDN, SGP), each collect data from forwa...
by Hazel Communicator in Splunk Search 06-15-2010
0 5
0
5
hans
If I have one event such as: 2010-06-10 15:01:16,882 .main INFO :: x=1 x=12 x=154 x=123 x=123 will it be able t...
by hans Splunk Employee Splunk Employee in Splunk Search 06-14-2010
0 5
0
5
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors