| For some reason this search maxes out at 10000 (i.e. only returns 10000 sources, there are more...), and I can't seem... by parallaxed Path Finder in Splunk Search 06-02-2010 1 3 | 1 | 3 | ||
| Hi experts, I would like to know if it is possible to exclude the result of 'addcoltotals' from the y axis scale. ... by sflisher Explorer in Splunk Search 06-02-2010 1 1 | 1 | 1 | ||
| I have some log like following: 13:47:04 -2 receive request [type=0|desc=TimeStamp] <---event one | [8 ] [BCA3.5] | ... by mzorzi Splunk Employee 2 1 | 2 | 1 | ||
| I'm sure someone has figured out how to handle this data. What I am trying to do is index and extract all of the dat... by Steven_McGrath Engager in Splunk Search 06-02-2010 1 1 | 1 | 1 | ||
| I need to aggregate the values found in the apache weblogs. First I need to parse out several fields. I can get these... by pbenner Explorer in Splunk Search 06-01-2010 0 1 | 0 | 1 | ||
| i have a case to count db operations. in the log file, the format is like: [time1] op=select data=.... [time2] op=SE... by William Path Finder in Splunk Search 06-01-2010 1 1 | 1 | 1 | ||
| For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table",... by William Path Finder in Splunk Search 06-01-2010 0 3 | 0 | 3 | ||
| We've got log events that read like the following: Mar 14 12:26:38 mailsrv.example.com MM: [Jilter Processor 21 - ... by smisplunk Path Finder in Splunk Search 05-31-2010 1 7 | 1 | 7 | ||
| Hi All, I need a sanity check. This extraction seemed to work in 4.0, Can someone help? mac_address and source_ip ... by dcroteau Splunk Employee 0 4 | 0 | 4 | ||
| Running this search: http://host1.com:8000/en-US/app/search/flashtimeline?q=search%20* | regex_raw%3D%22%25SYS-5-CON... by Jaci Splunk Employee 3 2 | 3 | 2 | ||
| I am trying to setup a scheduled search that runs every morning and looks for users logged on between 2200 the previo... by Mike_Spellane New Member in Splunk Search 05-27-2010 0 2 | 0 | 2 | ||
| I am having trouble getting my form search to bring back anything. The xml is accepted by splunk but the search won't... by riderofyamaha Explorer in Splunk Search 05-27-2010 0 2 | 0 | 2 | ||
| I need help with a query to find the forwarders which stopped reporting for more than 2 weeks. by sanju005ind Communicator in Splunk Search 05-27-2010 0 4 | 0 | 4 | ||
| I've been able to get AmMap to work with scheduled searches. Is there a way to get it to work in realtime? I thought ... by jjernigan Engager in Splunk Search 05-27-2010 2 1 | 2 | 1 | ||
| I'm running Splunk 4.1.2. It seems that when Splunk sends out URL that correspond to searches (say when it triggers a... by mfrost8 Builder in Splunk Search 05-27-2010 1 2 | 1 | 2 | ||
| can I get transaction to show hostname or sourcetype for each event within? I'd like to be able to pass a transactio... by bfaber Communicator in Splunk Search 05-26-2010 0 5 | 0 | 5 | ||
| In inputs.conf and props.conf, the wildcards ... and * are supported for use in the spec headers. What do they trans... by hulahoop Splunk Employee 2 3 | 2 | 3 | ||
| While the following extraction below works, I wanted to see if I could extract both custom fields EAR_FILE and DOMAIN... by Rob_Jordan Explorer in Splunk Search 05-26-2010 2 2 | 2 | 2 | ||
| When searching for lost forwarders a host with an all caps name is returned as lost when the same host with a lower c... by rgcox1 Communicator in Splunk Search 05-26-2010 0 3 | 0 | 3 | ||
| If I have data like this: src=1.1.1.1 dst=2.2.2.2 can I create a mvfield of ip's? like: ips=1.1.1.1,2.2.2.2 FRO... by bfaber Communicator in Splunk Search 05-26-2010 1 2 | 1 | 2 | ||
| If I have data that looks like (date) srcip=x.x.x.x dstip=y.y.y.y How can I create a single list of all unique IPs... by bfaber Communicator in Splunk Search 05-26-2010 1 6 | 1 | 6 | ||
| Is there a way to report on the position of an event relative to the rest of the events in the result set? For examp... by maverick Splunk Employee 0 2 | 0 | 2 | ||
| How can I use lookups for a source CSV file that is not under the Splunk code tree? I am using Splunk 4.0.10. CSV lo... by nbharadwaj Path Finder in Splunk Search 05-24-2010 1 1 | 1 | 1 | ||
| We were on 3.4.6 and I think subsearches worked fine. We upgraded to 4.0.10 and they broke. So I upgraded to 4.1.1, ... by Genti Splunk Employee 1 4 | 1 | 4 | ||
| Hi all, I've got a problem with the execution of this command from a Windows ".bat" script: splunk.exe search "| sa... by logicasrl Explorer in Splunk Search 05-24-2010 0 8 | 0 | 8 |