Splunk Search

Splunk Search
Community Activity
dcroteau
Hi All, I need a sanity check. This extraction seemed to work in 4.0, Can someone help? mac_address and source_ip ...
by dcroteau Splunk Employee Splunk Employee in Splunk Search 05-30-2010
0 4
0
4
Jaci
Running this search: http://host1.com:8000/en-US/app/search/flashtimeline?q=search%20* | regex_raw%3D%22%25SYS-5-CON...
by Jaci Splunk Employee Splunk Employee in Splunk Search 05-28-2010
3 2
3
2
Mike_Spellane
I am trying to setup a scheduled search that runs every morning and looks for users logged on between 2200 the previo...
by Mike_Spellane New Member in Splunk Search 05-27-2010
0 2
0
2
riderofyamaha
I am having trouble getting my form search to bring back anything. The xml is accepted by splunk but the search won't...
by riderofyamaha Explorer in Splunk Search 05-27-2010
0 2
0
2
sanju005ind
I need help with a query to find the forwarders which stopped reporting for more than 2 weeks.
by sanju005ind Communicator in Splunk Search 05-27-2010
0 4
0
4
jjernigan
I've been able to get AmMap to work with scheduled searches. Is there a way to get it to work in realtime? I thought ...
by jjernigan Engager in Splunk Search 05-27-2010
2 1
2
1
mfrost8
I'm running Splunk 4.1.2. It seems that when Splunk sends out URL that correspond to searches (say when it triggers a...
by mfrost8 Builder in Splunk Search 05-27-2010
1 2
1
2
bfaber
can I get transaction to show hostname or sourcetype for each event within? I'd like to be able to pass a transactio...
by bfaber Communicator in Splunk Search 05-26-2010
0 5
0
5
hulahoop
In inputs.conf and props.conf, the wildcards ... and * are supported for use in the spec headers. What do they trans...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 05-26-2010
2 3
2
3
Rob_Jordan
While the following extraction below works, I wanted to see if I could extract both custom fields EAR_FILE and DOMAIN...
by Rob_Jordan Explorer in Splunk Search 05-26-2010
2 2
2
2
rgcox1
When searching for lost forwarders a host with an all caps name is returned as lost when the same host with a lower c...
by rgcox1 Communicator in Splunk Search 05-26-2010
0 3
0
3
bfaber
If I have data like this: src=1.1.1.1 dst=2.2.2.2 can I create a mvfield of ip's? like: ips=1.1.1.1,2.2.2.2 FRO...
by bfaber Communicator in Splunk Search 05-26-2010
1 2
1
2
bfaber
If I have data that looks like (date) srcip=x.x.x.x dstip=y.y.y.y How can I create a single list of all unique IPs...
by bfaber Communicator in Splunk Search 05-26-2010
1 6
1
6
maverick
Is there a way to report on the position of an event relative to the rest of the events in the result set? For examp...
by maverick Splunk Employee Splunk Employee in Splunk Search 05-25-2010
0 2
0
2
nbharadwaj
How can I use lookups for a source CSV file that is not under the Splunk code tree? I am using Splunk 4.0.10. CSV lo...
by nbharadwaj Path Finder in Splunk Search 05-24-2010
1 1
1
1
Genti
We were on 3.4.6 and I think subsearches worked fine. We upgraded to 4.0.10 and they broke. So I upgraded to 4.1.1, ...
by Genti Splunk Employee Splunk Employee in Splunk Search 05-24-2010
1 4
1
4
logicasrl
Hi all, I've got a problem with the execution of this command from a Windows ".bat" script: splunk.exe search "| sa...
by logicasrl Explorer in Splunk Search 05-24-2010
0 8
0
8
sidafydd
Hi, I've created the following field extraction and field transform in their respective files - props.conf and trans...
by sidafydd New Member in Splunk Search 05-24-2010
0 3
0
3
sflisher
Hi All, I am using splunk to analyse squid logs and my goal is to identify how many minutes of the day a client ip ...
by sflisher Explorer in Splunk Search 05-23-2010
0 4
0
4
stephanbuys
I have a data source where all events get logged in hour intervals. There could be several hundred thousand events pe...
by stephanbuys Path Finder in Splunk Search 05-21-2010
0 3
0
3
jwestberg
I have a macro that accepts 5 arguments. I was hoping to get the arguments into the macro from a previous search resu...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 05-21-2010
0 1
0
1
Simeon
I have created regular expressions (regex) to extract fields and want to know what syntax style Splunk supports.
by Simeon Splunk Employee Splunk Employee in Splunk Search 05-20-2010
1 2
1
2
Skippy
Hi, my first question here so sorry if I use some stange terminology, I'll try and be as concise as I can! To start ...
by Skippy Explorer in Splunk Search 05-20-2010
2 2
2
2
Marinus
Hi All I'd like to create a search script that uses a field to do some internal calculations. The output isn't a se...
by Marinus Communicator in Splunk Search 05-19-2010
1 1
1
1
Voltaire
I am trying to set up a search then alert on our *nix systems SAN-LUNs storage system. I modified a default *NIX dis...
by Voltaire Communicator in Splunk Search 05-19-2010
2 2
2
2
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...