Splunk Search

Splunk Search
Community Activity
zliu
"The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration 'ntsyslog:security'." Th...
by zliu Splunk Employee Splunk Employee in Splunk Search 06-10-2010
0 1
0
1
pbenner
I need to enrich my event data (web logs) with several other fields based on a value of one of the events fields. I p...
by pbenner Explorer in Splunk Search 06-09-2010
0 1
0
1
mctester
If I write a custom command, where does it need to be located if I have a distributed search setup? On the local splu...
by mctester Communicator in Splunk Search 06-09-2010
0 1
0
1
kbains
Can you have both span=x and bins=y in timechart? If both are specified, which one wins?
by kbains Splunk Employee Splunk Employee in Splunk Search 06-08-2010
0 4
0
4
cmeredith
I'm new to Splunk and I have a question about how to query the information I need. I'm indexing IIS web server logs....
by cmeredith Engager in Splunk Search 06-07-2010
2 2
2
2
pbenner
I need to parse apache web logs that can run into the billions of requests per month. I need to coorelate and aggrega...
by pbenner Explorer in Splunk Search 06-07-2010
0 2
0
2
pde
I'm doing something like this: [search host=*prod* source=*stats.log execTime > 10000 | fields msgID] | search host=...
by pde Path Finder in Splunk Search 06-07-2010
3 1
3
1
sanju005ind
This is the View which I created with a form which contains a dropdown to list department names.All the hosts are tag...
by sanju005ind Communicator in Splunk Search 06-07-2010
0 2
0
2
sdagostino
I need to add something to the following search string (or rewrite it) that captures the following; UserDestination ...
by sdagostino Engager in Splunk Search 06-06-2010
3 6
3
6
maverick
I have Windows Security events that tell me when a user logged on and I have an ActiveDirectory event that tells me t...
by maverick Splunk Employee Splunk Employee in Splunk Search 06-06-2010
1 8
1
8
nik_splunk
Good morning Splunkers, I'm working on the search detailed below. By using two subsearches I'm trying to identify ...
by nik_splunk Path Finder in Splunk Search 06-06-2010
0 3
0
3
Lowell
I'm trying to build transaction that has an optional leading starting event. The events I'm using don't have any hel...
by Lowell Super Champion in Splunk Search 06-06-2010
1 9
1
9
snortymcsnort
When I click on extract fields from the drop down box on a search result I keep getting this error messsage 500 ...
by snortymcsnort New Member in Splunk Search 06-05-2010
0 6
0
6
shirolu
hello I have a search problem I would like to set a time interval Interval last Monday to last Sunday if today is...
by shirolu Explorer in Splunk Search 06-05-2010
0 3
0
3
Jaci
The first search (1) will return host values and time values. Need to have those values used in another search (2) s...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-05-2010
0 3
0
3
seanlon11
I looked at the documentation here: http://www.splunk.com/base/Documentation/4.1.1/SearchReference/CLIsearchsyntax A...
by seanlon11 Path Finder in Splunk Search 06-04-2010
0 3
0
3
oreoshake
sourcetype=package_formatted [search sourcetype=package_formatted | stats dc(version) as version_test by name | searc...
by oreoshake Communicator in Splunk Search 06-04-2010
0 1
0
1
dianbo_1
Hi, There are login messages and logout messages in the log files. I want to get those users who have not been logou...
by dianbo_1 Path Finder in Splunk Search 06-04-2010
1 4
1
4
sranga
Hi We have a scheduled-search that does summary indexing. For some reason, it doesn't capture all of the data that...
by sranga Path Finder in Splunk Search 06-04-2010
0 6
0
6
hiddenkirby
So i have some custom app logs that contain an ip address in the filename. I am attempting to extract them. any ide...
by hiddenkirby Contributor in Splunk Search 06-04-2010
1 11
1
11
maverick
On my LightWeightForwader (LWF), if I set the bandwidth thruput limit in limits.conf too low and the queue fills up o...
by maverick Splunk Employee Splunk Employee in Splunk Search 06-04-2010
1 1
1
1
sranga
Hi We have a summary indexed search that puts events into buckets for a day. We then use that to get the top 5 val...
by sranga Path Finder in Splunk Search 06-04-2010
0 8
0
8
sideview
I actually need a right join in some cases. I know im not supposed to use joins at all, and wherever possible use a...
by SplunkTrust SplunkTrust in Splunk Search 06-04-2010
0 4
0
4
Jaci
I am attempting to use the real time view over time. It stops displaying events that are happening and hangs...the ti...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-04-2010
1 1
1
1
straffin
I'd like to remove all data that matches a given search from my Splunk 3.4.14 for Windows install. I've found Windows...
by straffin Explorer in Splunk Search 06-03-2010
0 3
0
3
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors