Splunk Search

Splunk Search
Community Activity
cmeredith
I'm new to Splunk and I have a question about how to query the information I need. I'm indexing IIS web server logs....
by cmeredith Engager in Splunk Search 06-07-2010
2 2
2
2
pbenner
I need to parse apache web logs that can run into the billions of requests per month. I need to coorelate and aggrega...
by pbenner Explorer in Splunk Search 06-07-2010
0 2
0
2
pde
I'm doing something like this: [search host=*prod* source=*stats.log execTime > 10000 | fields msgID] | search host=...
by pde Path Finder in Splunk Search 06-07-2010
3 1
3
1
sanju005ind
This is the View which I created with a form which contains a dropdown to list department names.All the hosts are tag...
by sanju005ind Communicator in Splunk Search 06-07-2010
0 2
0
2
sdagostino
I need to add something to the following search string (or rewrite it) that captures the following; UserDestination ...
by sdagostino Engager in Splunk Search 06-06-2010
3 6
3
6
maverick
I have Windows Security events that tell me when a user logged on and I have an ActiveDirectory event that tells me t...
by maverick Splunk Employee Splunk Employee in Splunk Search 06-06-2010
1 8
1
8
nik_splunk
Good morning Splunkers, I'm working on the search detailed below. By using two subsearches I'm trying to identify ...
by nik_splunk Path Finder in Splunk Search 06-06-2010
0 3
0
3
Lowell
I'm trying to build transaction that has an optional leading starting event. The events I'm using don't have any hel...
by Lowell Super Champion in Splunk Search 06-06-2010
1 9
1
9
snortymcsnort
When I click on extract fields from the drop down box on a search result I keep getting this error messsage 500 ...
by snortymcsnort New Member in Splunk Search 06-05-2010
0 6
0
6
shirolu
hello I have a search problem I would like to set a time interval Interval last Monday to last Sunday if today is...
by shirolu Explorer in Splunk Search 06-05-2010
0 3
0
3
Jaci
The first search (1) will return host values and time values. Need to have those values used in another search (2) s...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-05-2010
0 3
0
3
seanlon11
I looked at the documentation here: http://www.splunk.com/base/Documentation/4.1.1/SearchReference/CLIsearchsyntax A...
by seanlon11 Path Finder in Splunk Search 06-04-2010
0 3
0
3
oreoshake
sourcetype=package_formatted [search sourcetype=package_formatted | stats dc(version) as version_test by name | searc...
by oreoshake Communicator in Splunk Search 06-04-2010
0 1
0
1
dianbo_1
Hi, There are login messages and logout messages in the log files. I want to get those users who have not been logou...
by dianbo_1 Path Finder in Splunk Search 06-04-2010
1 4
1
4
sranga
Hi We have a scheduled-search that does summary indexing. For some reason, it doesn't capture all of the data that...
by sranga Path Finder in Splunk Search 06-04-2010
0 6
0
6
hiddenkirby
So i have some custom app logs that contain an ip address in the filename. I am attempting to extract them. any ide...
by hiddenkirby Contributor in Splunk Search 06-04-2010
1 11
1
11
maverick
On my LightWeightForwader (LWF), if I set the bandwidth thruput limit in limits.conf too low and the queue fills up o...
by maverick Splunk Employee Splunk Employee in Splunk Search 06-04-2010
1 1
1
1
sranga
Hi We have a summary indexed search that puts events into buckets for a day. We then use that to get the top 5 val...
by sranga Path Finder in Splunk Search 06-04-2010
0 8
0
8
sideview
I actually need a right join in some cases. I know im not supposed to use joins at all, and wherever possible use a...
by SplunkTrust SplunkTrust in Splunk Search 06-04-2010
0 4
0
4
Jaci
I am attempting to use the real time view over time. It stops displaying events that are happening and hangs...the ti...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-04-2010
1 1
1
1
straffin
I'd like to remove all data that matches a given search from my Splunk 3.4.14 for Windows install. I've found Windows...
by straffin Explorer in Splunk Search 06-03-2010
0 3
0
3
Jaci
I need to add something to the following string (or rewrite it) that captures users sum by url by date. Any help woul...
by Jaci Splunk Employee Splunk Employee in Splunk Search 06-03-2010
1 1
1
1
jeni
Hi I am trying to do the following. I have to prepare a report which contains the TransactionId, servername, some ...
by jeni New Member in Splunk Search 06-03-2010
0 7
0
7
the_wolverine
In Splunk, what is an intention? The Splexicon somewhat describes it .. but not really: http://www.splunk.com/base/...
by the_wolverine Champion in Splunk Search 06-02-2010
4 3
4
3
rayfoo
The fields command in 4.1.2, build 79191 has a bug. It includes all results from the _* fields even when specified w...
by rayfoo Path Finder in Splunk Search 06-02-2010
0 3
0
3
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...