Splunk Search

Splunk Search
Community Activity
the_wolverine
In Splunk, what is an intention? The Splexicon somewhat describes it .. but not really: http://www.splunk.com/base/...
by the_wolverine Champion in Splunk Search 06-02-2010
4 3
4
3
rayfoo
The fields command in 4.1.2, build 79191 has a bug. It includes all results from the _* fields even when specified w...
by rayfoo Path Finder in Splunk Search 06-02-2010
0 3
0
3
Marinus
Is there a way to apply a SED like filter after a search. The plumbing is there to filter and sanitize data going int...
by Marinus Communicator in Splunk Search 06-02-2010
1 2
1
2
parallaxed
For some reason this search maxes out at 10000 (i.e. only returns 10000 sources, there are more...), and I can't seem...
by parallaxed Path Finder in Splunk Search 06-02-2010
1 3
1
3
sflisher
Hi experts, I would like to know if it is possible to exclude the result of 'addcoltotals' from the y axis scale. ...
by sflisher Explorer in Splunk Search 06-02-2010
1 1
1
1
mzorzi
I have some log like following: 13:47:04 -2 receive request [type=0|desc=TimeStamp] <---event one | [8 ] [BCA3.5] | ...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 06-02-2010
2 1
2
1
Steven_McGrath
I'm sure someone has figured out how to handle this data. What I am trying to do is index and extract all of the dat...
by Steven_McGrath Engager in Splunk Search 06-02-2010
1 1
1
1
pbenner
I need to aggregate the values found in the apache weblogs. First I need to parse out several fields. I can get these...
by pbenner Explorer in Splunk Search 06-01-2010
0 1
0
1
William
i have a case to count db operations. in the log file, the format is like: [time1] op=select data=.... [time2] op=SE...
by William Path Finder in Splunk Search 06-01-2010
1 1
1
1
William
For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table",...
by William Path Finder in Splunk Search 06-01-2010
0 3
0
3
smisplunk
We've got log events that read like the following: Mar 14 12:26:38 mailsrv.example.com MM: [Jilter Processor 21 - ...
by smisplunk Path Finder in Splunk Search 05-31-2010
1 7
1
7
dcroteau
Hi All, I need a sanity check. This extraction seemed to work in 4.0, Can someone help? mac_address and source_ip ...
by dcroteau Splunk Employee Splunk Employee in Splunk Search 05-30-2010
0 4
0
4
Jaci
Running this search: http://host1.com:8000/en-US/app/search/flashtimeline?q=search%20* | regex_raw%3D%22%25SYS-5-CON...
by Jaci Splunk Employee Splunk Employee in Splunk Search 05-28-2010
3 2
3
2
Mike_Spellane
I am trying to setup a scheduled search that runs every morning and looks for users logged on between 2200 the previo...
by Mike_Spellane New Member in Splunk Search 05-27-2010
0 2
0
2
riderofyamaha
I am having trouble getting my form search to bring back anything. The xml is accepted by splunk but the search won't...
by riderofyamaha Explorer in Splunk Search 05-27-2010
0 2
0
2
sanju005ind
I need help with a query to find the forwarders which stopped reporting for more than 2 weeks.
by sanju005ind Communicator in Splunk Search 05-27-2010
0 4
0
4
jjernigan
I've been able to get AmMap to work with scheduled searches. Is there a way to get it to work in realtime? I thought ...
by jjernigan Engager in Splunk Search 05-27-2010
2 1
2
1
mfrost8
I'm running Splunk 4.1.2. It seems that when Splunk sends out URL that correspond to searches (say when it triggers a...
by mfrost8 Builder in Splunk Search 05-27-2010
1 2
1
2
bfaber
can I get transaction to show hostname or sourcetype for each event within? I'd like to be able to pass a transactio...
by bfaber Communicator in Splunk Search 05-26-2010
0 5
0
5
hulahoop
In inputs.conf and props.conf, the wildcards ... and * are supported for use in the spec headers. What do they trans...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 05-26-2010
2 3
2
3
Rob_Jordan
While the following extraction below works, I wanted to see if I could extract both custom fields EAR_FILE and DOMAIN...
by Rob_Jordan Explorer in Splunk Search 05-26-2010
2 2
2
2
rgcox1
When searching for lost forwarders a host with an all caps name is returned as lost when the same host with a lower c...
by rgcox1 Communicator in Splunk Search 05-26-2010
0 3
0
3
bfaber
If I have data like this: src=1.1.1.1 dst=2.2.2.2 can I create a mvfield of ip's? like: ips=1.1.1.1,2.2.2.2 FRO...
by bfaber Communicator in Splunk Search 05-26-2010
1 2
1
2
bfaber
If I have data that looks like (date) srcip=x.x.x.x dstip=y.y.y.y How can I create a single list of all unique IPs...
by bfaber Communicator in Splunk Search 05-26-2010
1 6
1
6
maverick
Is there a way to report on the position of an event relative to the rest of the events in the result set? For examp...
by maverick Splunk Employee Splunk Employee in Splunk Search 05-25-2010
0 2
0
2
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...