Splunk Search

Splunk Search
Community Activity
sranga
Hi I have a question about the workings of the scheduled saved search. Suppose I have a slow-running search that h...
by sranga Path Finder in Splunk Search 05-06-2010
0 1
0
1
hacktastic
Hi, I'm Splunking some report data that is in CSV format, which may or may not matter in the context of this questio...
by hacktastic Path Finder in Splunk Search 05-05-2010
4 6
4
6
Hazel
Hello, I am trying to build up a report using multiple stats, but I am having issues with duplication. I will do on...
by Hazel Communicator in Splunk Search 05-05-2010
0 5
0
5
thinguyen
Hi When I ran this preset , there was no results diplayed. What was wrong?
by thinguyen Engager in Splunk Search 05-05-2010
1 2
1
2
Peter
I am attempting to write a search that can alert if a user deviates from some normal data viewing pattern. The event ...
by Peter Path Finder in Splunk Search 05-03-2010
1 16
1
16
clyde772
I want to chop multiline events like below. I had splunk to automatically process the data, but it didn't quite work...
by clyde772 Communicator in Splunk Search 05-03-2010
0 1
0
1
nik_splunk
Hello Splunkers, Thanks to visit my question. I have two subsets of data related to each other. The set A consists...
by nik_splunk Path Finder in Splunk Search 05-02-2010
0 1
0
1
clyde772
Let assume the following, the data source for analysis is Firewall traffic log. I guess It could be applied to any ...
by clyde772 Communicator in Splunk Search 05-02-2010
0 1
0
1
ghnwmlguy
I have configured automatic lookups with the intention of using it in only one app (my own ossec app). However, when...
by ghnwmlguy Explorer in Splunk Search 04-30-2010
0 4
0
4
vbumgarn
We have logs that do stuff like this: message id=1 message id=2 parent=1 message id=2 parent=1 message id=3 ...
by vbumgarn Path Finder in Splunk Search 04-30-2010
2 1
2
1
clyde772
How I can I remove specfic indexed data from an exsiting data index?
by clyde772 Communicator in Splunk Search 04-30-2010
3 2
3
2
Steve_Litras
Prior to 4.1, my host field reverse resolved (i.e. instead of ip addresses, it showed hostnames from DNS) for syslog ...
by Steve_Litras Path Finder in Splunk Search 04-30-2010
1 3
1
3
sanju005ind
After initial installation of the forwarder when the Splunk service is started the forwarder reports by Ip Address.Af...
by sanju005ind Communicator in Splunk Search 04-30-2010
2 1
2
1
Nicholas_Key
I would like to know if there is a way to generalize the following EXTRACT regexes in my props.conf? The configuratio...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 04-30-2010
0 2
0
2
Lowell
Is there a way to split the text of an event into multiple events (preferably using a regular expression) at search-t...
by Lowell Super Champion in Splunk Search 04-29-2010
1 2
1
2
the_wolverine
I have a search-time field extraction that shows up in my pick fields list and everything. The fields list is showin...
by the_wolverine Champion in Splunk Search 04-29-2010
3 7
3
7
Lowell
Is there some reason why using the lookup command doesn't seem to be working properly after stats? The search I'm tr...
by Lowell Super Champion in Splunk Search 04-29-2010
0 3
0
3
yzubarev
Greetings, I introduced a new sourcetype "access_combined_wperformance" but I cannot get it utilized as "access_comb...
by yzubarev Explorer in Splunk Search 04-28-2010
3 12
3
12
Josh
How can I consolidate 2 or more fields into one new field at search time? e.g. ...| fields a,b,c | d In the above I...
by Josh Path Finder in Splunk Search 04-28-2010
0 7
0
7
Hazel
Hello, I am trying to configure a props/transforms and it is not working. it does not come up as an extra field tha...
by Hazel Communicator in Splunk Search 04-28-2010
1 3
1
3
Hazel
Hello, I am rewriting this - hope it makes more sense. I have config files, which I am passing into splunk as follo...
by Hazel Communicator in Splunk Search 04-28-2010
0 6
0
6
igotimac
In Previous versions of splunk on the search interface a "source" and "sourcetype" were reported underneath each in e...
by igotimac Engager in Splunk Search 04-26-2010
1 2
1
2
Josh
Hi All, I am having trouble breaking up the log file below: Each log entry starts with id:#################### and ...
by Josh Path Finder in Splunk Search 04-26-2010
1 5
1
5
prodport
In the Splunk 4.1 webcast earlier this week, one of the presenters showed a combined_access report that looked to pro...
by prodport New Member in Splunk Search 04-26-2010
0 2
0
2
rayfoo
After upgrading to version 4.1.1, build 78281, Splunk shows a JavaScript prompt with the following error in the searc...
by rayfoo Path Finder in Splunk Search 04-26-2010
1 3
1
3
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors