| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Saw this error in splunklogger.log. What does it mean?
        
         
           by 
           
                
                    
                        Jaci
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               04-01-2010
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        We are indexing a lot of Cisco syslog messages. I notice that the host field is extracted correctly, but src/dst IP a...
        
         
           by 
           
                
                    
                        rsimmons
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-26-2010
             
           
         
        | 
		
		3
   | 
	  
	  3
	 | |||
| 
        I have a script that populates the previous day's data early in the following morning. How do I set a time range such...
        
         
           by 
           
                
                    
                        Peter
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-30-2010
             
           
         
        | 
		
		2
   | 
	  
	  3
	 | |||
| 
        I've got a field extraction defined in my props.conf, but now I want to be able to select it in a search without usin...
        
         
           by 
           
                
                    
                        thepocketwade
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-29-2010
             
           
         
        | 
		
		1
   | 
	  
	  5
	 | |||
| 
        I have heard that this is possible - please correct me if I am wrong. 
  Firstly, the reason I want to do this. We in...
        
         
           by 
           
                
                    
                        Glenn
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               03-26-2010
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I'm curious how to plan a deployment where i have many concurrent searches. I understand how to account for indexing,...
        
         
           by 
           
                
                    
                        Erik_Swan
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-29-2010
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I understand summary indexing can drastically improve the load time of my dashboards. In addition, if I schedule each...
        
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-25-2010
             
           
         
        | 
		
		7
   | 
	  
	  5
	 | |||
| 
        Are search-time fields slow? Can I rely on them to efficiently sort through my data? 
  Are there significant differe...
        
         
           by 
           
                
                    
                        jrodman
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-23-2010
             
           
         
        | 
		
		5
   | 
	  
	  4
	 | |||
| 
        I got Your index exceeded your 20.00 GB/day limit again. I would like to know which data inputs cause this.
        
         
           by 
           
                
                    
                        Alan_Bradley
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-19-2010
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        For every Retention key (already extracted by Splunk: 20181947800000) I want to subtract the requestTime="2009-05-26T...
        
         
           by 
           
                
                    
                        Alan_Bradley
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-19-2010
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi  
  I would like to have a way to find out whether hosts have stopped logging to our central log infrastructure or...
        
         
           by 
           
                
                    
                        chris
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               03-17-2010
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I am having trouble getting my head around the search required to graph multiple values from the same log event. It s...
        
         
           by 
           
                
                    
                        Glenn
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               03-18-2010
             
           
         
        | 
		
		2
   | 
	  
	  5
	 | |||
| 
        Our office has a specific TRANSACTION search we do frequently to track all events related to a particular user. The s...
        
         
           by 
           
                
                    
                        Justin_Grant
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               03-15-2010
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I'd like to provide a table where the event count for today and yesterday are displayed. For example, count by status...
        
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-16-2010
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I know that in general, regular expressions in Splunk use PCRE (or a modified PCRE for matching in props.conf source ...
        
         
           by 
           
                
                    
                        gkanapathy
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-03-2010
             
           
         
        | 
		
		3
   | 
	  
	  1
	 | |||
| 
        I would like to use a lookup into an external database to add fields to my events, but need some advice about perform...
        
         
           by 
           
                
                    
                        Justin_Grant
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               03-13-2010
             
           
         
        | 
		
		2
   | 
	  
	  3
	 | |||
| 
        On the Search App > Status > Index activity dashboard, there is an Index health report showing the bucket spread over...
        
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-13-2010
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        I'm trying to throw out search results from a couple of different ip ranges. Currently I'm working with 2, but I migh...
        
         
           by 
           
                
                    
                        thepocketwade
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               03-12-2010
             
           
         
        | 
		
		3
   | 
	  
	  4
	 | |||
| 
        It is a subtlety of the search language that keyword searches run against the raw event data only. To search metadata...
        
         
           by 
           
                
                    
                        hulahoop
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-09-2010
             
           
         
        | 
		
		1
   | 
	  
	  2
	 | |||
| 
        I'd like to limit certain users from running expensive searches by limiting the number of results that can be returne...
        
         
           by 
           
                
                    
                        the_wolverine
                    
                
           
             
             
               Champion
             
           
           in
           Splunk Search
           
           
              
               03-09-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        How do I change the default granularity on a chart? It appears I'm hitting a limit somewhere and I'm not getting as m...
        
         
           by 
           
                
                    
                        dskillman
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-03-2010
             
           
         
        | 
		
		5
   | 
	  
	  2
	 | |||
| 
        While I browse my local drive in Explorer I would like to add and search some log files with Splunk without opening a...
        
         
           by 
           
                
                    
                        Leo
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               03-03-2010
             
           
         
        | 
		
		1
   | 
	  
	  1
	 | |||
| 
        There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a spl...
        
         
           by 
           
                
                    
                        matt_1
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               02-25-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        Does maxresults in limits.conf have an effect when piping results to the stats command? For example, if I run a searc...
        
         
           by 
           
                
                    
                        kbecker
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               02-26-2010
             
           
         
        | 
		
		2
   | 
	  
	  1
	 | |||
| 
        I have millions of events being indexed by Splunk now and I suspect something is happening within my IT environment a...
        
         
           by 
           
                
                    
                        maverick
                    
                
           
             
             
               Splunk Employee
             
           
           in
           Splunk Search
           
           
              
               02-24-2010
             
           
         
        | 
		
		1
   | 
	  
	  1
	 |