Splunk Search

Splunk Search
Community Activity
bfaber
If I have data like this: src=1.1.1.1 dst=2.2.2.2 can I create a mvfield of ip's? like: ips=1.1.1.1,2.2.2.2 FRO...
by bfaber Communicator in Splunk Search 05-26-2010
1 2
1
2
bfaber
If I have data that looks like (date) srcip=x.x.x.x dstip=y.y.y.y How can I create a single list of all unique IPs...
by bfaber Communicator in Splunk Search 05-26-2010
1 6
1
6
maverick
Is there a way to report on the position of an event relative to the rest of the events in the result set? For examp...
by maverick Splunk Employee Splunk Employee in Splunk Search 05-25-2010
0 2
0
2
nbharadwaj
How can I use lookups for a source CSV file that is not under the Splunk code tree? I am using Splunk 4.0.10. CSV lo...
by nbharadwaj Path Finder in Splunk Search 05-24-2010
1 1
1
1
Genti
We were on 3.4.6 and I think subsearches worked fine. We upgraded to 4.0.10 and they broke. So I upgraded to 4.1.1, ...
by Genti Splunk Employee Splunk Employee in Splunk Search 05-24-2010
1 4
1
4
logicasrl
Hi all, I've got a problem with the execution of this command from a Windows ".bat" script: splunk.exe search "| sa...
by logicasrl Explorer in Splunk Search 05-24-2010
0 8
0
8
sidafydd
Hi, I've created the following field extraction and field transform in their respective files - props.conf and trans...
by sidafydd New Member in Splunk Search 05-24-2010
0 3
0
3
sflisher
Hi All, I am using splunk to analyse squid logs and my goal is to identify how many minutes of the day a client ip ...
by sflisher Explorer in Splunk Search 05-23-2010
0 4
0
4
stephanbuys
I have a data source where all events get logged in hour intervals. There could be several hundred thousand events pe...
by stephanbuys Path Finder in Splunk Search 05-21-2010
0 3
0
3
jwestberg
I have a macro that accepts 5 arguments. I was hoping to get the arguments into the macro from a previous search resu...
by jwestberg Splunk Employee Splunk Employee in Splunk Search 05-21-2010
0 1
0
1
Simeon
I have created regular expressions (regex) to extract fields and want to know what syntax style Splunk supports.
by Simeon Splunk Employee Splunk Employee in Splunk Search 05-20-2010
1 2
1
2
Skippy
Hi, my first question here so sorry if I use some stange terminology, I'll try and be as concise as I can! To start ...
by Skippy Explorer in Splunk Search 05-20-2010
2 2
2
2
Marinus
Hi All I'd like to create a search script that uses a field to do some internal calculations. The output isn't a se...
by Marinus Communicator in Splunk Search 05-19-2010
1 1
1
1
Voltaire
I am trying to set up a search then alert on our *nix systems SAN-LUNs storage system. I modified a default *NIX dis...
by Voltaire Communicator in Splunk Search 05-19-2010
2 2
2
2
dcroteau
From the Doc: Edit existing automatic lookups or configure a new lookup to run automatically Instead of invoking ...
by dcroteau Splunk Employee Splunk Employee in Splunk Search 05-19-2010
0 2
0
2
hiddenkirby
So this stemmed from a previous question, but i figured it warranted a new question. (hey more points for everyone) ...
by hiddenkirby Contributor in Splunk Search 05-19-2010
0 3
0
3
sideview
We want to end up with this kind of table on a dashboard. Average GB By Host and Time host last 24 hours ...
by SplunkTrust SplunkTrust in Splunk Search 05-19-2010
3 3
3
3
the_wolverine
I recently restarted Splunk and found that a bunch of jobs return this error when I click on the jobs link. What hap...
by the_wolverine Champion in Splunk Search 05-18-2010
1 4
1
4
sranga
Hi I was wondering if there was a way to search for logs that don't have a specific field in them. If I have the f...
by sranga Path Finder in Splunk Search 05-18-2010
0 1
0
1
Rob_Jordan
How can I report on all of those thousands of BEA- messages in our weblogic logs?
by Rob_Jordan Explorer in Splunk Search 05-18-2010
0 1
0
1
hulahoop
Here's what we are trying to do with our Juniper Netscreen Firewall data for outbound denied traffic: Find the top 3...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 05-17-2010
2 4
2
4
clyde772
How can I process tables like below where Data is spread across multiple lines. and Top start set defines Field name...
by clyde772 Communicator in Splunk Search 05-16-2010
0 2
0
2
Oren
I've got weblogs going into splunk. We have a bunch of different domain names (extracted as http_domain) in the logs...
by Oren Explorer in Splunk Search 05-16-2010
0 1
0
1
Josh
So I have used props and tranforms to extract a field in my application by using a particular regex expression. For ...
by Josh Path Finder in Splunk Search 05-15-2010
0 1
0
1
nunyabizness
I don't understand how to get Splunk to properly parse the Teardown messages from my ASA cluster. It claims that "byt...
by nunyabizness Explorer in Splunk Search 05-14-2010
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors