| I'm trying to throw out search results from a couple of different ip ranges. Currently I'm working with 2, but I mig... by thepocketwade Path Finder in Splunk Search 03-12-2010 3 4 | 3 | 4 | ||
| It is a subtlety of the search language that keyword searches run against the raw event data only. To search metadat... by hulahoop Splunk Employee 1 2 | 1 | 2 | ||
| I'd like to limit certain users from running expensive searches by limiting the number of results that can be returne... by the_wolverine Champion in Splunk Search 03-09-2010 2 1 | 2 | 1 | ||
| How do I change the default granularity on a chart? It appears I'm hitting a limit somewhere and I'm not getting as ... by dskillman Splunk Employee 5 2 | 5 | 2 | ||
| While I browse my local drive in Explorer I would like to add and search some log files with Splunk without opening a... by Leo Splunk Employee 1 1 | 1 | 1 | ||
| There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a spl... by matt_1 Explorer in Splunk Search 03-03-2010 2 1 | 2 | 1 | ||
| Does maxresults in limits.conf have an effect when piping results to the stats command? For example, if I run a sear... by kbecker Communicator in Splunk Search 02-26-2010 2 1 | 2 | 1 | ||
| I have millions of events being indexed by Splunk now and I suspect something is happening within my IT environment a... by maverick Splunk Employee 1 1 | 1 | 1 | ||
| Hi Splunkers, I have a sample Perforce log file and I'm trying to extract the code contributors. Here is an example:... by Nicholas_Key Splunk Employee 2 2 | 2 | 2 | ||
| How do i use the same search strings in splunks UI on the command line? by Chris_R_ Splunk Employee 0 4 | 0 | 4 | ||
| There are plenty of ways to specify the exact time range or maximum range between two events in a search. But I need ... by Tisiphone Engager in Splunk Search 02-19-2010 3 1 | 3 | 1 | ||
| explain the significance of the connected flag in transaction by Ledion_Bitincka Splunk Employee 2 1 | 2 | 1 | ||
| Dan Goldburt asks: I'm consistently getting the following request from customers: "can I see where each event came fr... by Ledion_Bitincka Splunk Employee 1 1 | 1 | 1 | ||
| Such a helpful command, and yet doesn't work for me... by V_at_Splunk Splunk Employee 1 3 | 1 | 3 | ||
| When I run this search - source="*conn.log" | rex field=_raw "\.IP = '(?<connectionIp>[^']+)" | fields host, connect... by Mick Splunk Employee 4 1 | 4 | 1 | ||
| We are attempting to create a report that compares message traffic for the past two complete weeks. We have this as... by Mick Splunk Employee 0 2 | 0 | 2 | ||
| Any recommended best practices for managing eventtypes and their corresponding tags? I've found the Splunk Common In... by Yancy Path Finder in Splunk Search 02-02-2010 0 2 | 0 | 2 | ||
| What is wrong with this regex? (?P<AUTH_PIN_TYPE>[^ ]+)( [^ ]+){2}$ The interactive field extractor gives this err... by dinh Path Finder in Splunk Search 02-01-2010 0 5 | 0 | 5 | ||
| I am using the transaction command to sessionize web access log events and therefore have made referer, uri etc. into... by cfrln Explorer in Splunk Search 02-01-2010 4 3 | 4 | 3 | ||
| Let say I have events coming in everyday and I want to group the events as Monday's events, Tuesday's events, and so ... by hans Splunk Employee 1 2 | 1 | 2 | ||
| Use Case: Find Juniper firewall events where the source/destination IP (Src_Zone/Dst_Zone) does or does not belong in... by hulahoop Splunk Employee 5 5 | 5 | 5 | ||
| Use Case: Correlate logon events from a Windows desktop to events on the domain controller. Sample (shortened) event... by hulahoop Splunk Employee 2 9 | 2 | 9 | ||
| I've got an application that logs status events. The values in these events generally will not change. Is there a s... by matt Splunk Employee 1 1 | 1 | 1 | ||
| What is wrong with the way I'm using eval here? source="/some.audit.log" "End" "/foo/baz" | rex field=_raw "(?P<ReqI... by dinh Path Finder in Splunk Search 01-27-2010 0 5 | 0 | 5 | ||
| Sometimes I come across an event in my index that I'd like to refer to later, either as part of an investigation or t... by Johnvey Contributor in Splunk Search 01-25-2010 1 3 | 1 | 3 |