Splunk Search

Splunk Search
Community Activity
jrich523
how do i show the average number of hits per minute for each hour? basically i have a system that will, on peak hour...
by jrich523 Path Finder in Splunk Search 04-14-2010
3 1
3
1
Simon
Hi folks I have a directory structure on my server box (with splunk LWF) like this: /foo/bar/node1/server1/SystemOu...
by Simon Contributor in Splunk Search 04-14-2010
1 3
1
3
Marinus
If you have a time range and certain days contain data you'd like to exclude can you drop the days from your search r...
by Marinus Communicator in Splunk Search 04-14-2010
4 2
4
2
netwrkr
I would like to be able to see if a user logs in via ssh but doesn't log out within 30 minutes. For example 12:28:4...
by netwrkr Communicator in Splunk Search 04-14-2010
2 1
2
1
the_wolverine
My understanding is that this is now done via a splunk config file. How?
by the_wolverine Champion in Splunk Search 04-14-2010
2 1
2
1
Alan_Bradley
I see lots of reference to search heads as a way to improve search performance. I can't find a search head section o...
by Alan_Bradley Path Finder in Splunk Search 04-14-2010
0 2
0
2
Ayn
I have a number of hosts that have a certain tag on them (let's say "sensitive"). I want to look for account lockout ...
by Legend in Splunk Search 04-13-2010
1 2
1
2
Yancy
Is it possible with subsearch to pass a list of search results to the outside search? similar to a SQL correlated sub...
by Yancy Path Finder in Splunk Search 04-13-2010
3 3
3
3
andynu
Given a sequence of general to specific events (like product browsing a pages, followed by particular product pages)...
by andynu Engager in Splunk Search 04-13-2010
2 2
2
2
Michael_Wilde
I'm trying to map search performance to specific searches. I have to discover if its possible to marry up a job ID t...
by Michael_Wilde Splunk Employee Splunk Employee in Splunk Search 04-13-2010
2 8
2
8
rsimmons
The asterisk character is not matching all characters. A search for : rectype="bl*query" returns 0 matching event...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 04-13-2010
10 5
10
5
sideview
In a dashboard we're working with we are displaying a table of events and the times always have 000 as the millisecon...
by SplunkTrust SplunkTrust in Splunk Search 04-13-2010
1 1
1
1
the_wolverine
Livetail was around in version 3.x and went away in 4.0. When is it coming back?
by the_wolverine Champion in Splunk Search 04-13-2010
2 1
2
1
the_wolverine
I'm running summary searches and the splunk-system-user keeps hitting a quota limit. 04-12-2010 16:50:28.436 ERR...
by the_wolverine Champion in Splunk Search 04-13-2010
3 1
3
1
aagmon
Hi All... i'll first describe my scenario.. i have logs that contains entries regarding open ports like: 1-1-2000 ...
by aagmon New Member in Splunk Search 04-12-2010
0 2
0
2
bfaber
Can I do a live search over multiple Splunk indexers?
by bfaber Communicator in Splunk Search 04-10-2010
1 2
1
2
Justin_Grant
My search returns 10 fields in each event and I want to create a table with one row per event and columns for 3 of th...
by Justin_Grant Contributor in Splunk Search 04-09-2010
0 6
0
6
rayfoo
Wanted to see what is/are the possible methods to do so. One way I could think of is to export the results using out...
by rayfoo Path Finder in Splunk Search 04-08-2010
1 7
1
7
MHS
I use the following query against a Cisco as5400 to find the number of calls per hour during a day. 10.200.90.19 Cal...
by MHS Explorer in Splunk Search 04-08-2010
0 4
0
4
imrago
After upgrading to 4.1 from 4.0.10 I am unable to get fields using a search from python script. The simplified versio...
by imrago Contributor in Splunk Search 04-08-2010
0 2
0
2
zscgeek
I am trying to get scripted auth working on the new 4.1. I had a configuration on 3.4.x that worked great but after m...
by zscgeek Path Finder in Splunk Search 04-07-2010
0 2
0
2
Justin_Grant
What are the searches required to search across Windows Event Logs for: most recent events of a particular event ID ...
by Justin_Grant Contributor in Splunk Search 04-07-2010
2 1
2
1
the_wolverine
Splunk does such an awesome job with distributed search. It seems like all my data is on one server (my search head)...
by the_wolverine Champion in Splunk Search 04-07-2010
1 2
1
2
Alan_Bradley
After upgrading to Splunk 4.1 from 4.0.10 today, we find that we can no longer run searches. splunkd.log shows: 04-...
by Alan_Bradley Path Finder in Splunk Search 04-05-2010
4 1
4
1
SteveS
If I have a bunch of saved searches I run hourly, what should I consider before switching any or all of them to real ...
by SteveS Splunk Employee Splunk Employee in Splunk Search 04-05-2010
2 2
2
2
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors