Splunk Search

Splunk Search
Community Activity
swerner
I am evaluating Splunk for use in monitoring application logs and am wondering if it is possible to group together li...
by swerner Explorer in Splunk Search 05-11-2010
1 4
1
4
carmackd
could someone please explain what stanza configuration i should include in the props.conf file to extract the size at...
by carmackd Communicator in Splunk Search 05-11-2010
1 2
1
2
Johnvey
I would like to use the following cmd in splunk and I am getting errors. egrep "Failed password" auth.log | awk '{p...
by Johnvey Contributor in Splunk Search 05-10-2010
2 3
2
3
fox
I have two related sets of data: Errors and CalcRun. The relationship in SQl speak is Many Errors to a CalcRun. When ...
by fox Path Finder in Splunk Search 05-10-2010
0 1
0
1
Andrew_Goktepe
Is it possible to define custom fields and hard-code their values on a per-forwarder basis? I'm looking to use such ...
by Andrew_Goktepe New Member in Splunk Search 05-10-2010
0 6
0
6
clyde772
Let's say we want to process the typical data input like below : 12|Jones Indiana|76|223-33-3323|US|CALIFORNIA|MARRI...
by clyde772 Communicator in Splunk Search 05-10-2010
0 4
0
4
nbharadwaj
I have a several log lines like this: X:20100507193758.385:50:INFO:DTM:AppServerStartupTaskManager-pool-1-thread-1:R...
by nbharadwaj Path Finder in Splunk Search 05-07-2010
0 1
0
1
sideview
Im trying to use timechart to pass along the values of a particular field for each time bucket. I know that the fi...
by SplunkTrust SplunkTrust in Splunk Search 05-07-2010
2 1
2
1
Jaci
Is there any way to control the reported fields in an email alert? I have configured splunk to add the search results...
by Jaci Splunk Employee Splunk Employee in Splunk Search 05-07-2010
5 4
5
4
mikebrittain
I'm trying to build a report of slowest pages/scripts on our server based on times for serving those scripts. This w...
by mikebrittain Explorer in Splunk Search 05-07-2010
1 4
1
4
dhaffner
Is it possible to have indexer A distribute to indexer B and have B distribute to A? What are the settings for it. J...
by dhaffner Path Finder in Splunk Search 05-06-2010
0 5
0
5
sranga
Hi If I have a summary-populating-index search that is scheduled to run daily. Is it possible to index data that i...
by sranga Path Finder in Splunk Search 05-06-2010
0 2
0
2
Justin_Grant
We're stumped how to approach field extraction for XML configuration files for ASP.NET web applications. I want to en...
by Justin_Grant Contributor in Splunk Search 05-06-2010
1 2
1
2
sranga
Hi I have a question about the workings of the scheduled saved search. Suppose I have a slow-running search that h...
by sranga Path Finder in Splunk Search 05-06-2010
0 1
0
1
hacktastic
Hi, I'm Splunking some report data that is in CSV format, which may or may not matter in the context of this questio...
by hacktastic Path Finder in Splunk Search 05-05-2010
4 6
4
6
Hazel
Hello, I am trying to build up a report using multiple stats, but I am having issues with duplication. I will do on...
by Hazel Communicator in Splunk Search 05-05-2010
0 5
0
5
thinguyen
Hi When I ran this preset , there was no results diplayed. What was wrong?
by thinguyen Engager in Splunk Search 05-05-2010
1 2
1
2
Peter
I am attempting to write a search that can alert if a user deviates from some normal data viewing pattern. The event ...
by Peter Path Finder in Splunk Search 05-03-2010
1 16
1
16
clyde772
I want to chop multiline events like below. I had splunk to automatically process the data, but it didn't quite work...
by clyde772 Communicator in Splunk Search 05-03-2010
0 1
0
1
nik_splunk
Hello Splunkers, Thanks to visit my question. I have two subsets of data related to each other. The set A consists...
by nik_splunk Path Finder in Splunk Search 05-02-2010
0 1
0
1
clyde772
Let assume the following, the data source for analysis is Firewall traffic log. I guess It could be applied to any ...
by clyde772 Communicator in Splunk Search 05-02-2010
0 1
0
1
ghnwmlguy
I have configured automatic lookups with the intention of using it in only one app (my own ossec app). However, when...
by ghnwmlguy Explorer in Splunk Search 04-30-2010
0 4
0
4
vbumgarn
We have logs that do stuff like this: message id=1 message id=2 parent=1 message id=2 parent=1 message id=3 ...
by vbumgarn Path Finder in Splunk Search 04-30-2010
2 1
2
1
clyde772
How I can I remove specfic indexed data from an exsiting data index?
by clyde772 Communicator in Splunk Search 04-30-2010
3 2
3
2
Steve_Litras
Prior to 4.1, my host field reverse resolved (i.e. instead of ip addresses, it showed hostnames from DNS) for syslog ...
by Steve_Litras Path Finder in Splunk Search 04-30-2010
1 3
1
3
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors