Splunk Search

Splunk Search
Community Activity
Alan_Bradley
For every Retention key (already extracted by Splunk: 20181947800000) I want to subtract the requestTime="2009-05-26T...
by Alan_Bradley Path Finder in Splunk Search 03-19-2010
0 1
0
1
chris
Hi I would like to have a way to find out whether hosts have stopped logging to our central log infrastructure or i...
by chris Motivator in Splunk Search 03-19-2010
0 3
0
3
Glenn
I am having trouble getting my head around the search required to graph multiple values from the same log event. It s...
by Glenn Builder in Splunk Search 03-18-2010
2 5
2
5
Justin_Grant
Our office has a specific TRANSACTION search we do frequently to track all events related to a particular user. The s...
by Justin_Grant Contributor in Splunk Search 03-16-2010
0 5
0
5
hulahoop
I'd like to provide a table where the event count for today and yesterday are displayed. For example, count by statu...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 03-16-2010
0 2
0
2
gkanapathy
I know that in general, regular expressions in Splunk use PCRE (or a modified PCRE for matching in props.conf source ...
by gkanapathy Splunk Employee Splunk Employee in Splunk Search 03-15-2010
3 1
3
1
Justin_Grant
I would like to use a lookup into an external database to add fields to my events, but need some advice about perform...
by Justin_Grant Contributor in Splunk Search 03-15-2010
2 3
2
3
hulahoop
On the Search App > Status > Index activity dashboard, there is an Index health report showing the bucket spread over...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 03-13-2010
1 1
1
1
thepocketwade
I'm trying to throw out search results from a couple of different ip ranges. Currently I'm working with 2, but I mig...
by thepocketwade Path Finder in Splunk Search 03-12-2010
3 4
3
4
hulahoop
It is a subtlety of the search language that keyword searches run against the raw event data only. To search metadat...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 03-09-2010
1 2
1
2
the_wolverine
I'd like to limit certain users from running expensive searches by limiting the number of results that can be returne...
by the_wolverine Champion in Splunk Search 03-09-2010
2 1
2
1
dskillman
How do I change the default granularity on a chart? It appears I'm hitting a limit somewhere and I'm not getting as ...
by dskillman Splunk Employee Splunk Employee in Splunk Search 03-04-2010
5 2
5
2
Leo
While I browse my local drive in Explorer I would like to add and search some log files with Splunk without opening a...
by Leo Splunk Employee Splunk Employee in Splunk Search 03-03-2010
1 1
1
1
matt_1
There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a spl...
by matt_1 Explorer in Splunk Search 03-03-2010
2 1
2
1
kbecker
Does maxresults in limits.conf have an effect when piping results to the stats command? For example, if I run a sear...
by kbecker Communicator in Splunk Search 02-26-2010
2 1
2
1
maverick
I have millions of events being indexed by Splunk now and I suspect something is happening within my IT environment a...
by maverick Splunk Employee Splunk Employee in Splunk Search 02-24-2010
1 1
1
1
Nicholas_Key
Hi Splunkers, I have a sample Perforce log file and I'm trying to extract the code contributors. Here is an example:...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 02-22-2010
2 2
2
2
Chris_R_
How do i use the same search strings in splunks UI on the command line?
by Chris_R_ Splunk Employee Splunk Employee in Splunk Search 02-19-2010
0 4
0
4
Tisiphone
There are plenty of ways to specify the exact time range or maximum range between two events in a search. But I need ...
by Tisiphone Engager in Splunk Search 02-19-2010
3 1
3
1
Ledion_Bitincka
explain the significance of the connected flag in transaction
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 02-11-2010
2 1
2
1
Ledion_Bitincka
Dan Goldburt asks: I'm consistently getting the following request from customers: "can I see where each event came fr...
by Ledion_Bitincka Splunk Employee Splunk Employee in Splunk Search 02-11-2010
1 1
1
1
V_at_Splunk
Such a helpful command, and yet doesn't work for me...
by V_at_Splunk Splunk Employee Splunk Employee in Splunk Search 02-05-2010
1 3
1
3
Mick
When I run this search - source="*conn.log" | rex field=_raw "\.IP = '(?<connectionIp>[^']+)" | fields host, connect...
by Mick Splunk Employee Splunk Employee in Splunk Search 02-05-2010
4 1
4
1
Mick
We are attempting to create a report that compares message traffic for the past two complete weeks. We have this as...
by Mick Splunk Employee Splunk Employee in Splunk Search 02-05-2010
0 2
0
2
Yancy
Any recommended best practices for managing eventtypes and their corresponding tags? I've found the Splunk Common In...
by Yancy Path Finder in Splunk Search 02-02-2010
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...