Splunk Search

Splunk Search
Community Activity
Josh
How can I consolidate 2 or more fields into one new field at search time? e.g. ...| fields a,b,c | d In the above I...
by Josh Path Finder in Splunk Search 04-28-2010
0 7
0
7
Hazel
Hello, I am trying to configure a props/transforms and it is not working. it does not come up as an extra field tha...
by Hazel Communicator in Splunk Search 04-28-2010
1 3
1
3
Hazel
Hello, I am rewriting this - hope it makes more sense. I have config files, which I am passing into splunk as follo...
by Hazel Communicator in Splunk Search 04-28-2010
0 6
0
6
igotimac
In Previous versions of splunk on the search interface a "source" and "sourcetype" were reported underneath each in e...
by igotimac Engager in Splunk Search 04-26-2010
1 2
1
2
Josh
Hi All, I am having trouble breaking up the log file below: Each log entry starts with id:#################### and ...
by Josh Path Finder in Splunk Search 04-26-2010
1 5
1
5
prodport
In the Splunk 4.1 webcast earlier this week, one of the presenters showed a combined_access report that looked to pro...
by prodport New Member in Splunk Search 04-26-2010
0 2
0
2
rayfoo
After upgrading to version 4.1.1, build 78281, Splunk shows a JavaScript prompt with the following error in the searc...
by rayfoo Path Finder in Splunk Search 04-26-2010
1 3
1
3
Mystere
I have a logfile that is not very orthogonal. It will include, for example, IP Address of an action one line, and th...
by Mystere New Member in Splunk Search 04-26-2010
0 2
0
2
maverick
The tagcreate and tagdelete commands existed in Splunk 3.x, but they do not seem to be supported in Splunk 4.0. Any ...
by maverick Splunk Employee Splunk Employee in Splunk Search 04-26-2010
3 4
3
4
zliu
build an application limiting end-user searches to a single field (by using HiddenSearch/ExtendedFieldSearch modules)...
by zliu Splunk Employee Splunk Employee in Splunk Search 04-24-2010
0 1
0
1
Peter
I need to generate a splunk coverage report that shows all of the hosts and all of the sources they are sending from....
by Peter Path Finder in Splunk Search 04-24-2010
0 5
0
5
maxmichaels
I'm trying to define a custom set of fields for a sourcetype and am finding that the "train" command is a) tedious b)...
by maxmichaels New Member in Splunk Search 04-23-2010
0 2
0
2
ghnwmlguy
The results of a report show the following in a table: -variable value -Allowed 1 -Allowed_Tagged 1 -Blocked...
by ghnwmlguy Explorer in Splunk Search 04-23-2010
1 4
1
4
sreedhardudi
--input.conf [monitor:///etl/issrdr/scripts/tst/splunk/input/updates.csv] index=iss-rdr --props.conf [source::/et...
by sreedhardudi New Member in Splunk Search 04-23-2010
0 4
0
4
muebel
I have been having repeated warnings that the system is unable to read metadata.csv, which looks like it should be lo...
by SplunkTrust SplunkTrust in Splunk Search 04-23-2010
1 1
1
1
mzorzi
I'm running a search based on a field extracted at search time using props.conf. I've noticed that if I don't have a...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 04-23-2010
3 4
3
4
nik_splunk
Good morning all! Today my goal is : evaluate suspicious logfail by a criteria (as follow). If "logfail" on the same...
by nik_splunk Path Finder in Splunk Search 04-23-2010
2 4
2
4
the_wolverine
I have a simple case where I want to see if the value of one field has shown up as the value of another field. rec=d...
by the_wolverine Champion in Splunk Search 04-23-2010
1 3
1
3
sranga
Hi I was wondering if it is possible to generate a chart based on the following criteria: “Display the top X perce...
by sranga Path Finder in Splunk Search 04-23-2010
2 4
2
4
sranga
Hi Say I have the following log statements (generated throughout the day): id=111,type=2,field1=y id=141,type=2...
by sranga Path Finder in Splunk Search 04-23-2010
1 7
1
7
Justin_Grant
I have indexed the contents of a relational database along with a log file. My log contains these fields: cost - thi...
by Justin_Grant Contributor in Splunk Search 04-22-2010
8 6
8
6
gkanapathy
I thought there was a way to enumerate the enabled and disabled apps from the CLI. Is this so, and if so, what is it?
by gkanapathy Splunk Employee Splunk Employee in Splunk Search 04-22-2010
2 7
2
7
pj
Hi, am looking to pull together a table chart of our threat data that contains 3 columns: threat, totalhosts and uniq...
by pj Contributor in Splunk Search 04-22-2010
1 1
1
1
Yancy
What are some methods of determining anomalous login behavior with Splunk?
by Yancy Path Finder in Splunk Search 04-21-2010
2 3
2
3
mctester
I need to create a custom chart in splunk and be able to tag the results of that search with a ticket number for trac...
by mctester Communicator in Splunk Search 04-21-2010
2 1
2
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...