Splunk Search

Splunk Search
Community Activity
Lowell
Is there a way to split the text of an event into multiple events (preferably using a regular expression) at search-t...
by Lowell Super Champion in Splunk Search 04-29-2010
1 2
1
2
the_wolverine
I have a search-time field extraction that shows up in my pick fields list and everything. The fields list is showin...
by the_wolverine Champion in Splunk Search 04-29-2010
3 7
3
7
Lowell
Is there some reason why using the lookup command doesn't seem to be working properly after stats? The search I'm tr...
by Lowell Super Champion in Splunk Search 04-29-2010
0 3
0
3
yzubarev
Greetings, I introduced a new sourcetype "access_combined_wperformance" but I cannot get it utilized as "access_comb...
by yzubarev Explorer in Splunk Search 04-28-2010
3 12
3
12
Josh
How can I consolidate 2 or more fields into one new field at search time? e.g. ...| fields a,b,c | d In the above I...
by Josh Path Finder in Splunk Search 04-28-2010
0 7
0
7
Hazel
Hello, I am trying to configure a props/transforms and it is not working. it does not come up as an extra field tha...
by Hazel Communicator in Splunk Search 04-28-2010
1 3
1
3
Hazel
Hello, I am rewriting this - hope it makes more sense. I have config files, which I am passing into splunk as follo...
by Hazel Communicator in Splunk Search 04-28-2010
0 6
0
6
igotimac
In Previous versions of splunk on the search interface a "source" and "sourcetype" were reported underneath each in e...
by igotimac Engager in Splunk Search 04-26-2010
1 2
1
2
Josh
Hi All, I am having trouble breaking up the log file below: Each log entry starts with id:#################### and ...
by Josh Path Finder in Splunk Search 04-26-2010
1 5
1
5
prodport
In the Splunk 4.1 webcast earlier this week, one of the presenters showed a combined_access report that looked to pro...
by prodport New Member in Splunk Search 04-26-2010
0 2
0
2
rayfoo
After upgrading to version 4.1.1, build 78281, Splunk shows a JavaScript prompt with the following error in the searc...
by rayfoo Path Finder in Splunk Search 04-26-2010
1 3
1
3
Mystere
I have a logfile that is not very orthogonal. It will include, for example, IP Address of an action one line, and th...
by Mystere New Member in Splunk Search 04-26-2010
0 2
0
2
maverick
The tagcreate and tagdelete commands existed in Splunk 3.x, but they do not seem to be supported in Splunk 4.0. Any ...
by maverick Splunk Employee Splunk Employee in Splunk Search 04-26-2010
3 4
3
4
zliu
build an application limiting end-user searches to a single field (by using HiddenSearch/ExtendedFieldSearch modules)...
by zliu Splunk Employee Splunk Employee in Splunk Search 04-24-2010
0 1
0
1
Peter
I need to generate a splunk coverage report that shows all of the hosts and all of the sources they are sending from....
by Peter Path Finder in Splunk Search 04-24-2010
0 5
0
5
maxmichaels
I'm trying to define a custom set of fields for a sourcetype and am finding that the "train" command is a) tedious b)...
by maxmichaels New Member in Splunk Search 04-23-2010
0 2
0
2
ghnwmlguy
The results of a report show the following in a table: -variable value -Allowed 1 -Allowed_Tagged 1 -Blocked...
by ghnwmlguy Explorer in Splunk Search 04-23-2010
1 4
1
4
sreedhardudi
--input.conf [monitor:///etl/issrdr/scripts/tst/splunk/input/updates.csv] index=iss-rdr --props.conf [source::/et...
by sreedhardudi New Member in Splunk Search 04-23-2010
0 4
0
4
muebel
I have been having repeated warnings that the system is unable to read metadata.csv, which looks like it should be lo...
by SplunkTrust SplunkTrust in Splunk Search 04-23-2010
1 1
1
1
mzorzi
I'm running a search based on a field extracted at search time using props.conf. I've noticed that if I don't have a...
by mzorzi Splunk Employee Splunk Employee in Splunk Search 04-23-2010
3 4
3
4
nik_splunk
Good morning all! Today my goal is : evaluate suspicious logfail by a criteria (as follow). If "logfail" on the same...
by nik_splunk Path Finder in Splunk Search 04-23-2010
2 4
2
4
the_wolverine
I have a simple case where I want to see if the value of one field has shown up as the value of another field. rec=d...
by the_wolverine Champion in Splunk Search 04-23-2010
1 3
1
3
sranga
Hi I was wondering if it is possible to generate a chart based on the following criteria: “Display the top X perce...
by sranga Path Finder in Splunk Search 04-23-2010
2 4
2
4
sranga
Hi Say I have the following log statements (generated throughout the day): id=111,type=2,field1=y id=141,type=2...
by sranga Path Finder in Splunk Search 04-23-2010
1 7
1
7
Justin_Grant
I have indexed the contents of a relational database along with a log file. My log contains these fields: cost - thi...
by Justin_Grant Contributor in Splunk Search 04-22-2010
8 6
8
6
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors