Splunk Search

Splunk Search
Community Activity
Justin_Grant
My search returns 10 fields in each event and I want to create a table with one row per event and columns for 3 of th...
by Justin_Grant Contributor in Splunk Search 04-09-2010
0 6
0
6
rayfoo
Wanted to see what is/are the possible methods to do so. One way I could think of is to export the results using out...
by rayfoo Path Finder in Splunk Search 04-08-2010
1 7
1
7
MHS
I use the following query against a Cisco as5400 to find the number of calls per hour during a day. 10.200.90.19 Cal...
by MHS Explorer in Splunk Search 04-08-2010
0 4
0
4
imrago
After upgrading to 4.1 from 4.0.10 I am unable to get fields using a search from python script. The simplified versio...
by imrago Contributor in Splunk Search 04-08-2010
0 2
0
2
zscgeek
I am trying to get scripted auth working on the new 4.1. I had a configuration on 3.4.x that worked great but after m...
by zscgeek Path Finder in Splunk Search 04-07-2010
0 2
0
2
Justin_Grant
What are the searches required to search across Windows Event Logs for: most recent events of a particular event ID ...
by Justin_Grant Contributor in Splunk Search 04-07-2010
2 1
2
1
the_wolverine
Splunk does such an awesome job with distributed search. It seems like all my data is on one server (my search head)...
by the_wolverine Champion in Splunk Search 04-07-2010
1 2
1
2
Alan_Bradley
After upgrading to Splunk 4.1 from 4.0.10 today, we find that we can no longer run searches. splunkd.log shows: 04-...
by Alan_Bradley Path Finder in Splunk Search 04-05-2010
4 1
4
1
SteveS
If I have a bunch of saved searches I run hourly, what should I consider before switching any or all of them to real ...
by SteveS Splunk Employee Splunk Employee in Splunk Search 04-05-2010
2 2
2
2
mfrost8
I'm using Splunk 4.0.10. I've been working on doing field extractions (transforms.conf) on a DB2 log file. I've man...
by mfrost8 Builder in Splunk Search 04-05-2010
0 1
0
1
zscgeek
Question: What pipeline module does the sed pre-indexing code run in. I have the following props.conf in my app an...
by zscgeek Path Finder in Splunk Search 04-05-2010
1 1
1
1
Jaci
Saw this error in splunklogger.log. What does it mean?
by Jaci Splunk Employee Splunk Employee in Splunk Search 04-01-2010
1 1
1
1
rsimmons
We are indexing a lot of Cisco syslog messages. I notice that the host field is extracted correctly, but src/dst IP a...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 04-01-2010
3 3
3
3
Peter
I have a script that populates the previous day's data early in the following morning. How do I set a time range such...
by Peter Path Finder in Splunk Search 04-01-2010
2 3
2
3
thepocketwade
I've got a field extraction defined in my props.conf, but now I want to be able to select it in a search without usin...
by thepocketwade Path Finder in Splunk Search 04-01-2010
1 5
1
5
Glenn
I have heard that this is possible - please correct me if I am wrong. Firstly, the reason I want to do this. We inde...
by Glenn Builder in Splunk Search 04-01-2010
0 4
0
4
Erik_Swan
I'm curious how to plan a deployment where i have many concurrent searches. I understand how to account for indexing...
by Erik_Swan Splunk Employee Splunk Employee in Splunk Search 03-29-2010
1 1
1
1
hulahoop
I understand summary indexing can drastically improve the load time of my dashboards. In addition, if I schedule eac...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 03-26-2010
7 5
7
5
jrodman
Are search-time fields slow? Can I rely on them to efficiently sort through my data? Are there significant differenc...
by jrodman Splunk Employee Splunk Employee in Splunk Search 03-24-2010
5 4
5
4
Alan_Bradley
I got Your index exceeded your 20.00 GB/day limit again. I would like to know which data inputs cause this.
by Alan_Bradley Path Finder in Splunk Search 03-21-2010
0 2
0
2
Alan_Bradley
For every Retention key (already extracted by Splunk: 20181947800000) I want to subtract the requestTime="2009-05-26T...
by Alan_Bradley Path Finder in Splunk Search 03-19-2010
0 1
0
1
chris
Hi I would like to have a way to find out whether hosts have stopped logging to our central log infrastructure or i...
by chris Motivator in Splunk Search 03-19-2010
0 3
0
3
Glenn
I am having trouble getting my head around the search required to graph multiple values from the same log event. It s...
by Glenn Builder in Splunk Search 03-18-2010
2 5
2
5
Justin_Grant
Our office has a specific TRANSACTION search we do frequently to track all events related to a particular user. The s...
by Justin_Grant Contributor in Splunk Search 03-16-2010
0 5
0
5
hulahoop
I'd like to provide a table where the event count for today and yesterday are displayed. For example, count by statu...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 03-16-2010
0 2
0
2
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors