Thread Info | |||||
---|---|---|---|---|---|
I'm doing a search for invalid logons for our vpn logs. But I want the search results to return when the invalid atte...
by
aanetserv
New Member
in
Splunk Search
09-27-2010
|
0
|
2
| |||
I want to gobble in CSV files containing numeric data. Each file will have between 500 and 150,000 fields. (Yes that'...
by
l0r3zz
New Member
in
Splunk Search
09-27-2010
|
0
|
8
| |||
I have the following search which I would like to use to populate a summary index for reporting (run every 30 minutes...
by
cudgel
Path Finder
in
Splunk Search
09-23-2010
|
1
|
4
| |||
Hey,
The answer to this question will be very useful to know
I have an advanced dashboard with a few charts (...
by
Ant1D
Motivator
in
Splunk Search
09-30-2010
|
2
|
4
| |||
In Windows I have the following in the Inputs.conf:
[monitor://C:\Program Files\Microsoft SQL Server\MSSQL10_50.MS...
by
Kyle_Brandt
Path Finder
in
Splunk Search
09-30-2010
|
0
|
5
| |||
I have a search that pipes to another search, and this search is highlighting the results. I do not want the highligh...
by
ericrobinson
Path Finder
in
Splunk Search
09-10-2010
|
10
|
4
| |||
I have a dataset where the rows in my search results all have a 'value' field, and there's another field that specifi...
by
sideview
SplunkTrust
in
Splunk Search
09-28-2010
|
5
|
4
| |||
In order to identify web content that hasn't been pulled in a while, I thought I would use Splunk since a) my Apache ...
by
Brian_Osburn
Builder
in
Splunk Search
09-29-2010
|
3
|
4
| |||
We're trying to set up a dynamic sourcetype extraction at index time. The reason for this is that we have about 40-50...
by
mattcg
Explorer
in
Splunk Search
09-30-2010
|
2
|
2
| |||
I don’t have any background in Telco world, I’m so blank about it,
Telco people asked this many times,
is it po...
by
donnylie
Explorer
in
Splunk Search
09-30-2010
|
0
|
1
| |||
I just ran a search that returned approximately 1 million results. Only after it completed (which took a bit longer t...
by
thepocketwade
Path Finder
in
Splunk Search
09-30-2010
|
3
|
2
| |||
We seem to be having an issue with the postfix_syslog sourcetype (that came as a default sourcetype in Splunk) and it...
by
adamw
Communicator
in
Splunk Search
09-29-2010
|
0
|
5
| |||
I have jboss logs that print a message size everytime jboss restarts. The message size is different everytime jboss s...
by
htkhtk
Path Finder
in
Splunk Search
09-30-2010
|
0
|
4
| |||
If I do a search for something such as: uri="/this/or/that.html" over, say, an hour.
Once the search completes (fi...
by
JohnB
Explorer
in
Splunk Search
09-29-2010
|
0
|
3
| |||
Hello, How do i use multikv to extract fields that have % or / in them ? I'm unable to extract if it has those charac...
by
pmr
Explorer
in
Splunk Search
09-29-2010
|
1
|
2
| |||
I have a Splunk app that parses some Snort files and assigns some fields to the content. The app works fine from the ...
by
klumpba
Engager
in
Splunk Search
06-17-2010
|
4
|
3
| |||
When I use the "diff" search command to compare events that contain several hundred lines, I notice that differences ...
by
hexx
Splunk Employee
in
Splunk Search
09-28-2010
|
4
|
2
| |||
I have read the this page about the concept of "Intention" : http://www.splunk.com/base/Splexicon:Intention
It say...
by
leo_wang
Path Finder
in
Splunk Search
09-24-2010
|
1
|
5
| |||
I have the following query which almost does what I want:
sourcetype="cisco_wsa_squid"
| lookup teamlookup cs_user...
by
cmeo
Contributor
in
Splunk Search
09-22-2010
|
0
|
4
| |||
For the AMMAP application for the map, I followed the instruction and installed MAXMIND and the AMMAP app, but I can'...
by
clyde772
Communicator
in
Splunk Search
05-05-2010
|
0
|
6
|