Thread Info | |||||
---|---|---|---|---|---|
I am trying to create a field that contains information about the type of host based on the host field. For example, ...
by
axsolis
Path Finder
in
Splunk Search
11-16-2010
|
1
|
4
| |||
I have log entries looking as follows:
Nov 16 08:37:47 psdkxt05 MID=xxx005I;XID=;SID=;UID=;STM=2010-11-16 08:37:47...
by
JYTTEJ
Communicator
in
Splunk Search
11-18-2010
|
0
|
2
| |||
I'm new to creating subsearches. I need to combine fields from two different sourcetypes based on a date. Event one h...
by
snowmizer
SplunkTrust
in
Splunk Search
06-28-2010
|
2
|
5
| |||
Hey everyone. Right now I'm dealing with some CSV files that are set up in the following format: line 1: version head...
by
msarro
Builder
in
Splunk Search
11-15-2010
|
2
|
11
| |||
Couldn't see to find a question like this here, but maybe my search for it is no good.
What I'd like to do is have...
by
skippylou
Communicator
in
Splunk Search
11-17-2010
|
1
|
2
| |||
Some sources will produce data that overlaps i.e. you get some of the data you already indexed. This can have quite a...
by
Marinus
Communicator
in
Splunk Search
07-29-2010
|
4
|
5
| |||
I'm trying to find the quickest way to run a large search against a large dataset which will have a large set of resu...
by
blurblebot
Communicator
in
Splunk Search
11-16-2010
|
1
|
3
| |||
I'm having a tough time searching for this, sorry if it's been asked many times. I have an event that carries a few t...
by
wmwilson01
Engager
in
Splunk Search
11-16-2010
|
2
|
2
| |||
I would like to find
All Users that have not logged in for 90 days ans active scheduled searches associated with ...
by
sanju005ind
Communicator
in
Splunk Search
11-02-2010
|
0
|
1
| |||
Hi,all
I want to use "substr" to get what I want.
A=1420014
... |eval A=if(substr(A, 1,2)="14",replace(A, "1...
by
flora123
Path Finder
in
Splunk Search
11-16-2010
|
1
|
2
| |||
I have hosts/forwarders reporting to multiple indexers using load balancing.I have 3 in Americas,2 in Aspac.
I am ...
by
sanju005ind
Communicator
in
Splunk Search
11-12-2010
|
0
|
3
| |||
Dear All,
I'm doing a search as the following:
sourcetype="sophos" pmx_action="keep" fur!="none"| bucket span=2...
by
fedevietti
New Member
in
Splunk Search
11-08-2010
|
0
|
3
| |||
I want to search my firewall log for tcp denials from the outside on port 22. So far, I have this:
"deny tcp sourc...
by
patrickbass
New Member
in
Splunk Search
11-12-2010
|
0
|
1
| |||
Appreciate the answer to my original question, but it leads me to a couple of additional issues:
0) As I write thi...
by
nbcohen
Explorer
in
Splunk Search
11-12-2010
|
0
|
2
| |||
I have an extracted field called ruby_completed_call, that extracts the completion time from a ruby log:
Processin...
by
Simeon
Splunk Employee
in
Splunk Search
11-11-2010
|
1
|
2
|