Splunk Search

Splunk Search
Community Activity
SplunkMonster
So I have two log sources-- one that stores values X and Y together in the same index, and the second which stores va...
by SplunkMonster Engager in Splunk Search 01-27-2019
0 6
0
6
DavidHourani
Hello, Does anyone have a search command to find / list all scheduled searches, the time they should run at and the ...
by DavidHourani Super Champion in Splunk Search 01-27-2019
0 4
0
4
james_n
Hi, I have data like mentioned below 28-11-01 10:30:13,127 digits=30 28-11-01 07:20:08,240 digits=50 28-11-01 05:0...
by james_n Path Finder in Splunk Search 01-27-2019
0 6
0
6
vkari
How do i get different events names and same reference ID stat time from one event and end time from one event and a...
by vkari New Member in Splunk Search 01-27-2019
0 3
0
3
srampally
I am getting an error from Heavy Forwarder. Below is the error : The monitor input cannot produce data because splun...
by srampally Path Finder in Splunk Search 01-27-2019
2 1
2
1
mumblingsages
Given data like: _time, lastname How would I do a count of lastname and display the most recent _time for that la...
by mumblingsages Path Finder in Splunk Search 01-27-2019
0 2
0
2
pinkyyu
how do I get common information from two users in a proxy log? for example, i would like to find whether a URL that...
by pinkyyu Explorer in Splunk Search 01-27-2019
0 2
0
2
christay
Hi I have the following setup : 1 x Node Master with 2 x indexer ( Clustering) How can I configure to designate one...
by christay New Member in Splunk Search 01-27-2019
0 3
0
3
johnsmithcy
how to set the log size limit? how to make automatic deletion for the log collected
by johnsmithcy Path Finder in Splunk Search 01-27-2019
0 8
0
8
lakshmichandu
Warning: overriding %SPLUNK_HOME% setting in environment ("C:\Program Files\Splunk\bin") with "C:\Program Files\Splun...
by lakshmichandu New Member in Splunk Search 01-27-2019
0 1
0
1
ddrillic
We have a case in with the time is off by a hundredth of a second for many events of a certain sourcetype - What c...
by ddrillic Ultra Champion in Splunk Search 01-26-2019
0 5
0
5
roayers
Here is a sample of a connection that spans the midnight hour into the next day. I'm trying to extract a new field na...
by roayers Explorer in Splunk Search 01-26-2019
0 5
0
5
bzsplunk54
ERROR UserManagerPro - Could not get info for non-existent user="tesla" We have alerts setup to trigger .py scripts f...
by bzsplunk54 New Member in Splunk Search 01-26-2019
0 2
0
2
asnegina
I have fully configured cluster running Splunk 6.6.5. All indexers and search heads work properly with other inputs. ...
by asnegina New Member in Splunk Search 01-26-2019
0 3
0
3
srampally
I want to know what is the command and from where can i execute to exclude ( /var) folder from backing up.
by srampally Path Finder in Splunk Search 01-26-2019
0 1
0
1
jmcclure
I can send a subset of windows data as syslog server by sourcetype and then use the TransFroms to REGEX out the host....
by jmcclure Explorer in Splunk Search 01-25-2019
0 1
0
1
ahmed23
As we have different regions in AWS, and different sites in that region, is multi site cluster architecture the same ...
by ahmed23 New Member in Splunk Search 01-25-2019
0 1
0
1
ssagar1009
Is there a way I can see how much data is being searched per index? Eg: for an index, a user has searched 10 GB of d...
by ssagar1009 New Member in Splunk Search 01-25-2019
0 3
0
3
rsharma1984
Example: Event A: LoggingAspect.BeforeController Event B: Found in Cache Event C: LoggingAspect.afterReturningCont...
by rsharma1984 Explorer in Splunk Search 01-25-2019
1 7
1
7
danielwan
my splunk server has high CPU usage and I saw a bunch of splunkd process like below search --id=admin_adminsearch_se...
by danielwan Explorer in Splunk Search 01-25-2019
1 3
1
3
navd
Hi , I am using the below query to get an average count . But how do I write a query to send an alert when the numbe...
by navd New Member in Splunk Search 01-25-2019
0 3
0
3
reed_kelly
It is becoming harder to submit cases, because our diag files have gotten very large. In the most recent case, the di...
by reed_kelly Contributor in Splunk Search 01-25-2019
2 4
2
4
sgoodman26
My company gets a log file that we are trying to compare a set of numbers to one another. These numbers have to be wi...
by sgoodman26 Explorer in Splunk Search 01-25-2019
0 4
0
4
joeldavideng
I recently upgraded a Windows heavy forwarder to 7.2.3 and I am now getting errors when it attempts to connect to an ...
by joeldavideng Path Finder in Splunk Search 01-25-2019
0 2
0
2
matansocher
Hi, I want to remove a number (up to 5 digits) from a string on its beginning. an example: 43.aaaa_vvvvv.cccccc:ddd...
by matansocher Contributor in Splunk Search 01-25-2019
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...