Top

Top
Category Activity
Yancy
Is there a way to set tags based off a wild card value? IE I have the following hosts and I want to apply the 'test'...
by Yancy Path Finder in Getting Data In 05-27-2010
0 2
0
2
bfaber
can I get transaction to show hostname or sourcetype for each event within? I'd like to be able to pass a transactio...
by bfaber Communicator in Splunk Search 05-26-2010
0 5
0
5
dwaddle
Is the output of 'splunk list monitor' clipped at all? I have a directory with (approx) 50 log files, but the outp...
by SplunkTrust SplunkTrust in Monitoring Splunk 05-26-2010
3 4
3
4
hulahoop
In inputs.conf and props.conf, the wildcards ... and * are supported for use in the spec headers. What do they trans...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 05-26-2010
2 3
2
3
Rob_Jordan
While the following extraction below works, I wanted to see if I could extract both custom fields EAR_FILE and DOMAIN...
by Rob_Jordan Explorer in Splunk Search 05-26-2010
2 2
2
2
rgcox1
When searching for lost forwarders a host with an all caps name is returned as lost when the same host with a lower c...
by rgcox1 Communicator in Splunk Search 05-26-2010
0 3
0
3
msenthilganesh
I am expecting to see each record as an event, but the result is not as expected. Some records are displayed as indi...
by msenthilganesh New Member in Getting Data In 05-26-2010
0 1
0
1
bfaber
If I have data like this: src=1.1.1.1 dst=2.2.2.2 can I create a mvfield of ip's? like: ips=1.1.1.1,2.2.2.2 FRO...
by bfaber Communicator in Splunk Search 05-26-2010
1 2
1
2
bfaber
If I have data that looks like (date) srcip=x.x.x.x dstip=y.y.y.y How can I create a single list of all unique IPs...
by bfaber Communicator in Splunk Search 05-26-2010
1 6
1
6
Chris_R_
If we have an indexer configured w/a raid 5 or raid 6 array is this going to negatively affect performance?
by Chris_R_ Splunk Employee Splunk Employee in Getting Data In 05-26-2010
2 4
2
4
littlejef
I am currently running a eval version of Splunk 4.0.9 on a Windows 2008 64Bit Host. Our purchase of Splunk has been a...
by littlejef Engager in Getting Data In 05-26-2010
1 1
1
1
balbano
Hi, we are currently testing a Palo Alto app sec firewall and are sending some test logs over to the central indexer ...
by balbano Contributor in Getting Data In 05-26-2010
0 6
0
6
Genti
I would like to deploy Light Forwarders at our remote locations to act as a syslog server. Can light forwarder be con...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-25-2010
2 2
2
2
smisplunk
I've got a summary index query which currently matches only one (1) event in my existing data. I've run the fill_sum...
by smisplunk Path Finder in Knowledge Management 05-25-2010
0 3
0
3
Ellen
After a Splunk restart without any configuration changes, I can no longer issue any Splunk CLI commands such as these...
by Ellen Splunk Employee Splunk Employee in Splunk Dev 05-25-2010
3 1
3
1
Pete_Bassill
Hi I need to extract a splunk app file (.spl) created in v4.1.2 onto a non splunk machine (linux workstation) to car...
by Pete_Bassill Path Finder in All Apps and Add-ons 05-25-2010
0 4
0
4
wdc
I've found how to get data from a remote users Security Log but we are after a centralised area to keep these logs. I...
by wdc New Member in Getting Data In 05-25-2010
0 3
0
3
maverick
Is there a way to report on the position of an event relative to the rest of the events in the result set? For examp...
by maverick Splunk Employee Splunk Employee in Splunk Search 05-25-2010
0 2
0
2
ASW3382
I am revisiting splunk to see if it will meet our goals. Right now I am working on the initial index of our data gat...
by ASW3382 New Member in Getting Data In 05-24-2010
0 4
0
4
nbharadwaj
How can I use lookups for a source CSV file that is not under the Splunk code tree? I am using Splunk 4.0.10. CSV lo...
by nbharadwaj Path Finder in Splunk Search 05-24-2010
1 1
1
1
Jaci
Our indexer and all forwarders are running 4.1.2. Recently we developed a need to send events from our forwarders in...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 3
1
3
Genti
What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load...
by Genti Splunk Employee Splunk Employee in Getting Data In 05-24-2010
0 1
0
1
Jaci
I have a deployment server app with a single inputs.conf file. [tcp://localhost:9997] sourcetype = tcp-raw index = p...
by Jaci Splunk Employee Splunk Employee in Getting Data In 05-24-2010
1 2
1
2
caphrim007
Is it possible to change the axis titles for line charts? I can do so with column charts <option name="charting.pr...
by caphrim007 Path Finder in Dashboards & Visualizations 05-24-2010
0 1
0
1
johnpulley
I want to use Splunk to monitor the error output of a telephone switch. I can easily see the data by connecting to th...
by johnpulley New Member in Monitoring Splunk 05-24-2010
0 5
0
5
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...
Top Karma Authors