The fields command in 4.1.2, build 79191 has a bug. It includes all results from the _* fields even when specified w... by rayfoo Path Finder in Splunk Search 06-02-2010 0 3 | 0 | 3 | ||
What is the recommended way to export/archive a large amount of historical data for retention or offline storage? I ... 0 1 | 0 | 1 | ||
Is there a way to apply a SED like filter after a search. The plumbing is there to filter and sanitize data going int... by Marinus Communicator in Splunk Search 06-02-2010 1 2 | 1 | 2 | ||
When using an entitySelectLister ... does the entityPath have to be a saved search name? or can i use a searchTemplat... by hiddenkirby Contributor in Dashboards & Visualizations 06-02-2010 0 6 | 0 | 6 | ||
For some reason this search maxes out at 10000 (i.e. only returns 10000 sources, there are more...), and I can't seem... by parallaxed Path Finder in Splunk Search 06-02-2010 1 3 | 1 | 3 | ||
Hi experts, I would like to know if it is possible to exclude the result of 'addcoltotals' from the y axis scale. ... by sflisher Explorer in Splunk Search 06-02-2010 1 1 | 1 | 1 | ||
I have some log like following: 13:47:04 -2 receive request [type=0|desc=TimeStamp] <---event one | [8 ] [BCA3.5] | ... by mzorzi Splunk Employee in Splunk Search 06-02-2010 2 1 | 2 | 1 | ||
I have two multiline events (they are stuffed with the contents of two versions of a config file) and I'd like a good... by Justin_Grant Contributor in Dashboards & Visualizations 06-02-2010 2 2 | 2 | 2 | ||
I'm sure someone has figured out how to handle this data. What I am trying to do is index and extract all of the dat... by Steven_McGrath Engager in Splunk Search 06-02-2010 1 1 | 1 | 1 | ||
I have an environment where there are about 2000 hosts. All the hosts are tagged according to the geographic location... by sanju005ind Communicator in Dashboards & Visualizations 06-01-2010 0 4 | 0 | 4 | ||
I need to aggregate the values found in the apache weblogs. First I need to parse out several fields. I can get these... by pbenner Explorer in Splunk Search 06-01-2010 0 1 | 0 | 1 | ||
i have a case to count db operations. in the log file, the format is like: [time1] op=select data=.... [time2] op=SE... by William Path Finder in Splunk Search 06-01-2010 1 1 | 1 | 1 | ||
For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table",... by William Path Finder in Splunk Search 06-01-2010 0 3 | 0 | 3 | ||
We've got log events that read like the following: Mar 14 12:26:38 mailsrv.example.com MM: [Jilter Processor 21 - ... by smisplunk Path Finder in Splunk Search 05-31-2010 1 7 | 1 | 7 | ||
Hi All, I need a sanity check. This extraction seemed to work in 4.0, Can someone help? mac_address and source_ip ... by dcroteau Splunk Employee in Splunk Search 05-30-2010 0 4 | 0 | 4 | ||
I'm looking for best practice when setting up a savedsearch email alerting when the alerting has the following requir... 2 6 | 2 | 6 | ||
I have a few scheduled searches that become 'unscheduled' randomly. I don't notice this until I miss a service outag... 1 1 | 1 | 1 | ||
Running this search: http://host1.com:8000/en-US/app/search/flashtimeline?q=search%20* | regex_raw%3D%22%25SYS-5-CON... by Jaci Splunk Employee in Splunk Search 05-28-2010 3 2 | 3 | 2 | ||
Hi I have a saved-search (my_search) that is configured to run every 30 minutes. It gathers aggregate data from th... 1 4 | 1 | 4 | ||
The docs reference the option of passing macro values into a saved search. How does that work exactly? I understand... 0 5 | 0 | 5 | ||
I am trying to setup a scheduled search that runs every morning and looks for users logged on between 2200 the previo... by Mike_Spellane New Member in Splunk Search 05-27-2010 0 2 | 0 | 2 | ||
I am willfully using the free version, and for now don't have the option to upgrade to the paid enterprise version. ... 0 3 | 0 | 3 | ||
I am having trouble getting my form search to bring back anything. The xml is accepted by splunk but the search won't... by riderofyamaha Explorer in Splunk Search 05-27-2010 0 2 | 0 | 2 | ||
I need help with a query to find the forwarders which stopped reporting for more than 2 weeks. by sanju005ind Communicator in Splunk Search 05-27-2010 0 4 | 0 | 4 | ||
I am trying to create a macro that would take as it's input the result of an eval earlier in the search string, for e... by stephanbuys Path Finder in Reporting 05-27-2010 0 4 | 0 | 4 |
Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.