Using Splunk

Using Splunk
Category Activity
Peter
I am attempting to write a search that can alert if a user deviates from some normal data viewing pattern. The event ...
by Peter Path Finder in Splunk Search 05-03-2010
1 16
1
16
clyde772
I want to chop multiline events like below. I had splunk to automatically process the data, but it didn't quite work...
by clyde772 Communicator in Splunk Search 05-03-2010
0 1
0
1
clyde772
Anybody out there had experience trying to correlate events with Splunk. A scenario would be like this: (Source : A...
by clyde772 Communicator in Alerting 05-03-2010
0 3
0
3
nik_splunk
Hello Splunkers, Thanks to visit my question. I have two subsets of data related to each other. The set A consists...
by nik_splunk Path Finder in Splunk Search 05-02-2010
0 1
0
1
clyde772
Let assume the following, the data source for analysis is Firewall traffic log. I guess It could be applied to any ...
by clyde772 Communicator in Splunk Search 05-02-2010
0 1
0
1
ghnwmlguy
I have configured automatic lookups with the intention of using it in only one app (my own ossec app). However, when...
by ghnwmlguy Explorer in Splunk Search 04-30-2010
0 4
0
4
Lowell
Has anyone thought through the pros/cons of setting up an external (independent) PDF server vs running the PDF server...
by Lowell Super Champion in Reporting 04-30-2010
0 2
0
2
vbumgarn
We have logs that do stuff like this: message id=1 message id=2 parent=1 message id=2 parent=1 message id=3 ...
by vbumgarn Path Finder in Splunk Search 04-30-2010
2 1
2
1
clyde772
How I can I remove specfic indexed data from an exsiting data index?
by clyde772 Communicator in Splunk Search 04-30-2010
3 2
3
2
Steve_Litras
Prior to 4.1, my host field reverse resolved (i.e. instead of ip addresses, it showed hostnames from DNS) for syslog ...
by Steve_Litras Path Finder in Splunk Search 04-30-2010
1 3
1
3
sanju005ind
After initial installation of the forwarder when the Splunk service is started the forwarder reports by Ip Address.Af...
by sanju005ind Communicator in Splunk Search 04-30-2010
2 1
2
1
Ellen
In the UI I navigate to Jobs and see entries identified as Owner "splunk-system-user" why is that?
by Ellen Splunk Employee Splunk Employee in Reporting 04-30-2010
2 2
2
2
Nicholas_Key
I would like to know if there is a way to generalize the following EXTRACT regexes in my props.conf? The configuratio...
by Nicholas_Key Splunk Employee Splunk Employee in Splunk Search 04-30-2010
0 2
0
2
the_wolverine
INFO SavedSplunker - Found 2 scheduled saved searches INFO SavedSplunker - About to run saved search: 'admin;search...
by the_wolverine Champion in Reporting 04-29-2010
0 1
0
1
Lowell
Is there a way to split the text of an event into multiple events (preferably using a regular expression) at search-t...
by Lowell Super Champion in Splunk Search 04-29-2010
1 2
1
2
the_wolverine
I have a search-time field extraction that shows up in my pick fields list and everything. The fields list is showin...
by the_wolverine Champion in Splunk Search 04-29-2010
3 7
3
7
bfaber
how can I change the fonts on an ubuntu server so they are not really ugly? Are there other packages I can install?
by bfaber Communicator in Reporting 04-29-2010
1 2
1
2
Lowell
Is there some reason why using the lookup command doesn't seem to be working properly after stats? The search I'm tr...
by Lowell Super Champion in Splunk Search 04-29-2010
0 3
0
3
yzubarev
Greetings, I introduced a new sourcetype "access_combined_wperformance" but I cannot get it utilized as "access_comb...
by yzubarev Explorer in Splunk Search 04-28-2010
3 12
3
12
Josh
How can I consolidate 2 or more fields into one new field at search time? e.g. ...| fields a,b,c | d In the above I...
by Josh Path Finder in Splunk Search 04-28-2010
0 7
0
7
Hazel
Hello, I am trying to configure a props/transforms and it is not working. it does not come up as an extra field tha...
by Hazel Communicator in Splunk Search 04-28-2010
1 3
1
3
rsimmons
Error message from users python.log: 2010-04-23 16:30:12,102 INFO xvfb:115 - Starting X Server: ['/usr/bin/Xvfb',...
by rsimmons Splunk Employee Splunk Employee in Reporting 04-28-2010
2 1
2
1
Hazel
Hello, I am rewriting this - hope it makes more sense. I have config files, which I am passing into splunk as follo...
by Hazel Communicator in Splunk Search 04-28-2010
0 6
0
6
rsimmons
2010-04-23 16:30:22,153 WARNING pdfhandler:396 - Restricting Firefox to following hosts only: *:53 10.128.11.67 201...
by rsimmons Splunk Employee Splunk Employee in Reporting 04-28-2010
1 1
1
1
the_wolverine
I want to change the default UI segmentation behavior for a certain sourcetype. How can I do this?
by the_wolverine Champion in Dashboards & Visualizations 04-27-2010
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security and Observability Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...
Top Karma Authors