I set up an external field lookup and got it working properly. Today I tried add a second. So far, I can only get o... by thepocketwade Path Finder in Splunk Search 04-16-2010 2 7 | 2 | 7 | ||
I've got a user that is missing the "show source" entry at the drop-down box at the left of any search result. How do... by Alan_Bradley Path Finder in Dashboards & Visualizations 04-16-2010 0 3 | 0 | 3 | ||
We had some issues with the way the splunk web server handled our internally signed SSL certs so we setup nginx to ha... 1 5 | 1 | 5 | ||
My panel shows refreshed at (time). It was refreshed at that time because of the scheduling I've applied to the pane... by blurblebot Communicator in Dashboards & Visualizations 04-15-2010 1 1 | 1 | 1 | ||
is it possible to do a stacked bar chart where it splits it in two to show how much is https requests and how much is... by jrich523 Path Finder in Splunk Search 04-15-2010 1 2 | 1 | 2 | ||
Splunk 4.0.10 I have a log file that has 5 fields, date, time, account, received, authorized. It looks like this: 4... by kmattern Builder in Splunk Search 04-14-2010 0 3 | 0 | 3 | ||
how do i show the average number of hits per minute for each hour? basically i have a system that will, on peak hour... by jrich523 Path Finder in Splunk Search 04-14-2010 3 1 | 3 | 1 | ||
Hi folks I have a directory structure on my server box (with splunk LWF) like this: /foo/bar/node1/server1/SystemOu... by Simon Contributor in Splunk Search 04-14-2010 1 3 | 1 | 3 | ||
If you have a time range and certain days contain data you'd like to exclude can you drop the days from your search r... by Marinus Communicator in Splunk Search 04-14-2010 4 2 | 4 | 2 | ||
I would like to be able to see if a user logs in via ssh but doesn't log out within 30 minutes. For example 12:28:4... by netwrkr Communicator in Splunk Search 04-14-2010 2 1 | 2 | 1 | ||
My understanding is that this is now done via a splunk config file. How? by the_wolverine Champion in Splunk Search 04-14-2010 2 1 | 2 | 1 | ||
I see lots of reference to search heads as a way to improve search performance. I can't find a search head section o... by Alan_Bradley Path Finder in Splunk Search 04-14-2010 0 2 | 0 | 2 | ||
My search command is ------ sourcetype="aix_" host="" | sendemail to="rsimmons@splunk.com" 3 1 | 3 | 1 | ||
I have a number of hosts that have a certain tag on them (let's say "sensitive"). I want to look for account lockout ... by Ayn Legend in Splunk Search 04-13-2010 1 2 | 1 | 2 | ||
Is it possible with subsearch to pass a list of search results to the outside search? similar to a SQL correlated sub... by Yancy Path Finder in Splunk Search 04-13-2010 3 3 | 3 | 3 | ||
Given a sequence of general to specific events (like product browsing a pages, followed by particular product pages)... by andynu Engager in Splunk Search 04-13-2010 2 2 | 2 | 2 | ||
I'm trying to map search performance to specific searches. I have to discover if its possible to marry up a job ID t... by Michael_Wilde Splunk Employee ![]() 2 8 | 2 | 8 | ||
The asterisk character is not matching all characters. A search for : rectype="bl*query" returns 0 matching event... by rsimmons Splunk Employee ![]() 10 5 | 10 | 5 | ||
In a dashboard we're working with we are displaying a table of events and the times always have 000 as the millisecon... by sideview SplunkTrust ![]() 1 1 | 1 | 1 | ||
Livetail was around in version 3.x and went away in 4.0. When is it coming back? by the_wolverine Champion in Splunk Search 04-13-2010 2 1 | 2 | 1 | ||
I'm running summary searches and the splunk-system-user keeps hitting a quota limit. 04-12-2010 16:50:28.436 ERR... by the_wolverine Champion in Splunk Search 04-13-2010 3 1 | 3 | 1 | ||
Hi folks Is there a way to manually migrate saved searches from splunk 3.x to 4.x? The problem is that I didn't upgr... 1 2 | 1 | 2 | ||
Hi All... i'll first describe my scenario.. i have logs that contains entries regarding open ports like: 1-1-2000 ... by aagmon New Member in Splunk Search 04-12-2010 0 2 | 0 | 2 | ||
I want to lock down a user to seeing only one app. I figured out how to set their default dashboard, but i want this... by bfaber Communicator in Dashboards & Visualizations 04-10-2010 2 1 | 2 | 1 | ||
Can I do a live search over multiple Splunk indexers? by bfaber Communicator in Splunk Search 04-10-2010 1 2 | 1 | 2 |
Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.