Using Splunk

Using Splunk
Category Activity
Ayn
I have a number of hosts that have a certain tag on them (let's say "sensitive"). I want to look for account lockout ...
by Legend in Splunk Search 04-13-2010
1 2
1
2
Yancy
Is it possible with subsearch to pass a list of search results to the outside search? similar to a SQL correlated sub...
by Yancy Path Finder in Splunk Search 04-13-2010
3 3
3
3
andynu
Given a sequence of general to specific events (like product browsing a pages, followed by particular product pages)...
by andynu Engager in Splunk Search 04-13-2010
2 2
2
2
Michael_Wilde
I'm trying to map search performance to specific searches. I have to discover if its possible to marry up a job ID t...
by Michael_Wilde Splunk Employee Splunk Employee in Splunk Search 04-13-2010
2 8
2
8
rsimmons
The asterisk character is not matching all characters. A search for : rectype="bl*query" returns 0 matching event...
by rsimmons Splunk Employee Splunk Employee in Splunk Search 04-13-2010
10 5
10
5
sideview
In a dashboard we're working with we are displaying a table of events and the times always have 000 as the millisecon...
by SplunkTrust SplunkTrust in Splunk Search 04-13-2010
1 1
1
1
the_wolverine
Livetail was around in version 3.x and went away in 4.0. When is it coming back?
by the_wolverine Champion in Splunk Search 04-13-2010
2 1
2
1
the_wolverine
I'm running summary searches and the splunk-system-user keeps hitting a quota limit. 04-12-2010 16:50:28.436 ERR...
by the_wolverine Champion in Splunk Search 04-13-2010
3 1
3
1
Simon
Hi folks Is there a way to manually migrate saved searches from splunk 3.x to 4.x? The problem is that I didn't upgr...
by Simon Contributor in Reporting 04-13-2010
1 2
1
2
aagmon
Hi All... i'll first describe my scenario.. i have logs that contains entries regarding open ports like: 1-1-2000 ...
by aagmon New Member in Splunk Search 04-12-2010
0 2
0
2
bfaber
I want to lock down a user to seeing only one app. I figured out how to set their default dashboard, but i want this...
by bfaber Communicator in Dashboards & Visualizations 04-10-2010
2 1
2
1
bfaber
Can I do a live search over multiple Splunk indexers?
by bfaber Communicator in Splunk Search 04-10-2010
1 2
1
2
davesplunkmonky
If there are no results found when a dashboard is rendered instead of having a "NO RESULTS FOUND" message in the dash...
by davesplunkmonky Splunk Employee Splunk Employee in Dashboards & Visualizations 04-09-2010
2 1
2
1
Justin_Grant
My search returns 10 fields in each event and I want to create a table with one row per event and columns for 3 of th...
by Justin_Grant Contributor in Splunk Search 04-09-2010
0 6
0
6
davesplunkmonky
instead of /var/run/splunk? I would like to stay away from having to point to or move the file in a script.
by davesplunkmonky Splunk Employee Splunk Employee in Reporting 04-09-2010
2 1
2
1
jpdubose
Hi! I posted this in the Splunk Forums the other day but I stumbled on Answers this morning and it seems like it m...
by jpdubose Explorer in Reporting 04-08-2010
1 5
1
5
Hazel
Hi, We get many alerts sent to us about cpu health under the email heading SERVER HEALTH ALERT - followed by tags. ...
by Hazel Communicator in Alerting 04-08-2010
0 4
0
4
rayfoo
Wanted to see what is/are the possible methods to do so. One way I could think of is to export the results using out...
by rayfoo Path Finder in Splunk Search 04-08-2010
1 7
1
7
MHS
I use the following query against a Cisco as5400 to find the number of calls per hour during a day. 10.200.90.19 Cal...
by MHS Explorer in Splunk Search 04-08-2010
0 4
0
4
imrago
After upgrading to 4.1 from 4.0.10 I am unable to get fields using a search from python script. The simplified versio...
by imrago Contributor in Splunk Search 04-08-2010
0 2
0
2
zscgeek
I am trying to get scripted auth working on the new 4.1. I had a configuration on 3.4.x that worked great but after m...
by zscgeek Path Finder in Splunk Search 04-07-2010
0 2
0
2
Justin_Grant
What are the searches required to search across Windows Event Logs for: most recent events of a particular event ID ...
by Justin_Grant Contributor in Splunk Search 04-07-2010
2 1
2
1
the_wolverine
Splunk does such an awesome job with distributed search. It seems like all my data is on one server (my search head)...
by the_wolverine Champion in Splunk Search 04-07-2010
1 2
1
2
BunnyHop
When I run a search on my custom dashboard, I get a notification bar on top stating the status of the dashboard queri...
by BunnyHop Contributor in Dashboards & Visualizations 04-06-2010
2 6
2
6
Alan_Bradley
After upgrading to Splunk 4.1 from 4.0.10 today, we find that we can no longer run searches. splunkd.log shows: 04-...
by Alan_Bradley Path Finder in Splunk Search 04-05-2010
4 1
4
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...
Top Karma Authors