Using Splunk

Using Splunk
Category Activity
matt
I've got an application that logs status events. The values in these events generally will not change. Is there a s...
by matt Splunk Employee Splunk Employee in Splunk Search 01-27-2010
1 1
1
1
dinh
What is wrong with the way I'm using eval here? source="/some.audit.log" "End" "/foo/baz" | rex field=_raw "(?P<ReqI...
by dinh Path Finder in Splunk Search 01-27-2010
0 5
0
5
benstraw
I have a report on my dashboard that takes a very long time to build, how can I use summary indexing to improve the p...
by benstraw Splunk Employee Splunk Employee in Dashboards & Visualizations 01-25-2010
0 3
0
3
Johnvey
Sometimes I come across an event in my index that I'd like to refer to later, either as part of an investigation or t...
by Johnvey Contributor in Splunk Search 01-25-2010
1 3
1
3
Mick
I have a saved seach setup to check every minute for file changes. I have the start time set for [-1m] to search bac...
by Mick Splunk Employee Splunk Employee in Splunk Search 01-22-2010
2 1
2
1
Justin_Grant
I have a log which often has redundant events, where "redundant" is defined as 2+ events, on subsequent lines, where ...
by Justin_Grant Contributor in Splunk Search 01-22-2010
0 2
0
2
Mick
I need to understand how adding fields to raw data will increase our index size growth. We are in the process of addi...
by Mick Splunk Employee Splunk Employee in Splunk Search 01-21-2010
2 1
2
1
matt
I need to share all of the field extractions in my app with all of the other apps on the system. What is the most ef...
by matt Splunk Employee Splunk Employee in Splunk Search 01-21-2010
2 5
2
5
matt
$SPLUNK_HOME/var/lib/splunk/defaultdb/db/Sources.data On a fresh install I see this file has something like this: ...
by matt Splunk Employee Splunk Employee in Splunk Search 01-21-2010
1 2
1
2
benstraw
I set up an alert action to create an rss feed and there is an rss link in the table view of all of my saved searches...
by benstraw Splunk Employee Splunk Employee in Reporting 01-20-2010
2 1
2
1
Justin_Grant
[UPDATE: from the answer below, it sounds like what I'm looking for is not supported in the product today. I'm tackin...
by Justin_Grant Contributor in Splunk Search 01-20-2010
18 2
18
2
jrodman
I wrote a search operator that takes actions external to splunk. It has to take an action to 'complete' its operatio...
by jrodman Splunk Employee Splunk Employee in Splunk Search 01-15-2010
2 2
2
2
Johnvey
I am using Splunk 4 and the email alerts that are sent to me have a bunch on junk in the 'To' and 'From' lines, like:...
by Johnvey Contributor in Alerting 01-14-2010
2 1
2
1
V_at_Splunk
Because wc -l of the input doesn't match my event count, and I'm trying to troubleshoot.
by V_at_Splunk Splunk Employee Splunk Employee in Splunk Search 01-14-2010
1 2
1
2
tpaulsen
In discussions, Johnvey has suggested to use the SingleValue module to display the output of the results. In fact, wi...
by tpaulsen Contributor in Dashboards & Visualizations 11-04-2009
4 2
4
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Karma Authors