I was trying to create a tag/eventtype/equivilent for a message length checksum in our logfiles and it seems eventtypes cannot have subsearches.
Log Entry: 20140815143255713732 R 0004 ,OK)
F...
I'm new to Splunk and trying to figure out how to find all events of type X that do NOT have an event of type Y within 1 minute (before or after) of them. I found http://answers.splunk.com/answers/1...
...o do more changes / reboots of the Splunk indexers, that you don't need to worry about missing network event logs if you have to restart an indexer server / service - RSysLog will just keep doing i...
...hat I must not know what I need to know about it, if that's my best avenue.
The idea is that given an event:
Oct 26, 2032 src_ip=132.32.23.4 proto=udp
How can I find the very next event (o...
I'm parsing an MSSQL Error Log file, and it has several different eventtypes in the log. There are "Server" events, "Logon" events, "Backup" events, and so on and so forth.
Most of these are s...
Need help on getting rex query. I am getting below two events. I am able to rex for event 1 with NULL field. But I also need to capture the sample event 2 which does not have NULL value. I...
I just want to know which filed name makes more sense to use for the segregation of the log type. for example, we have Linux and windows logs. for separation of the log types in the report or a...
Hello everyone,
Have you ever wondered why microsoft does not documented Operation types with Unicode + meaning?
You don´t need to anymore.
I have made the needed research (anyone can do) and h...
I have log items that have event messages but no IDs indicating that the log in and log out belong to the same session. However, obviously a log in will happen before a log out so on and so forth....