I was trying to create a tag/eventtype/equivilent for a message length checksum in our logfiles and it seems eventtypes cannot have subsearches.
Log Entry: 20140815143255713732 R 0004 ,OK)
F...
...o do more changes / reboots of the Splunk indexers, that you don't need to worry about missing network event logs if you have to restart an indexer server / service - RSysLog will just keep doing i...
...hat I must not know what I need to know about it, if that's my best avenue.
The idea is that given an event:
Oct 26, 2032 src_ip=132.32.23.4 proto=udp
How can I find the very next event (o...
I'm parsing an MSSQL Error Log file, and it has several different eventtypes in the log. There are "Server" events, "Logon" events, "Backup" events, and so on and so forth.
Most of these are s...
I'm new to Splunk and trying to figure out how to find all events of type X that do NOT have an event of type Y within 1 minute (before or after) of them. I found http://answers.splunk.com/answers/1...
I have log items that have event messages but no IDs indicating that the log in and log out belong to the same session. However, obviously a log in will happen before a log out so on and so forth....
...ID and Logon Type.
For example in the below log's the EventCode is 4624 but the Logon Type is 3. I would like to be able to select EventCode=4624 and Logon_Type=(2|10). I've tried the below h...
Hi,
I've written a query (see original query below) which joins 3 different eventtypes to display A_events started during the selected date range. The A_events are selected using the t...
Splunk's command types page is missing a few functions, including accum. I would like to know if accum is a centralized streaming command, distributable streaming command, or none of the above. E...
I just want to know which filed name makes more sense to use for the segregation of the log type. for example, we have Linux and windows logs. for separation of the log types in the report or a...