I just verified in 4.3.1 that where is still a current and active search keyword. So "| where count > 4" should work for you. What results are you getting when you use just the where portion?
... View more
If I understand correctly, for each day of the week, you only care if an event is present or not. Then, you want to know if that event occurs over the course of 5 days, right? Try this:
source="/var/log/alerts_splunk.log" hostname="" (name="df." AND value>99) OR (name="*.var" AND value>95) | dedup date_wday hostname name | stats count by hostname name value | where count > 4 | sort value desc
... View more
The default search app has 2 dashboards which will tell you CPU utilization issues related to indexing and searching. They can be accessed by:
http:// :8000/en-US/app/search/search_detail_activity
http:// :8000/en-US/app/search/index_status
Also, what version of Splunk are you using? I had similar issues when I upgraded from 4.2 to 4.3. Then I upgraded to 4.3.1 and the problem went away.
... View more
If you paste your search directly into the splunk web interface, do you get the expected results? If so, have you tried running "splunk search" from the cmd line instead of "exporttool"? Do you get the same results as in the GUI?
... View more
What happens if you copy & paste your iframe link directly into your browser? If you have to "log in" (which you kind of imply at the end of your post) then your insecure login setup is wrong. There should be no login required with that link.
... View more
The only time I've run into this is when the application that generated the csv file had corrupt data coming in. Can you post a sample of your data?
If you're sure your dataset is clean, you may want to look at enabling SHOULD_LINEMERGE and then tweaking MUST_NOT_BREAK_BEFORE discussed here: http://docs.splunk.com/Documentation/Splunk/latest/Data/Indexmulti-lineevents.
... View more
Depending on your dataset, it shouldn't be that hard. Try something like this (modify the dates accordingly):
earliest=3/18/2012:0:0:0 latest=3/23/2012:0:0:0 | dedup date_wday | stats c by | where c > 4
If you want a relative timeframe, make earliest=-7d.
... View more