Thread Info | |||||
---|---|---|---|---|---|
Hi
I would like to have a way to find out whether hosts have stopped logging to our central log infrastructure or...
by
chris
Motivator
in
Splunk Search
03-17-2010
|
0
|
3
| |||
I am having trouble getting my head around the search required to graph multiple values from the same log event. It s...
by
Glenn
Builder
in
Splunk Search
03-18-2010
|
2
|
5
| |||
Our office has a specific TRANSACTION search we do frequently to track all events related to a particular user. The s...
by
Justin_Grant
Contributor
in
Splunk Search
03-15-2010
|
0
|
5
| |||
I'd like to provide a table where the event count for today and yesterday are displayed. For example, count by status...
by
hulahoop
Splunk Employee
in
Splunk Search
03-16-2010
|
0
|
2
| |||
I know that in general, regular expressions in Splunk use PCRE (or a modified PCRE for matching in props.conf source ...
by
gkanapathy
Splunk Employee
in
Splunk Search
03-03-2010
|
3
|
1
| |||
I would like to use a lookup into an external database to add fields to my events, but need some advice about perform...
by
Justin_Grant
Contributor
in
Splunk Search
03-13-2010
|
2
|
3
| |||
On the Search App > Status > Index activity dashboard, there is an Index health report showing the bucket spread over...
by
hulahoop
Splunk Employee
in
Splunk Search
03-13-2010
|
1
|
1
| |||
I'm trying to throw out search results from a couple of different ip ranges. Currently I'm working with 2, but I migh...
by
thepocketwade
Path Finder
in
Splunk Search
03-12-2010
|
3
|
4
| |||
It is a subtlety of the search language that keyword searches run against the raw event data only. To search metadata...
by
hulahoop
Splunk Employee
in
Splunk Search
03-09-2010
|
1
|
2
| |||
I'd like to limit certain users from running expensive searches by limiting the number of results that can be returne...
by
the_wolverine
Champion
in
Splunk Search
03-09-2010
|
2
|
1
| |||
How do I change the default granularity on a chart? It appears I'm hitting a limit somewhere and I'm not getting as m...
by
dskillman
Splunk Employee
in
Splunk Search
03-03-2010
|
5
|
2
| |||
While I browse my local drive in Explorer I would like to add and search some log files with Splunk without opening a...
by
Leo
Splunk Employee
in
Splunk Search
03-03-2010
|
1
|
1
| |||
There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a spl...
by
matt_1
Explorer
in
Splunk Search
02-25-2010
|
2
|
1
| |||
Does maxresults in limits.conf have an effect when piping results to the stats command? For example, if I run a searc...
by
kbecker
Communicator
in
Splunk Search
02-26-2010
|
2
|
1
| |||
I have millions of events being indexed by Splunk now and I suspect something is happening within my IT environment a...
by
maverick
Splunk Employee
in
Splunk Search
02-24-2010
|
1
|
1
| |||
Hi Splunkers,
I have a sample Perforce log file and I'm trying to extract the code contributors. Here is an exampl...
by
Nicholas_Key
Splunk Employee
in
Splunk Search
02-22-2010
|
2
|
2
| |||
How do i use the same search strings in splunks UI on the command line?
by
Chris_R_
Splunk Employee
in
Splunk Search
02-17-2010
|
0
|
4
| |||
There are plenty of ways to specify the exact time range or maximum range between two events in a search. But I need ...
by
Tisiphone
Engager
in
Splunk Search
02-18-2010
|
3
|
1
| |||
explain the significance of the connected flag in transaction
by
Ledion_Bitincka
Splunk Employee
in
Splunk Search
02-11-2010
|
2
|
1
| |||
Dan Goldburt asks: I'm consistently getting the following request from customers: "can I see where each event came fr...
by
Ledion_Bitincka
Splunk Employee
in
Splunk Search
02-11-2010
|
1
|
1
| |||
Such a helpful command, and yet doesn't work for me...
by
V_at_Splunk
Splunk Employee
in
Splunk Search
01-17-2010
|
1
|
3
| |||
When I run this search -
source="*conn.log" | rex field=_raw "\.IP = '(?<connectionIp>[^']+)" | fields host, conne...
by
Mick
Splunk Employee
in
Splunk Search
02-05-2010
|
4
|
1
| |||
We are attempting to create a report that compares message traffic for the past two complete weeks.
We have this ...
by
Mick
Splunk Employee
in
Splunk Search
02-04-2010
|
0
|
2
| |||
Any recommended best practices for managing eventtypes and their corresponding tags?
I've found the Splunk Common ...
by
Yancy
Path Finder
in
Splunk Search
02-02-2010
|
0
|
2
| |||
What is wrong with this regex?
(?P<AUTH_PIN_TYPE>[^ ]+)( [^ ]+){2}$
The interactive field extractor gives this...
by
dinh
Path Finder
in
Splunk Search
01-30-2010
|
0
|
5
|