splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

Discussion Forum (68)

Discussions Replies Latest Activity
Michael Wilde

The "I suck at regex" class at Splunk User conference

I'm planning on doing a really fun regex class during Splunk's user conference.... the premise is: In this class, we'll make one of the mos…

Started by Michael Wilde in Cool Search Commands

1 Jul 26
Reply by Mark Sleeper
Adam Peterson

Forwarding setup

I am a real Splunk newbie, and trying to figure out forwarding.I've installed splunk on server1 and server2.  Server1 is my main server, an…

Started by Adam Peterson in Cool Search Commands

1 Jul 26
Reply by Mark Sleeper
Patrick Swackhammer

How do I migrate custom field extractions to my new Splunk server?

I just migrated all my warm buckets over to our new Splunk server (CentOS) from Windows. I have quite a few custom field extractions that I…

Started by Patrick Swackhammer in General Questions

1 Jul 20
Reply by Patrick Swackhammer
Agus Budi Harto

Splunk Monitoring not Working

Can anybody help me?   I am currently using Splunk 4.1.3 and install Splunk Monitoring as per installation instruction. But, in the Splunk…

Started by Agus Budi Harto in Help

1 Jul 9
Reply by Andi Susanto
Joe Rizzo

sum fields in same event

I need to sum fields by other fields in the same event. Here is an example event: _time                                somefieldname   some…

Started by Joe Rizzo in Cool Search Commands

2 Jun 30
Reply by Joe Rizzo
Blaine Morgan

Synthesizing sistats in search results

I have a service that drops a stats line every minute on every host on 20+ hosts.  If I use sistats I lose information on the true count of…

Started by Blaine Morgan in Cool Search Commands

0 Jun 22
Michael Wegener

How to Configure timestamps for events with multiple timestamps

I followed the directions for configuring custom timestamps for events with multiple timestamps but I am not getting the result I am lookin…

Started by Michael Wegener in Help

2 Jun 21
Reply by Michael Wilde
Hagar

Event aggregation

Event aggregation Is there any way to create event aggregation in splunk ? what happened is I got license violations do to Windows securi…

Started by Hagar in Features Needed

0 Apr 20
Alon Agmon

Comparing events from 2 dates to detect new events

Hi,were using NMAP via scripted input to track live hosts on the networkim getting events formated using sed like:Fri Apr 9 16:11:50 IDT 20…

Started by Alon Agmon in Cool Search Commands

0 Apr 10
Marcelo Finkielsztein

Encountered the following error while trying to update: In handler 'savedsearch': Argument "action.summary_index." is not supported by this handler

Hi, While trying to save a very simple search I ran into this: Encountered the following error while trying to update: In handler 'savedsea…

Started by Marcelo Finkielsztein in Cool Search Commands

1 Apr 8
Reply by Marcelo Finkielsztein

RSS

© 2010   Created by Michael Wilde.   Powered by .

Badges  |  Report an Issue  |  Terms of Service

Sign in to chat!