<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need a help with Query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710278#M239968</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276015"&gt;@SR&lt;/a&gt;&amp;nbsp;.. may i know if you get results for the first search.. if no, pls understand that Application= may be service= or something else(depends on your logs).&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your search fails, then pls check the search below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;do you get results for 
index="Nex" Application="Pe***g.Ne**s.Platform.Host"

OR the better do this search
index="Nex" "Pe***g.Ne**s.Platform.Host"&lt;/LI-CODE&gt;&lt;P&gt;maybe pls send me a direct msg here in my profile, i can try to help you further. thanks.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 16:19:21 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2025-01-30T16:19:21Z</dc:date>
    <item>
      <title>Need a help with Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710251#M239962</link>
      <description>&lt;P&gt;Below was the question for me&lt;BR /&gt;"I need a running report to be exported, with the number of errors on each of the services in the last 7 days then it has to show a graph for each week"&lt;BR /&gt;&lt;BR /&gt;i would need a query to search for this Serivce&amp;nbsp;"Per****ng.N**s.Platform.Host"&lt;BR /&gt;Index="Nex"&lt;BR /&gt;where i would need data for Information, Error, Debug, Warnings.&lt;BR /&gt;&lt;BR /&gt;Please help me with this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 10:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710251#M239962</guid>
      <dc:creator>SR</dc:creator>
      <dc:date>2025-01-30T10:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710252#M239963</link>
      <description>&lt;P&gt;What have you tried so far?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 10:20:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710252#M239963</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-30T10:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710253#M239964</link>
      <description>&lt;P&gt;Apologies i am pretty New to Splunk&amp;nbsp; and i still learning and going through tutorials&lt;BR /&gt;just got till the below but no results yet&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Index="Nex"&amp;nbsp;Application="Pe***g.Ne**s.Platform.Host"| Search&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 10:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710253#M239964</guid>
      <dc:creator>SR</dc:creator>
      <dc:date>2025-01-30T10:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710257#M239965</link>
      <description>&lt;P&gt;Asterisks are wild cards - are you really using wildcards or are you just obfuscating your search for the purposes of posting here?&lt;/P&gt;&lt;P&gt;It would also be very helpful if you could share some sample raw events, anonymised appropriately; please share them in a code block using the &amp;lt;/&amp;gt; button to create an area to place them in so that formatting is preserved&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 10:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710257#M239965</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-30T10:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710278#M239968</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276015"&gt;@SR&lt;/a&gt;&amp;nbsp;.. may i know if you get results for the first search.. if no, pls understand that Application= may be service= or something else(depends on your logs).&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your search fails, then pls check the search below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;do you get results for 
index="Nex" Application="Pe***g.Ne**s.Platform.Host"

OR the better do this search
index="Nex" "Pe***g.Ne**s.Platform.Host"&lt;/LI-CODE&gt;&lt;P&gt;maybe pls send me a direct msg here in my profile, i can try to help you further. thanks.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 16:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-help-with-Query/m-p/710278#M239968</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2025-01-30T16:19:21Z</dc:date>
    </item>
  </channel>
</rss>

