Splunk Search

Splunk Search
Community Activity
sureshchinta
I have three log transactions containing following extracted fields - all joined together by a common transaction id ...
by sureshchinta Explorer in Splunk Search 04-24-2018
0 3
0
3
albinortiz
I have an output that looks like this: AV_DATE=Jan-1-2018 I want to be able to just display the date as so: Jan-1-20...
by albinortiz Engager in Splunk Search 04-24-2018
0 1
0
1
rileyken
my index has events from many hosts. The hosts names contain information about what environment the host is part of. ...
by rileyken Explorer in Splunk Search 04-24-2018
0 6
0
6
teresachila
I am using the multireport command to help manage some external lookup and caching. When I use one multireport comman...
by teresachila Path Finder in Splunk Search 04-24-2018
0 0
0
0
Rocky31
index=XXX sourcetype="XXX-log" opName="LoginUser"    earliest=-60m latest=now()   | bucket _time span=10m | timechar...
by Rocky31 Path Finder in Splunk Search 04-24-2018
0 2
0
2
sawgata12345
I have similar json input as below, every minute similar blocks of data is send to index. I am plotting timechart bu...
by sawgata12345 Path Finder in Splunk Search 04-24-2018
0 5
0
5
fzfeng
hello I have tow problems 1 I export my search result to csv file but when I open it the time just display...
by fzfeng New Member in Splunk Search 04-24-2018
0 3
0
3
fzfeng
hello I export my search result to csv file but when I open it the time just display like this 1.52E+09 ...
by fzfeng New Member in Splunk Search 04-24-2018
0 6
0
6
abhishekroy168
Hi all, I am almost near to my requirement and there is just one issue that I am facing. I am having 2 columns from a...
by abhishekroy168 Path Finder in Splunk Search 04-24-2018
0 1
0
1
santosh_sshanbh
I have a dbinput configured to pull data from SQL table on a daily basis. So I am getting few events each day in a in...
by santosh_sshanbh Path Finder in Splunk Search 04-23-2018
0 4
0
4
lawzuns
field="URL1 OR URL2 OR URL3" I need to search each URL in . If the search is returns values, count >0 then it's Pass...
by lawzuns Explorer in Splunk Search 04-23-2018
0 10
0
10
bseifert14
I have a series of tests that are performed at random times throughout the week. There are a total of 12 events. Ea...
by bseifert14 Engager in Splunk Search 04-23-2018
0 1
0
1
pushpender07
The logging that we do is not perfect hence need some help. Log 1 (request) - {"date":"19-04-2018 21:40:11,221", "t...
by pushpender07 Explorer in Splunk Search 04-23-2018
0 7
0
7
mikehage
Hi, Hope someone can help me with creating a regular expression for an extraction. I have a log file and the lines d...
by mikehage New Member in Splunk Search 04-23-2018
0 6
0
6
harishalipaka
Hi all, I want max value by row wise not max (field name) **Date** **shiftA** **shiftB** **shiftC*...
by harishalipaka Motivator in Splunk Search 04-23-2018
1 8
1
8
summitsplunk
If I wanted everything with a .wav extension returned how would I format this? index="myindex" AttCnt=* AttNames=* A...
by summitsplunk Communicator in Splunk Search 04-23-2018
0 10
0
10
harry2007gsp
How can I use same search for 2 different lookup? For ex: lookup_qa.csv and lookup_prod.csv. I wanna use them in sear...
by harry2007gsp Path Finder in Splunk Search 04-23-2018
0 8
0
8
Tom_Oliveri
Here is a sample section of the XML Data I am attempting to sum: <Product> <ProductItem>1</ProductItem> ...
by Tom_Oliveri New Member in Splunk Search 04-23-2018
0 4
0
4
axelabs
When I use replace to update a field, it is updated properly (in the interesting fields sidebar) but my search displa...
by axelabs Explorer in Splunk Search 04-23-2018
0 3
0
3
Splunk_rocks
Hello Splunkers, I have case field with below information so i need to construct Eval field. case** XYZ 2 0 3 yzr...
by Splunk_rocks Path Finder in Splunk Search 04-23-2018
0 5
0
5
brdr
Hello, can you use a output lookup table just after creating it? I have this search... index=indexA sourcetype=mystA...
by brdr Contributor in Splunk Search 04-23-2018
0 3
0
3
adonio
Hello Splunkers, battling with this all morning and seeking your assistance. i have a CSV data set from a car worksho...
by adonio Ultra Champion in Splunk Search 04-23-2018
0 2
0
2
cmisztur
below example sums the duration when a machine is not running. ... | sort 0 - time | transaction startswi...
by cmisztur Explorer in Splunk Search 04-23-2018
0 5
0
5
nottheboss
Hi, I currently have 2 log. log 1 id, some data 1, "abc" 2, "def" log 2 id, some other data 1, "abc" 3, "ghi" wha...
by nottheboss Engager in Splunk Search 04-23-2018
0 1
0
1
sjafferali
I am trying to convert a string to numeric but it is not getting converted. index="dnr_ecc" jobname="*IC*HV_TREX" | ...
by sjafferali Explorer in Splunk Search 04-23-2018
0 16
0
16
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...