Splunk Search

Splunk Search
Community Activity
prabhunesanket1
index=test host=rider2*58* APP=TEST | rex field=_raw "*CAR:(?\d+)*" | table CAR this is my query. But whenever i run...
by prabhunesanket1 New Member in Splunk Search 04-11-2018
0 2
0
2
tdunphy_
Hello, I have a splunk query that goes into our AWS bill and outputs totals for various AWS resources: index=prd_aw...
by tdunphy_ Explorer in Splunk Search 04-11-2018
0 9
0
9
hsharma20
Hi, I have data something like this: Events in splunk search are as follows 04:30 [timestamp] [text] ty...
by hsharma20 Engager in Splunk Search 04-11-2018
1 2
1
2
cardinalga
Hi, I'm trying to build a mechanism to pre-define a set of fields in my searches. The mechanism normally uses a macr...
by cardinalga Explorer in Splunk Search 04-11-2018
0 9
0
9
fotc1969
Hello, I'm having a really hard time pulling the status code from an HA proxy log using a rex command. there are a n...
by fotc1969 New Member in Splunk Search 04-11-2018
0 1
0
1
robmoser
Hi Folks, I'm fairly brand new to splunk, and trying to build a transaction out of cisco ASA data. My search looks ...
by robmoser Explorer in Splunk Search 04-11-2018
0 5
0
5
rkassabov
I have the following query that looks at data from all-time (according to Splunk date window). My understanding is th...
by rkassabov Path Finder in Splunk Search 04-11-2018
0 2
0
2
dbcase
Hi, I have a lookup table that is just a list of MAC addresses. I need to be able to search a data set that has mac...
by dbcase Motivator in Splunk Search 04-11-2018
0 10
0
10
abilis
hi, can someone help me to complete the search to get the average of a count ?? we have a file that has the logins ...
by abilis Explorer in Splunk Search 04-11-2018
0 6
0
6
soumyajk
Hi, I am new in splunk and i want to save the value in fields before and after = for example events look like belo...
by soumyajk Engager in Splunk Search 04-11-2018
0 1
0
1
samwatson45
I have a single dataset which contains a couple of variables which are time (date) based. The format for all of them ...
by samwatson45 Path Finder in Splunk Search 04-11-2018
0 7
0
7
skhedim
Hello, I want to calculate a score based on a field (severity) containing different values (High, Medium, Low). This...
by skhedim Explorer in Splunk Search 04-11-2018
0 2
0
2
prysmuser
I'm trying to plot a timechart with below data. Empty Graph is displayed on the correct X-axis and Y-axis but values ...
by prysmuser New Member in Splunk Search 04-11-2018
0 3
0
3
Chandras11
Hi Team, I want to create a new field REGION_ID With following requrirements:- If (TKT_CREATOR ="IP-Z" OR "DEP-IP-Z")...
by Chandras11 Communicator in Splunk Search 04-11-2018
0 4
0
4
samwatson45
Hi, I am currently trying to write a search which will accurately measure how long it takes for a customer to log i...
by samwatson45 Path Finder in Splunk Search 04-11-2018
0 2
0
2
JyotiP
Completed executing query test_proc_SelectLatest_PricesBySecurity which took 1 milliseconds. Completed executing quer...
by JyotiP Path Finder in Splunk Search 04-11-2018
0 2
0
2
shayhibah
Hi, I have some logs that contain table data inside - which means there are multiple fields with the same key name. ...
by shayhibah Path Finder in Splunk Search 04-11-2018
0 4
0
4
faustf
Hi guys, I have a nodejs service that needs to perform number of sequential queries: e.g: search mysearch from 01/0...
by faustf Communicator in Splunk Search 04-11-2018
0 2
0
2
asabatini85
Hi Everyone, Is there a metric Search to define how many times load balanced forwarders switch indexers? Thank you.
by asabatini85 Path Finder in Splunk Search 04-11-2018
0 1
0
1
buraka
I am trying to customize charts, from default numeric.Only documentation I found was one for older versions http://do...
by buraka New Member in Splunk Search 04-10-2018
0 4
0
4
furkan_caliskan
Hi, I'm currently searching for a method that will help me alerting anomalies in historial event logs. Let's say; i...
by furkan_caliskan New Member in Splunk Search 04-10-2018
0 5
0
5
evinasco
Hi Team, I have the next source list indexed in Splunk I need to let in only the last source by each factory owne...
by evinasco Communicator in Splunk Search 04-10-2018
0 3
0
3
gearmana
I'm not sure if the title is clear, so hopefully this helps. I've got a dashboard with a search: host=hostname cs_u...
by gearmana Explorer in Splunk Search 04-10-2018
0 7
0
7
jwalzerpitt
I have an index that contains two fields, sig_names and sig_ids, that can contain multiple values for each. I'd like ...
by jwalzerpitt Influencer in Splunk Search 04-10-2018
1 4
1
4
matt4321
I have data in the following format. Value should be in Gb MemoryCount=64 I have a few values that were improperly ...
by matt4321 Explorer in Splunk Search 04-10-2018
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...