Splunk Search

Splunk Search
Community Activity
leo_wang
Hi, I have done some test using small set of data in my lab. It looks like the time-based lookup work correct when t...
by leo_wang Path Finder in Splunk Search 04-12-2018
0 0
0
0
kiddsupreme
Hello again, So lets say I have a CSV file that looks like the following: node_code region_code SAN AMER...
by kiddsupreme Explorer in Splunk Search 04-12-2018
0 3
0
3
matt4321
I have a field that looks like the below. PM=Rodhouse,Logan (PM Build VZT-PM) PM=Allen,Jim (PM Run-PM) Basically br...
by matt4321 Explorer in Splunk Search 04-12-2018
0 3
0
3
nnips
Hi, I'm have trouble with multiple line in my logs and i have many information dont need in this logs. So I'm want ge...
by nnips Engager in Splunk Search 04-12-2018
0 1
0
1
sarvan7777
Here is a sample content from my application log. I wish to extract the fields "rib-rmq Status is STATE_ACTIVE. Lo...
by sarvan7777 New Member in Splunk Search 04-12-2018
0 5
0
5
leo_systex
Hi, As title. I have done some test using small set of data in my lab. It looks like the time-based lookup work corre...
by leo_systex Explorer in Splunk Search 04-12-2018
0 0
0
0
axelabs
How would I perform a Unix grep on a multi-line event? Ex.: _raw="one two three" _raw="tree bee eleven" I'd like ...
by axelabs Explorer in Splunk Search 04-12-2018
0 1
0
1
fvegdom
I have a search like this: |inputlookup CSV-Generic-GenCus-GenLBL-SensitiveDataKeyWords.csv | map [search index="*" ...
by fvegdom Path Finder in Splunk Search 04-12-2018
0 5
0
5
subtrakt
Hi everyone, I have a requirement to use mvcombine after stats. When I use mvcombine the sparkline stops working ...
by subtrakt Contributor in Splunk Search 04-12-2018
0 1
0
1
ddrillic
When running the following - | makeresults 1 | eval total=0 | eval server1=host1 | eval server2=host2 | eval ser...
by ddrillic Ultra Champion in Splunk Search 04-12-2018
0 18
0
18
aboese
I have an accelerated data model where all events contain a duration field (ReqTot). In addition, some events include...
by aboese New Member in Splunk Search 04-12-2018
0 3
0
3
carlyleadmin
Hi there, I know there is an answer related to my question but I don't understand it. I already have this sourcetyp...
by carlyleadmin Contributor in Splunk Search 04-12-2018
0 4
0
4
brdr
I have a lookup file that contain 4 fields (field1, field2, field3, field4) which contains an account number. Same ac...
by brdr Contributor in Splunk Search 04-12-2018
0 2
0
2
harshal94
When I run the following query , I am getting data for limited days. Eg. When I run this query for 1 month ,I didn't...
by harshal94 Engager in Splunk Search 04-12-2018
0 1
0
1
jtitus3
What am I doing wrong? * Account_Name=smithjt OR Account_Name=jonestt* |eval X1=case (Account_Name=="smithjt", "John ...
by jtitus3 Explorer in Splunk Search 04-12-2018
0 4
0
4
HealyManTech
Does anyone know if you do a rex and create a new field could you use that field for the eval commands? IE: | rex fi...
by HealyManTech Explorer in Splunk Search 04-12-2018
0 3
0
3
mgianola
I'd like to search dashboard views by user, which is stored in index=_internal. REST allows me to limit results using...
by mgianola Explorer in Splunk Search 04-12-2018
0 3
0
3
shrikant0507198
We want to integrate JIRA Server with Splunk cloud using REST API. Is it possible? If yes, please share documentatio...
by shrikant0507198 New Member in Splunk Search 04-12-2018
0 0
0
0
mhornste
Hi, I have several fields which should be summed up to one count. I tried the following but the field is not showing...
by mhornste Path Finder in Splunk Search 04-12-2018
0 2
0
2
mcohen13
I have two indexes: index 1 contains a list of domains and event_timestamp, index 2 contains a description for every ...
by mcohen13 Loves-to-Learn in Splunk Search 04-11-2018
0 5
0
5
prabhunesanket1
index=test host=rider2*58* APP=TEST | rex field=_raw "*CAR:(?\d+)*" | table CAR this is my query. But whenever i run...
by prabhunesanket1 New Member in Splunk Search 04-11-2018
0 2
0
2
tdunphy_
Hello, I have a splunk query that goes into our AWS bill and outputs totals for various AWS resources: index=prd_aw...
by tdunphy_ Explorer in Splunk Search 04-11-2018
0 9
0
9
hsharma20
Hi, I have data something like this: Events in splunk search are as follows 04:30 [timestamp] [text] ty...
by hsharma20 Engager in Splunk Search 04-11-2018
1 2
1
2
cardinalga
Hi, I'm trying to build a mechanism to pre-define a set of fields in my searches. The mechanism normally uses a macr...
by cardinalga Explorer in Splunk Search 04-11-2018
0 9
0
9
fotc1969
Hello, I'm having a really hard time pulling the status code from an HA proxy log using a rex command. there are a n...
by fotc1969 New Member in Splunk Search 04-11-2018
0 1
0
1
Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...