Splunk Search

Splunk Search
Community Activity
mjshoaf
I need help figuring out how to correctly dedup the data below. The 10 log messages below represent 4 distinct events...
by mjshoaf New Member in Splunk Search 03-20-2018
0 10
0
10
astarchenkov
This is a part of custom search command (EventingCommand) fro example. I get some input events and start jobs based ...
by astarchenkov Explorer in Splunk Search 03-20-2018
0 2
0
2
astarchenkov
I create search jobs from my customsearch command. How can I get user's (not role's) limits on searches? And is it po...
by astarchenkov Explorer in Splunk Search 03-20-2018
0 0
0
0
DataOrg
i want case command to match case where abc = hhh and after word should be same as present as it is abc abc efg ffh
by DataOrg Builder in Splunk Search 03-20-2018
0 7
0
7
ashish9433
Hi Team, I have a scheduled search which generates a lookup file similar to below Whenever i run stats command on...
by ashish9433 Communicator in Splunk Search 03-20-2018
0 8
0
8
nkankur
I have data as given below in table format A B C D E F 517 2498 186 1000 250 100 399 314 1559 100 100 1000 I want ea...
by nkankur Path Finder in Splunk Search 03-20-2018
0 2
0
2
atemourt
Hello, I have a csv file with data from 2010 until 2017. Splunk seems to parse the timestamp correctly for most of ...
by atemourt Engager in Splunk Search 03-20-2018
0 9
0
9
baburao123
Hello, I need to get a string which is available in the INFO statement whenever there is an Warning statement in the ...
by baburao123 New Member in Splunk Search 03-20-2018
0 4
0
4
patrick_cheung
I have the following data set with says 1000+ data: Time, Duration in hours, eg. 13:23 2018-2-3, 0.234 15:13 2018-3-1...
by patrick_cheung New Member in Splunk Search 03-19-2018
0 3
0
3
brajaram
I want to join events within the same sourcetype into a single event based on a logID field. However, this logID fiel...
by brajaram Communicator in Splunk Search 03-19-2018
0 2
0
2
sansay
I have been investigating excessively expensive searches by querying the audit log, and I came across one that has th...
by sansay Contributor in Splunk Search 03-19-2018
1 9
1
9
Pravinraju
index="inx_prod" host="pweb*" "session_id=4w344fbrz5th1pzfatvb0u3u" | table host, session_id | stats count by host, s...
by Pravinraju New Member in Splunk Search 03-19-2018
0 1
0
1
daniel333
All, A user just asked me this, any ideas on how to do this? Splunkj Q: is the following supported? I create an al...
by daniel333 Builder in Splunk Search 03-19-2018
1 4
1
4
dbcase
Hi, I have this query earliest =-30m index=relay_json host=betamax* relayPairId!="null" | transaction relayPairId s...
by dbcase Motivator in Splunk Search 03-19-2018
0 1
0
1
hatbeard
I have this query that i've lightly changed from the winfra app, but i want to add a PID into it, that would be in th...
by hatbeard Explorer in Splunk Search 03-19-2018
0 3
0
3
samlinsongguo
Currently I have a table generate by my query as below query: index=a | stats count by name code signature name ...
by samlinsongguo Communicator in Splunk Search 03-19-2018
0 10
0
10
bomran
I have some CSV data about files imported in to Splunk. The data looks like this: "\\domain\path\to\file\","<filenam...
by bomran Explorer in Splunk Search 03-19-2018
1 2
1
2
linwqg
Need help. How to I obtain the following output? I tried the following SPL but doesn't work. index=car_record | sear...
by linwqg New Member in Splunk Search 03-19-2018
0 6
0
6
linwqg
Hello. I new to regex and have been trying to understand how it works. Let say i have a log containing strings of i...
by linwqg New Member in Splunk Search 03-19-2018
0 5
0
5
Splunk_rocks
Hello Splunkers, I would like to calculate below EPS values for 30 days time period for each source type on one c...
by Splunk_rocks Path Finder in Splunk Search 03-19-2018
0 4
0
4
Splunk_rocks
I want to calculate the amount of change in between today's score and yesterdays. This is a file with a few days data...
by Splunk_rocks Path Finder in Splunk Search 03-19-2018
0 6
0
6
shreyasathavale
My 1st search: earliest=-2mon@mon latest=-1mon@mon index=linux (host=abc OR host=xyz) COMMAND=LMN|dedup host,PID|stat...
by shreyasathavale Communicator in Splunk Search 03-19-2018
0 6
0
6
pratibha2018
I want to merge events that are in between state=" STARTED" and state="COMPLETED" i.e. All the following events of st...
by pratibha2018 Explorer in Splunk Search 03-19-2018
0 9
0
9
anandhalagarasa
Hi Team, I got a scenario as below: index=* host=A or host=B Type=Info "Service down" In this i want the following...
by anandhalagarasa Path Finder in Splunk Search 03-19-2018
0 6
0
6
mihenn
Hello, I am searching for a possibility to build a multi-level piechart in Splunk. Does anyone knew if the is an bui...
by mihenn Path Finder in Splunk Search 03-19-2018
1 5
1
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...