Splunk Search

Splunk Search
Community Activity
christopheryu
I have a field named "router" that has multiple values and have three sources. I would like to count the router value...
by christopheryu Communicator in Splunk Search 03-14-2018
0 5
0
5
nmohammed
My original search Query returns results- index="ver_logs" "ERORR detected" | rex field=source "VerLogs\\\(?.*?)\_...
by nmohammed Builder in Splunk Search 03-14-2018
0 11
0
11
matstap
I have a lookup table where one of the field columns is xml format. I'm trying to extract fields from the xml entries...
by matstap Communicator in Splunk Search 03-14-2018
0 4
0
4
Kendo213
I have a CSV that I've created via ldapsearch, that contains a single column with 'cn' and then a list of servers. I...
by Kendo213 Communicator in Splunk Search 03-14-2018
0 10
0
10
ReachDataScient
| makeresults | eval ipaddress=192.168.1.1 | lookup AM ipaddress OUTPUT hostname | table ipaddress,hostname This wor...
by ReachDataScient Explorer in Splunk Search 03-14-2018
0 7
0
7
Carolina
Hello, I need your help to correlation some transactions by a number of reference and responses Input and Output bu...
by Carolina Engager in Splunk Search 03-14-2018
0 1
0
1
gassershaun
Need to exclude the query parameters from a URL field. For e.g. the field contains http://www.google.com/india?searc...
by gassershaun Engager in Splunk Search 03-14-2018
0 4
0
4
ZigZaggin
Greetings All - I have a query that gives me the data I need. However when I tried to add a timechart function to b...
by ZigZaggin Explorer in Splunk Search 03-14-2018
0 18
0
18
dsnytkine
We have log entries in format like this: LogLevel=info username=some1 eventID=update So in case of error the LogL...
by dsnytkine Engager in Splunk Search 03-14-2018
0 7
0
7
taha13
Hello , So my question today is: for my earliest time i have "-1w@w1",so my research start from the last monday.The ...
by taha13 Explorer in Splunk Search 03-14-2018
0 7
0
7
Carolina
Hello, I need your help for the following: I need to add the Total row and then divide it by the column of funds. E...
by Carolina Engager in Splunk Search 03-14-2018
0 7
0
7
vemurisurya
I have a field called hostname,domain,ipaddress all my 5 sourcetypes are having same fieldname, I want to compare all...
by vemurisurya Path Finder in Splunk Search 03-14-2018
0 3
0
3
mawomommoh
I have multiple xml files which have been forwarded to Splunk from my machine. Each file has its own data which is us...
by mawomommoh Path Finder in Splunk Search 03-14-2018
0 4
0
4
Mike6960
I have events with a kind of chronological flow. The events contain a ID, status, _time and a time inside the event. ...
by Mike6960 Path Finder in Splunk Search 03-14-2018
0 10
0
10
SimonKof
Hi I have a dashboard which shows metrics for an API. It has a graph for response times, tables for min max average ...
by SimonKof New Member in Splunk Search 03-14-2018
0 2
0
2
PhenylVon
Hi All, I checked all the options in Splunk and I am unable to find an option for creating a user with a a role who ...
by PhenylVon New Member in Splunk Search 03-14-2018
0 1
0
1
carlyleadmin
hi below is my search, when I do search for Error this is what I get; then I run this search to create "Message" f...
by carlyleadmin Contributor in Splunk Search 03-14-2018
0 3
0
3
splunkt0n
Hi, Good day! have this search: | union [| pivot latest(field0) AS field0 SPLITROW field4 AS field4 | se...
by splunkt0n New Member in Splunk Search 03-14-2018
0 1
0
1
tchintam
|inputlookup |eval duration="xyz"|append[inputlookup |eval duration2="abc"]|eval dur3=duration-duration2| table dur ...
by tchintam Path Finder in Splunk Search 03-14-2018
0 4
0
4
markus007
Hi@all, i'm new a splunk and been trying to figure out this for a while now. But for me it is not possible to add a ...
by markus007 Engager in Splunk Search 03-14-2018
0 6
0
6
vumanhtai
i have a search in splunk search dest_ip=10.10.20.3 OR dest_ip=10.2.3.5 OR dest_ip=10.6.7.4 OR dest_ip=10.0.4.6 . I ...
by vumanhtai Path Finder in Splunk Search 03-14-2018
0 1
0
1
bluemarvel
the following produces all of the other stats except completion percentage sourcetype=access_combined | transaction ...
by bluemarvel Path Finder in Splunk Search 03-14-2018
0 3
0
3
FraserC1
Hi there, We are migrating from Kiwi syslog and one of the things Kiwi can do is show hostnames instead of IP addres...
by FraserC1 Path Finder in Splunk Search 03-14-2018
0 4
0
4
Lowell
I'm trying to figure out some discrepancies between the outputlookup search command and the action.populate_lookup sa...
by Lowell Super Champion in Splunk Search 03-14-2018
0 4
0
4
ndiphe13
I have a lot of RAW data with this format: date_time,serverA,down date_time,serverB,down date_time,serverA,down date_...
by ndiphe13 Engager in Splunk Search 03-13-2018
0 3
0
3
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...