Splunk Search

Splunk Search
Community Activity
vrmandadi
I am using rex to split an existing field,can I use the same rex in IFX ? | rex field="External ID" "(?.*)_" I want...
by vrmandadi Builder in Splunk Search 03-08-2018
0 18
0
18
Jamesfirth
hi All, i have a 2008 r2 server that is a file share, i have setup a universal forwarder to send logs to splunk. Tha...
by Jamesfirth New Member in Splunk Search 03-08-2018
0 4
0
4
Simeon
I want to run searches against the Splunk API. How can I do this?
by Simeon Splunk Employee Splunk Employee in Splunk Search 03-08-2018
4 7
4
7
krusovice
Hi all, I've a request to come out with a table with information as below. My query so far is to extract the requir...
by krusovice Path Finder in Splunk Search 03-08-2018
0 3
0
3
johnward4
I'm trying to create a new field that is the result of the Current Date minus the time stamp when my events were crea...
by johnward4 Communicator in Splunk Search 03-08-2018
0 8
0
8
brajaram
I'm trying to add a single value to a table I use to dynamically populate a selector in a dashboard. The search I use...
by brajaram Communicator in Splunk Search 03-08-2018
0 4
0
4
flow2k
In searching, I understand that I can specify the time range using one of the presets (like "Last 4 hours") or set it...
by flow2k Explorer in Splunk Search 03-08-2018
0 1
0
1
afamoyib
Searches index=nix sourcetype=cpu host="host a" CPU="all" | eval Percent_CPU_Load = 100 - pctIdle | timechart limit...
by afamoyib Path Finder in Splunk Search 03-08-2018
0 3
0
3
wainwrid
Currently, we are running 6.6.2 and are using the geolite2 DB to do the iplocation mapping. I have read the followi...
by wainwrid Engager in Splunk Search 03-08-2018
0 1
0
1
ashishlal82
I extracted a field SNDateCreated (regex shown below), the values in this field are represented as strings. index="...
by ashishlal82 Explorer in Splunk Search 03-08-2018
0 1
0
1
ibob0304
This query capture the id from logs and make a search in the database, when there is a id value in logs it works well...
by ibob0304 Communicator in Splunk Search 03-08-2018
0 1
0
1
baf879
Hi everyone, On my Universal Forwarder, I'm able to effectively blacklist Windows event codes when I do it based on ...
by baf879 Path Finder in Splunk Search 03-08-2018
1 28
1
28
surekhasplunk
| rest /services/authentication/users splunk_server=local | search [| rest /services/authentication/current-context |...
by surekhasplunk Communicator in Splunk Search 03-08-2018
0 1
0
1
balbano
0
6
chhawu
How to find out the event with max duration? I used command transaction to group events and I want to find out the ev...
by chhawu New Member in Splunk Search 03-08-2018
0 5
0
5
pal_sumit1
Let suppose,In a list(owner_name) as owner_name we are having following values, shyam ram Shyam Shyam And we have to...
by pal_sumit1 Path Finder in Splunk Search 03-08-2018
0 4
0
4
iomega311
I have a .csv file with multiple columns. This is an auto-generated .csv file, and I only need to search against one ...
by iomega311 Explorer in Splunk Search 03-08-2018
0 2
0
2
chrisschum
I'm getting log data from a system that uses codes for each entry and I'd like to replace or add a description of the...
by chrisschum Path Finder in Splunk Search 03-08-2018
0 3
0
3
tatery
Hello, I need to prepare statistics of some events occurrences and this is my data in splunk: 07-03-18;11:55:14;id...
by tatery Engager in Splunk Search 03-08-2018
0 12
0
12
emichels
Is there something like a "sql database view" in splunk to hide the complexity of a search/report from the end user?
by emichels Loves-to-Learn in Splunk Search 03-08-2018
0 2
0
2
kmaron
I'm having issues trying to break out individual events that are combined into multi-value fields When I do a table ...
by kmaron Motivator in Splunk Search 03-08-2018
0 4
0
4
hettervik
Hi, I've encountered this problem a couple of times now. I have a dashboard where some of the panels run on a base ...
by hettervik Builder in Splunk Search 03-08-2018
6 7
6
7
dabany
How can I transfer data from splunk to syslog? I did not understand the explanation in the link: http://docs.splunk.c...
by dabany Engager in Splunk Search 03-08-2018
0 1
0
1
jwillaime
So, I have this search on events that cover from the 28th of February to the 6th of March, 2018: Some basic search...
by jwillaime Explorer in Splunk Search 03-07-2018
0 3
0
3
auaave
Hi, I want to create dashboard that displays the 4 weeks data by week number. The database normally have 3 months of...
by auaave Communicator in Splunk Search 03-07-2018
0 10
0
10
Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...