Splunk Search

Splunk Search
Community Activity
smcdonald20
We have moved a large portion of our scheduled searches from one search head to another. We did this by copying and p...
by smcdonald20 Path Finder in Splunk Search 03-05-2018
0 2
0
2
karthi25
I am having the splunk log in the following format: 2018-03-02T17:02:27.453185+00:00 ESP-Finance-NPE.development.ab...
by karthi25 Path Finder in Splunk Search 03-05-2018
0 2
0
2
ninisimonishvil
Hello I have an event that starts like this: 02-12-2018 17:07:33 Local7.Info 10.5.0.11 Feb 12 17:07...
by ninisimonishvil Path Finder in Splunk Search 03-05-2018
0 7
0
7
Hppjet
I have 3 fields that will contain the same user IDs and I would like to merge them into 1. They each have a sum valu...
by Hppjet Path Finder in Splunk Search 03-05-2018
0 6
0
6
soumyasaha25
i have a list of query strings (these are just strings not a field) (eg. Too many open files, CPU Starvation detected...
by soumyasaha25 Contributor in Splunk Search 03-05-2018
0 8
0
8
maheshsat
Hi , Could you please help me to use of abstract command for below event.What would be output for below command if us...
by maheshsat Explorer in Splunk Search 03-05-2018
0 2
0
2
steverimar
We're trying to export data out of a very large splunk index using the dump command into multiple csv files where the...
by steverimar Explorer in Splunk Search 03-05-2018
3 4
3
4
Jt0140223
F5 BIG-IP APMのログをSplunkで管理しようとしているのですが、テンプレートでの表示がうまくできません。 ログ自体はsyslogで送れているのですが、F5 Networks Remote Accessのダッシュボードを見...
by Jt0140223 New Member in Splunk Search 03-05-2018
0 1
0
1
arizviherjavec
Here's a sample Log: Mar 2 09:27:24 Blue_Firewall 1,2018/03/02 09:27:24,00546543517,THREAT,url,1,2018/03/02 09:27:1...
by arizviherjavec Explorer in Splunk Search 03-05-2018
0 1
0
1
splunkrocks2014
I have list of the domains and groups, how to use ldapsearch to pull the sAMAccountName name and AccountIsDisabled as...
by splunkrocks2014 Communicator in Splunk Search 03-05-2018
0 1
0
1
matansocher
Hi, I have a very big data set, and I want to return different fields from it, based on a value of another field (2 ...
by matansocher Contributor in Splunk Search 03-05-2018
1 4
1
4
vumanhtai
i use addcoltotals to the sum of colum and get the result 4.51235743409 how do i rounding of the result
by vumanhtai Path Finder in Splunk Search 03-05-2018
0 3
0
3
Hakima
Hi, I would like to create an application on splunk that would allow me to display an array of particular events but...
by Hakima Engager in Splunk Search 03-05-2018
0 3
0
3
mlb19
Hi Splunkers, I need to extract the name of the computer generating the log from the file name. I found a way to do ...
by mlb19 Explorer in Splunk Search 03-05-2018
0 3
0
3
ygdrassil
Hello, I got a field that has a format and a value like this "S01-3101" and sometimes a value like this "S01-301" i...
by ygdrassil Engager in Splunk Search 03-04-2018
0 3
0
3
Kirantcs
This is the query is used: index=perfmon* sourcetype=Perfmon:CPU counter="% Processor Time" | eval status=if(Value!=...
by Kirantcs Path Finder in Splunk Search 03-04-2018
1 11
1
11
murat89
Hi guys, im a beginner in Splunk and my issue is that I have Cisco logs and I need to find out the conference durat...
by murat89 New Member in Splunk Search 03-04-2018
0 5
0
5
orion44
I'm able to find all the previous day's events by hard coding in date ranges as such: where mytime > "2018-03-01" AN...
by orion44 Communicator in Splunk Search 03-04-2018
0 2
0
2
JeffBothel
I have a data store that information is far faster and more reach to get to with Splunk and I am trying to figure out...
by JeffBothel Explorer in Splunk Search 03-04-2018
0 1
0
1
peiffer
I have data that is extracted from log events by multiple neighbor pairs. I would like to extract deltas on an integ...
by peiffer Path Finder in Splunk Search 03-03-2018
0 2
0
2
maheshsat
I have field called test, what would be out if use assume command command: -- | accum test as test2 ( It wi...
by maheshsat Explorer in Splunk Search 03-03-2018
0 2
0
2
dflodstrom
After upgrading my lab to 6.3.0 the search heads are reporting this error when no index is explicitly supplied in the...
by dflodstrom Builder in Splunk Search 03-02-2018
2 7
2
7
himpor
hi, I had the data in the following format location product price location1 Product1 price...
by himpor Engager in Splunk Search 03-02-2018
0 3
0
3
splunkrocks2014
Hi. I have a query to generate the events with timestamp, "_time", from the original events and ingested to a summar...
by splunkrocks2014 Communicator in Splunk Search 03-02-2018
0 11
0
11
ssgtballard
I use the following search for proxy logs index=proxy src="10.10.10.10" | table _time,src, action, dest, status | ded...
by ssgtballard New Member in Splunk Search 03-02-2018
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...