Splunk Search

Splunk Search
Community Activity
jacqu3sy
Can anyone help with the following please. Im looking to run a tstats query against the Web Data Model but exclude re...
by jacqu3sy Path Finder in Splunk Search 02-20-2018
0 7
0
7
Hemnaath
Hi All, Need a small help in the regex, I am able to match the host name but unable to over write to the host field i...
by Hemnaath Motivator in Splunk Search 02-20-2018
0 13
0
13
auaave
Hi Guys, I have 10 locations with around 100 spaces each then every 10 mins a new message is sent to update the curr...
by auaave Communicator in Splunk Search 02-20-2018
0 5
0
5
Matinrokz
Hello There, I am trying to get an overall stats for all the logs with a particular sourcetype, however in some sour...
by Matinrokz New Member in Splunk Search 02-20-2018
0 10
0
10
stwong
Hi all, We're trying to combine 2 searches: Search 1: application transaction log ...| transaction connId | eval ...
by stwong Communicator in Splunk Search 02-20-2018
0 3
0
3
packland
Hi, I'm trying to create a search that calculates how long a device has been offline, with a maximum of two days. H...
by packland Path Finder in Splunk Search 02-19-2018
0 1
0
1
_smp_
I have events that whose fields like this: Name=[name1,name2,name3] Application=[app1,app2,app3] Splunk is auto-e...
by _smp_ Builder in Splunk Search 02-19-2018
0 3
0
3
JoshuaJohn
I have 5 fields of data I want in a stats table, some of these fields have more than 1 value inside and they all corr...
by JoshuaJohn Contributor in Splunk Search 02-19-2018
0 2
0
2
auaave
Hi Guys, I have 2 queries that I have to combine. I haven't done this before and I'm really struggling.  1st query:...
by auaave Communicator in Splunk Search 02-19-2018
0 11
0
11
subtrakt
Hi Everyone, Trying to get the expression to read first match from the end off the line and not the beginning of the...
by subtrakt Contributor in Splunk Search 02-19-2018
0 5
0
5
macadminrohit
Hi, I have a search that lists top 50 events based on the following search : index=servers sourcetype=json appName=...
by macadminrohit Contributor in Splunk Search 02-19-2018
0 1
0
1
codymoore
After installing the free version of Splunk on a standalone Windows 7 PC and configuring Splunk to monitor the window...
by codymoore New Member in Splunk Search 02-19-2018
0 1
0
1
dbcase
Hi , I have a query that looks like this earliest=-100hr index=blahalarm STATUS=readyArmed OR STATUS=ready OR STATU...
by dbcase Motivator in Splunk Search 02-19-2018
0 2
0
2
murhammr
i'm trying to do something similar to grep -f over multiple sourcetypes that i've appended together into one search. ...
by murhammr Path Finder in Splunk Search 02-19-2018
0 3
0
3
Valisha2005
Hello, I'm new to splunk. I would like to know how to join several sources and have the results stats displayed from ...
by Valisha2005 New Member in Splunk Search 02-19-2018
0 1
0
1
greggz
Im trying to perform a condition based on 2 varibles, but I can't seem to get right the expression. I've been trying ...
by greggz Communicator in Splunk Search 02-19-2018
0 7
0
7
kdimaria
I want to remove the table headers completely from my dashboard so I can just display values in a table with the head...
by kdimaria Communicator in Splunk Search 02-19-2018
0 30
0
30
joshnicholson99
While using fschange we would like to see usernames rather than uid's in splunk while searching the audit logs.
by joshnicholson99 New Member in Splunk Search 02-19-2018
0 0
0
0
maurelio79
Hi to all, i need to create a table for a multivalue event. Event is like: field1=value1, field2=value2, field3="val...
by maurelio79 Communicator in Splunk Search 02-19-2018
0 2
0
2
sahil237888
Hi All, Can you please help. I want to create a query whiich could : Calculate average of current events on server.
by sahil237888 Path Finder in Splunk Search 02-19-2018
0 11
0
11
premforsplunk
Hello Folks, part 1 - As far as i know,Splunk can match below users with same pattern "John%" , but all 6 are same u...
by premforsplunk Explorer in Splunk Search 02-19-2018
0 1
0
1
mjlsnombrado
index=sampleidx |stats count(eval(value="1")) as total1 How to do this using eval?
by mjlsnombrado Communicator in Splunk Search 02-18-2018
0 5
0
5
tkwaller_2
Hello I am tabling a bunch of data. In the table there is a field called Workflow Sort Order which orders the the da...
by tkwaller_2 Communicator in Splunk Search 02-18-2018
0 4
0
4
tkwaller_2
Hello Im trying to get the contents of a field What I am wanting is the date from a field called "Past Due Step Due D...
by tkwaller_2 Communicator in Splunk Search 02-18-2018
0 4
0
4
auaave
Hi guys, With my below query, how can I convert the value of %Empty and %Occupied to Percentage instead of decimal? ...
by auaave Communicator in Splunk Search 02-18-2018
0 6
0
6
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...