Splunk Search

Splunk Search
Community Activity
dbcase
Hi, I have this query. If I change fieldformat to eval the query works but if it is left as fieldformat the query r...
by dbcase Motivator in Splunk Search 02-01-2018
0 3
0
3
rob3770
index=ABC source="ABC" ServiceName=ABC | stats distinct_count(CorrelationId) as TotalA | appendcols [search "T...
by rob3770 Explorer in Splunk Search 02-01-2018
0 7
0
7
mbeauchamp
Trying to search web access logs to find instances where a specific IP only called a single URL, and no other URLs. ...
by mbeauchamp Engager in Splunk Search 02-01-2018
0 3
0
3
crisjnelson
I have a set of field values 101,102,103,104,105 Here are sample log events datetime, val=101 datetime, val=105 dat...
by crisjnelson Explorer in Splunk Search 02-01-2018
0 2
0
2
swinte12
I have several indexes in my Splunk Instance. One of these instances is merging some of my log events into a single e...
by swinte12 New Member in Splunk Search 02-01-2018
0 2
0
2
cdgill
Here is my search query: index=jenkins* job_name="jenkins-representative-jobs_github_organization/math_utilities/ma...
by cdgill Explorer in Splunk Search 02-01-2018
0 8
0
8
jwalzerpitt
I have the following search: index="foo" EventCode=* | lookup windows_signatures.csv signature_id AS EventCode OUTPU...
by jwalzerpitt Influencer in Splunk Search 02-01-2018
1 3
1
3
shargrave
I have created a nice stacked timechart that I would like to see the Totals of in the table under the chart. The add...
by shargrave Engager in Splunk Search 02-01-2018
0 2
0
2
EricLloyd79
Hello, we currently have two virtual indexes with data in them retrieving data from Hadoop Distributed File System. W...
by EricLloyd79 Builder in Splunk Search 02-01-2018
0 5
0
5
gts_ame_tfo_cty
So this is what I want to do, and I don't know if Splunk can do this. This is the result for Table A Table A hostA...
by gts_ame_tfo_cty New Member in Splunk Search 02-01-2018
0 6
0
6
gts_ame_tfo_cty
Here is my query: index="backup_script" conf_brand=ios OR conf_brand=nxos | rex field=conf_hostname "(?P^[^.]+)" | ...
by gts_ame_tfo_cty New Member in Splunk Search 02-01-2018
0 5
0
5
Nam7Splnk
I have scheduled search that periodically updates lookup table CSV file every 15 minutes. I updated this lookup with ...
by Nam7Splnk Explorer in Splunk Search 02-01-2018
0 1
0
1
vrmandadi
I have the below sample data, and I want to extract everything after the service URL till maxd=60&mind=60 into a new...
by vrmandadi Builder in Splunk Search 02-01-2018
0 4
0
4
Bbyers3
I have a date in my SQL database that I want to group the data by that date and Type. The Year/Month/Week/Day each en...
by Bbyers3 New Member in Splunk Search 02-01-2018
0 0
0
0
DEAD_BEEF
I have web logs for my website and am trying to construct a table that shows the top visitors based on country and re...
by DEAD_BEEF Builder in Splunk Search 02-01-2018
0 2
0
2
niroren
Hi, I have few rows in 1 log: 2018-01-25 13:49:40,107 INFO [com.wss.service.agent.AgentServlet] (default task-46) ...
by niroren New Member in Splunk Search 02-01-2018
0 4
0
4
mnorindr
Hello, I would like to merge 2 lines which an ID is the unique Key. Ex Username Date ID M...
by mnorindr Engager in Splunk Search 02-01-2018
1 5
1
5
Marinus
I'm currently producing a table from a search. There is some static data that needs to be added which is not in the i...
by Marinus Communicator in Splunk Search 02-01-2018
7 7
7
7
Utkarsh_Singh
i am unable to search the data with sourcetype name but i can search data by index name.Please tell what can i do to ...
by Utkarsh_Singh New Member in Splunk Search 01-31-2018
0 2
0
2
chitreshakumar
I have counts of aging tickets which we have divided into different ranges .But I want to show it as chart which will...
by chitreshakumar Communicator in Splunk Search 01-31-2018
0 8
0
8
anupkpal
I have been investigating into searches for both admin user and splunk system user. Searched conducted by System User...
by anupkpal New Member in Splunk Search 01-31-2018
0 1
0
1
karthi2809
Now i am getting only count i need error messages and host index=test "java.nio.channels.ClosedChannelException"...
by karthi2809 Builder in Splunk Search 01-31-2018
0 2
0
2
Mayanakhan
Hi I want to add a priority as P3 for the below output. Query index=nonprod sourcetype=port_availability | de...
by Mayanakhan Explorer in Splunk Search 01-31-2018
0 5
0
5
zaynaly
This is the regex I have, though not finding anything..: |rex "(?<account>\w{2,6}\\.{3,15})" example of domain and...
by zaynaly Explorer in Splunk Search 01-31-2018
0 3
0
3
dbturner
So here is what I want to do. I want to be able to search an index and sort the results via subnet/location containe...
by dbturner New Member in Splunk Search 01-31-2018
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...