Splunk Search

Splunk Search
Community Activity
Utkarsh_Singh
i am unable to search the data with sourcetype name but i can search data by index name.Please tell what can i do to ...
by Utkarsh_Singh New Member in Splunk Search 01-31-2018
0 2
0
2
chitreshakumar
I have counts of aging tickets which we have divided into different ranges .But I want to show it as chart which will...
by chitreshakumar Communicator in Splunk Search 01-31-2018
0 8
0
8
anupkpal
I have been investigating into searches for both admin user and splunk system user. Searched conducted by System User...
by anupkpal New Member in Splunk Search 01-31-2018
0 1
0
1
karthi2809
Now i am getting only count i need error messages and host index=test "java.nio.channels.ClosedChannelException"...
by karthi2809 Builder in Splunk Search 01-31-2018
0 2
0
2
Mayanakhan
Hi I want to add a priority as P3 for the below output. Query index=nonprod sourcetype=port_availability | de...
by Mayanakhan Explorer in Splunk Search 01-31-2018
0 5
0
5
zaynaly
This is the regex I have, though not finding anything..: |rex "(?<account>\w{2,6}\\.{3,15})" example of domain and...
by zaynaly Explorer in Splunk Search 01-31-2018
0 3
0
3
dbturner
So here is what I want to do. I want to be able to search an index and sort the results via subnet/location containe...
by dbturner New Member in Splunk Search 01-31-2018
0 1
0
1
shehenshah14
Hello, I am trying to write a query which results in the subtraction of $datetimepicker value events counts & $datet...
by shehenshah14 New Member in Splunk Search 01-31-2018
0 2
0
2
tschrantz
We have a new sourcetype that's using the AWS Add-on to grab data from S3 (SQS-based). Whenever we do a stats count ...
by tschrantz New Member in Splunk Search 01-31-2018
0 4
0
4
tkwaller_2
Hello My base search uses CSV data and is very basic, simple field renames index=fp_dev_csv sourcetype=fp:dev:csv |...
by tkwaller_2 Communicator in Splunk Search 01-31-2018
0 2
0
2
rgarbac1
It always brings up no results. Here is my query: index=abc host = "123" OR host = "456" OR host = "789" OR host = ...
by rgarbac1 New Member in Splunk Search 01-31-2018
0 5
0
5
kwkeefer
I'm trying to rex out a new field from the message.Exception field. What I'm trying to extract is in the brackets be...
by kwkeefer Explorer in Splunk Search 01-31-2018
0 5
0
5
mahbs
Hi, Is there a way of writing an if condition that basically says, "if value x exists in all of tabled fields, then ...
by mahbs Path Finder in Splunk Search 01-31-2018
0 4
0
4
tonahoyos
Hello All, I am running the following search: index="ledata_2017" NOT Project="60*" | stats sum(ActualPTDCostsAMT) ...
by tonahoyos Explorer in Splunk Search 01-31-2018
0 7
0
7
mcollins42
I'm failing miserably at this. I'm hoping someone can help me out so I can build my knowledge for future extractions ...
by mcollins42 New Member in Splunk Search 01-31-2018
0 6
0
6
dmoulais
I have a collection of hundreds of files. I want to write a search that (1) finds which file has a certain keyword a...
by dmoulais New Member in Splunk Search 01-31-2018
0 1
0
1
CarmineCalo
Splunkers! I have a new problem I'm not able to solve, I hope you can help me... Basically, I'm counting the number ...
by CarmineCalo Path Finder in Splunk Search 01-31-2018
0 3
0
3
varunghai
Hi, I am a Splunk User and been using it for a few months now, I have created a query which creates a table of count...
by varunghai Engager in Splunk Search 01-31-2018
0 2
0
2
samwatson45
Is there any way I can manually add another line to a chart, which is just a single value that I can decide? All I ...
by samwatson45 Path Finder in Splunk Search 01-31-2018
0 6
0
6
vinoth12
Hi all, There are 2 fields, A and B... Values of A apple ora nge kite drink mask Values of B are orange.12 orang...
by vinoth12 New Member in Splunk Search 01-31-2018
0 2
0
2
bharathkumarnec
Hi All, My requirement is to display only percentages in the pie chart not the label names. I tried below two optio...
by bharathkumarnec Contributor in Splunk Search 01-31-2018
0 9
0
9
shiv1593
Hello fellow Splunkers,, I have a two fold question. I have a field called Call_DESCRIPTION_Text, which contains is...
by shiv1593 Communicator in Splunk Search 01-31-2018
0 0
0
0
sidhantbhayana
Hi All, I have a situation where the data is in csv format and first two columns have date and time information, my ...
by sidhantbhayana Path Finder in Splunk Search 01-30-2018
0 5
0
5
dmarcantonionw
I am pulling Windows event logs for software updates. There's a column for successRatio that is either Success or Fai...
by dmarcantonionw Engager in Splunk Search 01-30-2018
0 2
0
2
thomasreggi
I have a query like this: 213123123-231231230342 | transaction startswith="user login process start" endswith="user ...
by thomasreggi New Member in Splunk Search 01-30-2018
0 1
0
1
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors