Splunk Search

Splunk Search
Community Activity
tkwaller_2
Hello My base search uses CSV data and is very basic, simple field renames index=fp_dev_csv sourcetype=fp:dev:csv |...
by tkwaller_2 Communicator in Splunk Search 01-31-2018
0 2
0
2
rgarbac1
It always brings up no results. Here is my query: index=abc host = "123" OR host = "456" OR host = "789" OR host = ...
by rgarbac1 New Member in Splunk Search 01-31-2018
0 5
0
5
kwkeefer
I'm trying to rex out a new field from the message.Exception field. What I'm trying to extract is in the brackets be...
by kwkeefer Explorer in Splunk Search 01-31-2018
0 5
0
5
mahbs
Hi, Is there a way of writing an if condition that basically says, "if value x exists in all of tabled fields, then ...
by mahbs Path Finder in Splunk Search 01-31-2018
0 4
0
4
tonahoyos
Hello All, I am running the following search: index="ledata_2017" NOT Project="60*" | stats sum(ActualPTDCostsAMT) ...
by tonahoyos Explorer in Splunk Search 01-31-2018
0 7
0
7
mcollins42
I'm failing miserably at this. I'm hoping someone can help me out so I can build my knowledge for future extractions ...
by mcollins42 New Member in Splunk Search 01-31-2018
0 6
0
6
dmoulais
I have a collection of hundreds of files. I want to write a search that (1) finds which file has a certain keyword a...
by dmoulais New Member in Splunk Search 01-31-2018
0 1
0
1
CarmineCalo
Splunkers! I have a new problem I'm not able to solve, I hope you can help me... Basically, I'm counting the number ...
by CarmineCalo Path Finder in Splunk Search 01-31-2018
0 3
0
3
varunghai
Hi, I am a Splunk User and been using it for a few months now, I have created a query which creates a table of count...
by varunghai Engager in Splunk Search 01-31-2018
0 2
0
2
samwatson45
Is there any way I can manually add another line to a chart, which is just a single value that I can decide? All I ...
by samwatson45 Path Finder in Splunk Search 01-31-2018
0 6
0
6
vinoth12
Hi all, There are 2 fields, A and B... Values of A apple ora nge kite drink mask Values of B are orange.12 orang...
by vinoth12 New Member in Splunk Search 01-31-2018
0 2
0
2
bharathkumarnec
Hi All, My requirement is to display only percentages in the pie chart not the label names. I tried below two optio...
by bharathkumarnec Contributor in Splunk Search 01-31-2018
0 9
0
9
shiv1593
Hello fellow Splunkers,, I have a two fold question. I have a field called Call_DESCRIPTION_Text, which contains is...
by shiv1593 Communicator in Splunk Search 01-31-2018
0 0
0
0
sidhantbhayana
Hi All, I have a situation where the data is in csv format and first two columns have date and time information, my ...
by sidhantbhayana Path Finder in Splunk Search 01-30-2018
0 5
0
5
dmarcantonionw
I am pulling Windows event logs for software updates. There's a column for successRatio that is either Success or Fai...
by dmarcantonionw Engager in Splunk Search 01-30-2018
0 2
0
2
thomasreggi
I have a query like this: 213123123-231231230342 | transaction startswith="user login process start" endswith="user ...
by thomasreggi New Member in Splunk Search 01-30-2018
0 1
0
1
HattrickNZ
This is my search: | makeresults | eval data = " 1 2017-12 A 155749 131033 84.1; 2 2017-12 B 24869 236...
by HattrickNZ Motivator in Splunk Search 01-30-2018
0 5
0
5
dtakacssplunk
Hello I'm trying to convert an epoach time to the UTC time. I tried the following: e.g. pageStartTime = 15172758268...
by dtakacssplunk Explorer in Splunk Search 01-30-2018
0 3
0
3
subtrakt
Hi Everyone, Would like to reduce bin count to 1 for each bin if total bins is greater than 10. (basically I want...
by subtrakt Contributor in Splunk Search 01-30-2018
0 5
0
5
dkotowsk
How do you create a stats count after aggregating multiple fields into one? Example: Given the following table: ind...
by dkotowsk Engager in Splunk Search 01-30-2018
0 1
0
1
cdgill
Basically just trying to add three time values together by doing this: eval total_time = queue_time + Duration + test...
by cdgill Explorer in Splunk Search 01-30-2018
0 7
0
7
fzhao2
I have multiple tables, can I add/OR/AND... on each cell of all the tables? For example, if I have below two tables,...
by fzhao2 Engager in Splunk Search 01-30-2018
0 2
0
2
shiv1593
Hi All, I have a dashboard, which contains a pie chart, that looks like this. As visible, there are only 5 values...
by shiv1593 Communicator in Splunk Search 01-30-2018
0 6
0
6
chandana204
i have this kind of data: event 1: field_name=field_value status="process" status_file="file_name" event 2: fiel...
by chandana204 Communicator in Splunk Search 01-30-2018
0 2
0
2
JarrettM
My iis data has a field name cs_uri_query, for example: Cmd=Sync&User=XYZ%5Cjqpublic%40xyz.com&DeviceId=SEC539D6F312...
by JarrettM Path Finder in Splunk Search 01-30-2018
0 3
0
3
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...