Splunk Search

Splunk Search
Community Activity
Pramodkuber
Need to fetch API name from URL. e.g. base_url/products_support/system_name/api-name?parameters Here I need to fet...
by Pramodkuber Engager in Splunk Search 12-13-2017
0 2
0
2
jibin1988
Hi Splunkers, I need a search query for browsing time by user. I have one query : | stats sum(duration) AS session_...
by jibin1988 Path Finder in Splunk Search 12-12-2017
0 5
0
5
DataOrg
the Information in service : ID R1-7857hi75 is duplicated i want to make it as the Information in service : ID R1-*...
by DataOrg Builder in Splunk Search 12-12-2017
0 4
0
4
Maverick904
Hello All, I wrote below query to get the URLs from inputlookup file that is not captured in syslog.But didnt give m...
by Maverick904 Explorer in Splunk Search 12-12-2017
0 4
0
4
raviteja029
Hi Everyone, I am trying to create a report where I am able to get the list of username's / number for calls for las...
by raviteja029 Explorer in Splunk Search 12-12-2017
0 5
0
5
pkashou
I need the ability to dedup a multi-value field on a per event basis. Something like values() but limited to one even...
by pkashou Explorer in Splunk Search 12-12-2017
3 6
3
6
bdesatnik
I'm trying to format the query in the search bar so it appears on multiple lines (for easier readability). From this...
by bdesatnik New Member in Splunk Search 12-12-2017
0 4
0
4
aohls
I am looking to create a table for distinct errors we have. Unfortunately I had this working at one point and am unab...
by aohls Contributor in Splunk Search 12-12-2017
1 5
1
5
netanelm7
Hi everybody, I have a problem with an "appendcols" command. I have a query which needs to count how many times a fi...
by netanelm7 Path Finder in Splunk Search 12-12-2017
0 3
0
3
fsrodriguez
I have the values I just don't have the syntax. host="app-1" source="df" | stats max(storage_used) as storage_used b...
by fsrodriguez New Member in Splunk Search 12-12-2017
0 3
0
3
dangtran
Have good day for Everybody Pls help me to search exactly the content. My input log is: status system replication si...
by dangtran Explorer in Splunk Search 12-12-2017
0 5
0
5
robrang558
I have two timecharts that only hit on http status code of 500 (one for the past hour and one for the same hour but l...
by robrang558 Explorer in Splunk Search 12-12-2017
0 8
0
8
meechy85
Hello, I'm attempting to use a Splunk view to edit a Lookup table based on an input field and a radio button selecti...
by meechy85 New Member in Splunk Search 12-12-2017
0 3
0
3
snipedown21
Hi There. I have a lookup like below. end_date activity description start_date 1496325600 run XYZ ...
by snipedown21 Path Finder in Splunk Search 12-12-2017
0 1
0
1
kishen2017
How to join multiple select statements in dbxquery Need to display output as Total Defects 532 Open defects 147 Close...
by kishen2017 Path Finder in Splunk Search 12-12-2017
0 5
0
5
belle501
Hey everyone, I'm building a simple dashboard to show some info about SFTP traffic. I'm using a time picker to pick t...
by belle501 Path Finder in Splunk Search 12-12-2017
0 2
0
2
glenngermiathen
Im trying to show a trend in event data by platform. I want to create a line chart showing the last 6 months with on...
by glenngermiathen Path Finder in Splunk Search 12-12-2017
0 2
0
2
jibin1988
Hi Splunkers, I want to generate a catogery wise Browsing time report per user. Here is my search given below : hos...
by jibin1988 Path Finder in Splunk Search 12-12-2017
0 3
0
3
deepa_purushoth
My data looks something like below, here first two rows are indexed data and 3,4th rows are derived data and added as...
by deepa_purushoth Engager in Splunk Search 12-12-2017
0 1
0
1
greggz
I have ton a couple of events like this: Mime.stuff.1 = 10 Mime.pop = "blabla" Basically I want to create a field "...
by greggz Communicator in Splunk Search 12-12-2017
0 5
0
5
kamgineer
The goal here is to get CPU usage per SQL instance. As far as I can tell there is no perfmon counter that will give y...
by kamgineer Explorer in Splunk Search 12-12-2017
0 1
0
1
JyotiP
Query : "POST" "200" "api/platform/v1/Session" FirmName Output: Level="INFO", Date="2017-12-12 04:06:26,200", Messag...
by JyotiP Path Finder in Splunk Search 12-12-2017
0 2
0
2
woodcock
Any search that has many field values and ends in "| stats values(field)" will show a short list of field values foll...
by Esteemed Legend in Splunk Search 12-12-2017
1 2
1
2
Shan
Hi, My current search I'm using to populate the value is given below. source= transaction.csv | stats values(A...
by Shan Builder in Splunk Search 12-12-2017
0 7
0
7
ByteFlinger
I have a bunch of indexes in the format of <environment>-<machineType> This is something like test-manager, staging-...
by ByteFlinger Engager in Splunk Search 12-12-2017
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...