Splunk Search

Splunk Search
Community Activity
kpavan
Hi All, Need help on below query to calculate ticket age from ticket creation date with current date. Please help me...
by kpavan Path Finder in Splunk Search 12-11-2017
0 3
0
3
jrprez1804
I created a csv file critical.csv with a list of critical assets, and uploaded the lookup table into Splunk. How woul...
by jrprez1804 Path Finder in Splunk Search 12-11-2017
0 1
0
1
jamesmatthews
Hey, I am very new to Splunk so apologies if this is a very simple question. Currently Splunk is monitoring applica...
by jamesmatthews New Member in Splunk Search 12-11-2017
0 3
0
3
ahmadjabr
Hello, I'm trying to eliminate the "unknown action, hosts" etc. there is some log's that don't contain an Action, so...
by ahmadjabr Engager in Splunk Search 12-11-2017
0 2
0
2
claatu
Have seen a lot of Q&A about wildcards in the lookup table; this is the reverse. Here is the scenario. Lookup table ...
by claatu Explorer in Splunk Search 12-11-2017
0 9
0
9
rafiqul
I want to find the number of events occurring in sourcetype=B based on the distinct Device_MAC_Address searched from ...
by rafiqul New Member in Splunk Search 12-11-2017
0 2
0
2
cameronjust
So I was doing some debugging for someone on CIDR matching and appeared to get inconsistent results between versions ...
by cameronjust Path Finder in Splunk Search 12-11-2017
0 1
0
1
alfiyashaikh
I have case such as : if date is older than 5 working (eg if today is Thursday 19th, then anything older than Thursd...
by alfiyashaikh New Member in Splunk Search 12-10-2017
0 3
0
3
luchin
Hi, I am new in splunk and I would like to search for some info in my Logfile. I am just trying to count the total o...
by luchin New Member in Splunk Search 12-09-2017
0 1
0
1
splunkjpm
I would like to change the default search time for all users who select the custom app i have created from all time t...
by splunkjpm Loves-to-Learn Lots in Splunk Search 12-08-2017
0 7
0
7
spark2310
index=logs ip_address=* has single ip addresses like 5.9.100.100 CSV file: range, owner 5.9.0.0/24 Owner1 5.10.64.0...
by spark2310 Explorer in Splunk Search 12-08-2017
0 4
0
4
sogeniusio
I'm interested in knowing why it's frowned upon not to search index=*. I was asked by one of our employees and rememb...
by sogeniusio Path Finder in Splunk Search 12-08-2017
0 2
0
2
glenngermiathen
I'm running the following search, but when I add the dedup line my d_name field goes blank. I have two sourcetypes bo...
by glenngermiathen Path Finder in Splunk Search 12-08-2017
0 3
0
3
glenngermiathen
I have combined data from two searches and want to compare them to identify what is new in the second search, what is...
by glenngermiathen Path Finder in Splunk Search 12-08-2017
0 15
0
15
DianaR
Hi there, I am new and I expect, that a have only a small Problem. I want to select all Source-IPs, whitch called mo...
by DianaR New Member in Splunk Search 12-08-2017
0 8
0
8
spark2310
index=source earliest=-2h sourcetype=e | bucket _time span=1h |stats count by code _time| delta count as difference ...
by spark2310 Explorer in Splunk Search 12-08-2017
0 8
0
8
dbcase
Hi, I have the below data. I'm looking to extract out the sensor types which are designated by "sensor","q":"water...
by dbcase Motivator in Splunk Search 12-08-2017
0 2
0
2
byu168
Hi, I'm trying to plot a dataset over time. Here is my query: index=gpm AND (ExperimentStart OR runtimedatatransfer...
by byu168 Path Finder in Splunk Search 12-08-2017
0 8
0
8
leagawa
I have the following CVE results form a vulnerability report and would like to extract the CVEs to individual CVEs on...
by leagawa New Member in Splunk Search 12-08-2017
0 4
0
4
cgalligan
I'm running a query to pull data on some agents, which have each have a unique "aid". For example, my computer would...
by cgalligan Explorer in Splunk Search 12-08-2017
0 2
0
2
mahbs
Hi, I've written a regular expression to capture international characters, the only trouble I'm having with it now i...
by mahbs Path Finder in Splunk Search 12-08-2017
0 3
0
3
splunknoob408
I've got a ordering log that includes two fields, order_id and shipped_date. I am playing with Splunk to see how har...
by splunknoob408 Explorer in Splunk Search 12-08-2017
0 5
0
5
carlyleadmin
Hi everyone i am runnig the following search and getting an error.i am sure it is something so simple that i am mi...
by carlyleadmin Contributor in Splunk Search 12-08-2017
0 2
0
2
dbcase
Hi, I have a field in my existing data set called mso. Within that field are company names Example CompanyA Compa...
by dbcase Motivator in Splunk Search 12-08-2017
0 7
0
7
rsharma1984
index =ttt beforeController [search index = ttt beforeController | fields pnr, bnr, NOT(gnr)] How can I achieve tha...
by rsharma1984 Explorer in Splunk Search 12-08-2017
0 5
0
5
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...