Splunk Search

Splunk Search
Community Activity
elliotproebstel
We have a number of scheduled searches that run every few minutes to search for events recently indexed that match ce...
by elliotproebstel Champion in Splunk Search 12-01-2017
1 9
1
9
vrmandadi
I have the below query index=abc sourcetype=xy.. |timechart span=1d count as events by host | addtotals time ...
by vrmandadi Builder in Splunk Search 12-01-2017
0 21
0
21
minura
I am trying to create a dashboard of CPU and Memory usage from some log files. Because of the way the data is inputte...
by minura Engager in Splunk Search 12-01-2017
0 7
0
7
mahbs
Hi, I'm trying to list data per field. I've used stats list which works partially, it lists all the data for both fi...
by mahbs Path Finder in Splunk Search 12-01-2017
0 11
0
11
smakwana
Hi Splunkers, I am looking for some help in modifying current regex to meet our updated project criteria. Link: htt...
by smakwana Explorer in Splunk Search 12-01-2017
1 5
1
5
dreschke
Hi Splunkers, I am looking for some help in creation of regular expression to Anonymize data with a regular expressi...
by dreschke Explorer in Splunk Search 11-30-2017
0 5
0
5
rfernandez2010
Hello I'm new to Splunk and I'm stuck trying to create what should be a simple table. Basically, I have a database o...
by rfernandez2010 New Member in Splunk Search 11-30-2017
0 1
0
1
katzr
Hello, I have a new set of users who I want to only be able to access 2 specific lookups. However, those lookups nee...
by katzr Path Finder in Splunk Search 11-30-2017
0 6
0
6
srobinsonxtl
All, I have the following Data: (192 of these) and trying to split the data into a multi-lined event, to extract th...
by srobinsonxtl Path Finder in Splunk Search 11-30-2017
0 9
0
9
splunker1981
Hello Splunk experts, I'm trying to figure out a better way to handle the large number of case statements that I wou...
by splunker1981 Path Finder in Splunk Search 11-30-2017
0 1
0
1
9738078959
i have a data like below.... ID | Name | 2017-12 |2018-01|2018-02|2018-03 X123 |aaa | 90 | ...
by 9738078959 Engager in Splunk Search 11-30-2017
0 9
0
9
JacobPN
Hi all, As I understand it, the cofilter command counts how many times pairs of items occur. If the same user views...
by JacobPN Path Finder in Splunk Search 11-30-2017
0 1
0
1
Mike6960
Is it possible to search results from a count when they are odd or even? So the results only show the lines/events wh...
by Mike6960 Path Finder in Splunk Search 11-30-2017
0 6
0
6
AnmolKohli
We have a requirement wherein we want to check if logs have not been updated in last 24 hours. There are around 20 in...
by AnmolKohli Explorer in Splunk Search 11-30-2017
0 1
0
1
jvmerilla
Hi, I'm doing some search query where I used timechart command that creates fields. Now, what I want to do is to som...
by jvmerilla Path Finder in Splunk Search 11-30-2017
0 3
0
3
cwl
以下のサーチ文で、regexreplacementプロセッサーがかなりのCPUリソースを使用していることまではわかりましたが、どのように問題のREGEXを特定できますでしょうか。 index=_internal source=*me...
by cwl Contributor in Splunk Search 11-30-2017
0 1
0
1
saurabhkunte
Hi All, I have a lookup table where I am maintaining States of a field. It's rather a chatty table and grows to a la...
by saurabhkunte Path Finder in Splunk Search 11-29-2017
0 1
0
1
timcolpo
I have the following SPL that is used to compute an average duration from events with 2 dates for the last 3 months. ...
by timcolpo Explorer in Splunk Search 11-29-2017
0 4
0
4
pavanae
I have defined a field extraction in a macro as below my_search | eval field_A="EventCode: " + EventCode + "; Event...
by pavanae Builder in Splunk Search 11-29-2017
0 2
0
2
mvagionakis
Hello, I'm trying to combine values from two events and to make a table with them. Let me explain you. I have the sa...
by mvagionakis Path Finder in Splunk Search 11-29-2017
0 9
0
9
bagarwal
Hello All, I want to create a report for top 10 URL's visited by the users. However, when I see the events in Palo...
by bagarwal Path Finder in Splunk Search 11-29-2017
0 7
0
7
GersonGarcia
All, I have this search: index=main sourcetype=app | transaction jobId jobExecId startswith="Starting IgniteUpdater...
by GersonGarcia Path Finder in Splunk Search 11-29-2017
0 4
0
4
davidcraven02
I want to count distinct machine names only once for each day for the last 7 days. The machine name is signified in t...
by davidcraven02 Communicator in Splunk Search 11-29-2017
0 6
0
6
heathramos
I would like to create a query (and later a real time alert) that shows when a hostname/workstation in the log files ...
by heathramos Path Finder in Splunk Search 11-29-2017
0 2
0
2
SplunkIsLife
I'm running a search on the same index and sourcetype with a few different messages, but one particular message has s...
by SplunkIsLife Explorer in Splunk Search 11-29-2017
0 4
0
4
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...