Splunk Search

Splunk Search
Community Activity
jared_anderson
I have a field with event IDs. Some of the IDs indicate an issue, while some of them indicate the opposite. eventid=...
by jared_anderson Path Finder in Splunk Search 10-24-2017
0 5
0
5
N92
I want to ignore below user name. So I written following manner is it correct? ......| where NOT (user="*$" OR user=...
by N92 Path Finder in Splunk Search 10-24-2017
0 1
0
1
florencegoh
I have list of lookup list yyyy which I want to shown the latest login based on max login time and also user that did...
by florencegoh New Member in Splunk Search 10-24-2017
0 7
0
7
nieivan
Hi I'm trying to combine fields in multiple search result in one output table as overall result, for example: Sear...
by nieivan New Member in Splunk Search 10-24-2017
0 2
0
2
splunk_worker
Hi I want identify the long running searches who are running more than 5 min and stop them. I'm able to find the l...
by splunk_worker Path Finder in Splunk Search 10-23-2017
1 4
1
4
vik123ash
Error: Update failed. First exception on row 0 with id abcd; first error: INVALID_EMAIL_ADDRESS, Email: invalid ema...
by vik123ash Explorer in Splunk Search 10-23-2017
0 3
0
3
rsokolova
Thanks in advance, Having a hard time trying to put 3 searches together to sum both search counts by PO. Please see ...
by rsokolova Path Finder in Splunk Search 10-23-2017
0 3
0
3
pavanae
I have a query as follows to display the list of hosts which are seen in last 24 hours and hosts which are not seen i...
by pavanae Builder in Splunk Search 10-23-2017
0 14
0
14
jared_anderson
I want to create charts based on number of results. I have tried "172.20.3.6 (199.0.8.62 OR 199.0.8.57) StoresOutBo...
by jared_anderson Path Finder in Splunk Search 10-23-2017
0 2
0
2
pavanae
I have a lookup search as follows |inputlookup hostnames.csv Which displays the results as follows my_hostname...
by pavanae Builder in Splunk Search 10-23-2017
0 5
0
5
ejespiritu
Hi All, Is there an easier way in designing the charts? What i've found is using css but building one from scratch...
by ejespiritu Explorer in Splunk Search 10-23-2017
0 8
0
8
AKG1_old1
Hello, In my data, there could be multiple values(duration) for Scriptname. I am using Time Chart to display data an...
by AKG1_old1 Builder in Splunk Search 10-23-2017
2 4
2
4
isha_rastogi
I've log file something like below, DA FILE: /archive/attr/ABC/XYZ/20170911/file.log-new*** Files traversed: 128 - ...
by isha_rastogi Path Finder in Splunk Search 10-23-2017
0 4
0
4
jared_anderson
I have the following command: sourcetype="sourcetype" eventid=731 OR eventid=730 | stats latest(eventid) by target |...
by jared_anderson Path Finder in Splunk Search 10-23-2017
1 4
1
4
Rialf1959
Hello, why this is not working ? | gentimes start=-1 | eval WithUnit="0/1 2/2 3/8 0/0 5/5" | makemv WithUnit | table...
by Rialf1959 Explorer in Splunk Search 10-23-2017
0 5
0
5
kiran331
Hi I need to create an alert to trigger when an account is locked out with the details of where and why account lock...
by kiran331 Builder in Splunk Search 10-23-2017
0 6
0
6
pyamamoto
I want to find/graph the count of (dc(X) as dc_X_count by Y) by day. In other words, I have some events in a basic s...
by pyamamoto New Member in Splunk Search 10-23-2017
0 6
0
6
griffinpair
My goal for this search is to find if a file was not imported. If the file is imported "Could not find a file in the"...
by griffinpair Path Finder in Splunk Search 10-23-2017
0 6
0
6
eddychuah
I'm trying to create 1 bar chart to kill 2 views, my search is as follows; sourcetype="error log" severity=ERROR | t...
by eddychuah Path Finder in Splunk Search 10-23-2017
0 2
0
2
pbsuju
I am trying to create a dashboard for the Job status and I want to convert the job duration to HH:MM:SS. I use the be...
by pbsuju Explorer in Splunk Search 10-23-2017
0 6
0
6
dineshraj
I get a message "waiting for your queued job to start" while running search queries. Anybody knows why this message i...
by dineshraj Explorer in Splunk Search 10-23-2017
0 2
0
2
cjmckenna
For some reason I am having a real hard time wrapping my head around something..... We have an application where we ...
by cjmckenna New Member in Splunk Search 10-22-2017
0 4
0
4
ecanmaster
Does anybody have a good documentation regarding on how to use tstats? I have mainly used "normal" searches but need ...
by ecanmaster Explorer in Splunk Search 10-22-2017
1 2
1
2
romelrkhan
I have a csv lookup table with 3 columns, eg: input1,input2,output 240,789,303456 240,330,303457 240,default,303458 2...
by romelrkhan New Member in Splunk Search 10-22-2017
0 4
0
4
guru1
Which field should be extracted for this relevant use-case? index={wxxx} googlebot | fields URIs | stats count by UR...
by guru1 New Member in Splunk Search 10-22-2017
0 4
0
4
Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...