| Hi I use a JOIN and now i have multiple lines and not unique ones. It returned one line per unique Context+Command. ... by robertlynch2020 Influencer in Splunk Search 10-06-2017 0 5 | 0 | 5 | ||
| Hi all! The case is that I want to calculate sum of purchase price of the applications where the application status ... by Jurala Explorer in Splunk Search 10-06-2017 0 2 | 0 | 2 | ||
| My fields contains " search | eval status=if(value>10,Success,failure) | table Name message status Name Message Sta... by karthikeyan_k14 New Member in Splunk Search 10-05-2017 0 3 | 0 | 3 | ||
| Hello Splunk Community, Business requirements pushing my knowledge on Splunk so far... just wondering if Splunk quer... by cabauah Path Finder in Splunk Search 10-05-2017 0 1 | 0 | 1 | ||
| Hello folks, I am new to Splunk and need to get a report in CSV file or table. I like to see only URL and values of ... by BaharJ New Member in Splunk Search 10-05-2017 0 2 | 0 | 2 | ||
| Hello, Is there an available post-processing method to use a base search and produce a secondary search id? I'm putt... by jocobknight Explorer in Splunk Search 10-05-2017 0 5 | 0 | 5 | ||
| So I have to queries... First one gives me a normal time/date format which is human-readable i.e. (2017-10-05 15:20:... by packet_hunter Contributor in Splunk Search 10-05-2017 0 1 | 0 | 1 | ||
| Hello, Hopefully, you will understand what I mean...It was not clear how I could formulate a search to find some doc... by adamski007 Explorer in Splunk Search 10-05-2017 0 11 | 0 | 11 | ||
| Hello, I have this query to alert me when percentage_q_full reaches greater than certain number eval alert=case((PE... by charanramireddy New Member in Splunk Search 10-05-2017 0 2 | 0 | 2 | ||
| Hi, I wrote the following Splunk query which returns a list of distinct USER_AGENTs for each SESSION_ID: index=abc ... by jbrenner Path Finder in Splunk Search 10-05-2017 0 2 | 0 | 2 | ||
| in my search contcxtid and sourceSession has the same vales but indexing in to different places how could i compare ... by svemurilv Path Finder in Splunk Search 10-05-2017 0 2 | 0 | 2 | ||
| We have a cluster of four nodes and one of them just crashed. We brought it up, but it hasn't joined the cluster. Rol... by ddrillic Ultra Champion in Splunk Search 10-05-2017 0 2 | 0 | 2 | ||
| Hi Guys, We have UFs on our DCs and 2 indexers and on both indexers, to drop the unwanted text from events I tried... by hrithiktej Communicator in Splunk Search 10-05-2017 0 4 | 0 | 4 | ||
| I have a about 250 Admin users and I would like to to know when was the last time each of them have logged in. Is the... by RASHO123 New Member in Splunk Search 10-05-2017 0 1 | 0 | 1 | ||
| HI! I have two search heads in cluster and multiple lookups in Splunk but currently started facing issues of replica... by MousumiChowdhur Contributor in Splunk Search 10-05-2017 7 3 | 7 | 3 | ||
| When I am on the Search Head and I go to data summary under Search and Reporting, it only shows 2 host but they come ... by andsmith2 Explorer in Splunk Search 10-05-2017 0 3 | 0 | 3 | ||
| I run index=hydra bu=dmg env="prod-*" ERROR everyday and record the count. I lost the statistics I had kept and would... by manish41711 Engager in Splunk Search 10-05-2017 0 3 | 0 | 3 | ||
| Besides running "index=foo *" is there a way to quickly check the total number of events indexed in an index? by muebel SplunkTrust 3 4 | 3 | 4 | ||
| So here's my issue. We are creating a chart that shows each user and which desktops they use. The desktops are div... by kmaron Motivator in Splunk Search 10-05-2017 0 4 | 0 | 4 | ||
| I have four fields, baseline, lvl1,lvl2,lv3. I have to compare baseline vs (lvl1+lvl2+lvl3) to see if sum of lvl1,lvl... by prafulljha New Member in Splunk Search 10-05-2017 0 13 | 0 | 13 | ||
| Hi Splunk, Having a problem with one of our ingestion in splunk. The logs are delayed and cant seem to find the caus... by cymondcuba New Member in Splunk Search 10-05-2017 0 1 | 0 | 1 | ||
| Hi everyone! So, I have this search: index=XXXXX sourcetype=XXXXX earliest="$time_token.earliest$" latest="$time_to... by tsomod Path Finder in Splunk Search 10-05-2017 0 6 | 0 | 6 | ||
| Query: search...| eval earliest=relative_time(strptime("01-February 2017","%d-%B %Y"),"+0mon"), latest=relative_time... by rishavvaidya Explorer in Splunk Search 10-05-2017 0 3 | 0 | 3 | ||
| This is the event : 02OCT2017_16:46:47.212 130880:140149567481600 INFO event.py:177 root event = {"hopTrace": {"hops... by bharpur183 Explorer in Splunk Search 10-04-2017 0 33 | 0 | 33 | ||
| I have a search from which I get the below result one of the columns in the statistics table : Sat Oct 07 2017 07:30... by bharpur183 Explorer in Splunk Search 10-04-2017 0 8 | 0 | 8 |