Splunk Search

Splunk Search
Community Activity
viggor
Given a timeinterval provided by the user, I would like to output those buckets who contain more elements than the av...
by viggor Path Finder in Splunk Search 09-29-2017
0 6
0
6
dhavamanis
We have monthly data for each SBU and we want to setup an alert if any total increase more than 5% for up coming mont...
by dhavamanis Builder in Splunk Search 09-29-2017
0 4
0
4
hmrabet2
I am not getting iplocation working in this query: tag= web | stats count by IP, sessionId | stats dc(IP) as count, ...
by hmrabet2 Observer in Splunk Search 09-29-2017
0 3
0
3
ringbbg
HI All. I have a simple dashboard where the data in the statistic table changes everytime you change the dropdown inp...
by ringbbg Engager in Splunk Search 09-29-2017
0 1
0
1
christoffertoft
I have the following search term .... | | stats count(eval(action="failure")) as fails, count(eval(action="success"...
by christoffertoft Communicator in Splunk Search 09-29-2017
0 7
0
7
fre
Hi and thanks for reading in advance, I have two tables: events for status=50* on a /submissions URL endpoint, let'...
by fre Engager in Splunk Search 09-28-2017
0 4
0
4
puneetkharband1
need to print dates from Thanksgiving onward for the rest of the week until Monday index="test" source="test" date=*...
by puneetkharband1 Path Finder in Splunk Search 09-28-2017
0 4
0
4
mk197m
How to remove duplicate device_id within five min interval for 24 hours search, for example : 10:00am device id =aa...
by mk197m New Member in Splunk Search 09-28-2017
0 1
0
1
sunnyparmar
I have one user (scpet) to whom I assigned rights and roles of some apps. Now the user is facing a problem that he is...
by sunnyparmar Communicator in Splunk Search 09-28-2017
0 4
0
4
kiran331
Hi I have distinguishedName values from Ldap query, how can I convert it to canonical names using Regex? for eg: C...
by kiran331 Builder in Splunk Search 09-28-2017
0 2
0
2
dbcase
Hi, I have this data 10.210.192.15 - - [26/Sep/2017:19:59:59 -0400] "POST /rest/icontrol/sites/315568/network/insta...
by dbcase Motivator in Splunk Search 09-28-2017
0 4
0
4
letpeter
I would like to capture the value of used_memory_peak_human =>"26.28M" as it increases or decreases from all servers....
by letpeter New Member in Splunk Search 09-28-2017
0 2
0
2
mlange2007
The JSON part to extract is MESSAGES. We created a REGEX which works in the search, but it should be also added perma...
by mlange2007 New Member in Splunk Search 09-28-2017
0 1
0
1
frizzoS3
Guided and Manual Mode? Real Time and Continuous? Is one more efficient then the other? Thank you. Frank
by frizzoS3 New Member in Splunk Search 09-28-2017
0 2
0
2
mateibos
Hello, I am extracting from a database the list of the largest 20 tables. The format would be something like =: For...
by mateibos New Member in Splunk Search 09-28-2017
0 1
0
1
Hemnaath
Hi All Currently we are facing an issue for Some of the universal forwarders have had their hostname updated, but it ...
by Hemnaath Motivator in Splunk Search 09-28-2017
0 17
0
17
katzr
So i am trying to convert some of my searches from joins to appendcol to improve performance but I am running into so...
by katzr Path Finder in Splunk Search 09-28-2017
0 4
0
4
bgagliardi1
I'm working with ServiceNow incident logs and I'm trying to group events weekly, based on their final state in the we...
by bgagliardi1 Path Finder in Splunk Search 09-28-2017
0 5
0
5
packet_hunter
So I noticed that when I run two searches like the following and I am looking for a value, in this case some computer...
by packet_hunter Contributor in Splunk Search 09-28-2017
0 1
0
1
dbcase
Hi, I have this data 10.210.192.15 - - [26/Sep/2017:19:59:59 -0400] "POST /rest/icontrol/sites/315568/network/insta...
by dbcase Motivator in Splunk Search 09-28-2017
0 2
0
2
francly
Hi I can use the search string to get the statistics output index=data sourcetype="data1" host=HOSTA | stats count ...
by francly Explorer in Splunk Search 09-28-2017
0 8
0
8
khanlarloo
hi i have one problem in making report. in my report result i have repeated name how can I avoid to not show the rep...
by khanlarloo Explorer in Splunk Search 09-27-2017
0 3
0
3
dsmithson8812
I'm lost. I'm trying to capture the _time and UserName (custom field) from a search and use the _time to find events...
by dsmithson8812 Engager in Splunk Search 09-27-2017
0 14
0
14
nabeel652
I have a field in Windows Backup Events named VolumesInfo Sample: <VolumeInfoItem Name="System" OriginalAccessPath="...
by nabeel652 Builder in Splunk Search 09-27-2017
0 3
0
3
alaking
Hello, I am trying to create a correlation search that will detect users accessing devices for which they aren't aut...
by alaking Explorer in Splunk Search 09-27-2017
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...