Splunk Search

Splunk Search
Community Activity
ReufRamon
Hello everyone, I have indexed a number of events which all have an "Amount" field. I have to search for events from...
by ReufRamon New Member in Splunk Search 08-20-2017
0 2
0
2
vrmandadi
Hello, I have the below URL Types and I am trying to extract 3 fields from them LIVE as form hls as rule TWAMCPH as...
by vrmandadi Builder in Splunk Search 08-19-2017
0 7
0
7
kaushik1218
For example below is my XML <serviceType>xxx</serviceType> <some stuff> <some more stuff> <code>D</code> Now I ne...
by kaushik1218 New Member in Splunk Search 08-19-2017
0 2
0
2
vrmandadi
Hello Experts, I am using the interactive field extractor (IFE) to extract URL and status from every event, but the ...
by vrmandadi Builder in Splunk Search 08-19-2017
0 6
0
6
splunk4now
I have 3 data sets (say src1, src2, sr3), with merged resultsets of single merge greater than the 50k limit - hence n...
by splunk4now Explorer in Splunk Search 08-19-2017
0 4
0
4
viveklucky1848
I have following phtml file which is a hybrid of php and html code. <?php /** * Magento * * NOTICE OF LICENSE * ...
by viveklucky1848 New Member in Splunk Search 08-18-2017
0 1
0
1
jcoyan
Apologies for what I assume is a fairly simple question, but my searches online and on here have led me nowhere. I h...
by jcoyan New Member in Splunk Search 08-18-2017
0 6
0
6
icrit
I have a field with a date in the format of %m/$d/%Y. I'm trying to use the date picker in the dashboard to only sear...
by icrit Explorer in Splunk Search 08-18-2017
0 7
0
7
Baguvik
For example i have such event PassengerID=F123 Origin=LHR Destination=BER Flight=1121 DepartureDate=07AUG Passenger...
by Baguvik Explorer in Splunk Search 08-18-2017
0 11
0
11
harishnpandey
index=xyz "The Key is not in cache the source Code:" |rex field=_raw ":(?\w+)" | stats count by imagetype However, i...
by harishnpandey Explorer in Splunk Search 08-18-2017
0 10
0
10
melonman
Hi Can anyone help me create a search in audittrail index to get the min/avg/max number of concurrent searches in a ...
by melonman Motivator in Splunk Search 08-18-2017
0 3
0
3
rsreese
I am attempting to extract Time using TIME_FORMAT and TIME_PREFIX in props.conf. Would like to understand how to corr...
by rsreese Explorer in Splunk Search 08-18-2017
0 1
0
1
mwinkel
Hi, I'm trying double loop through a csv list of words using the map command. The idea behind it is to perform a sea...
by mwinkel New Member in Splunk Search 08-18-2017
0 2
0
2
duffeysplunk
I have a service which we need to monitor discrete states. I only get events if the state changes. I can map these ...
by duffeysplunk Path Finder in Splunk Search 08-18-2017
0 2
0
2
xbbj3nj
Assuming that Splunk is installed as per the recommended reference architecture and hardware, then based on real-worl...
by xbbj3nj Path Finder in Splunk Search 08-18-2017
0 1
0
1
mjm295
I have this query to create a stats table: index=star_aws sourcetype=aws:ec2 State=running | dedup InstanceID | rena...
by mjm295 Path Finder in Splunk Search 08-18-2017
0 4
0
4
pranaynanda
The gut who was doing this job before me made some servicenow reports using excel . He devised a term something that ...
by pranaynanda Path Finder in Splunk Search 08-18-2017
0 9
0
9
akarivaratharaj
I have a below search query which gives me the count of the error(the corresponding events have only the description ...
by akarivaratharaj Communicator in Splunk Search 08-18-2017
0 8
0
8
kteng2024
We have 3 heavy forwarders and universal forwarders are sending data to these 3 HF. But the CPU usage on one of the h...
by kteng2024 Path Finder in Splunk Search 08-17-2017
0 1
0
1
msscott63
I have numerous events, each of which has a multivalue field that has a list of X (where X is a number) hashes in it....
by msscott63 New Member in Splunk Search 08-17-2017
0 2
0
2
HattrickNZ
This is my search index=X ....| search column!="T*" column!="I*" column!="m*" column!="l*" column!="d*" ...
by HattrickNZ Motivator in Splunk Search 08-17-2017
0 3
0
3
asdfxqwert
We have the below data: IP Count A 50 B 100 C 20 D 60 E ...
by asdfxqwert Explorer in Splunk Search 08-17-2017
0 7
0
7
jpvalenc
So I've been trying to use TA-Webtools app to get data from a Sharepoint site after some googling. As a test, I’ve t...
by jpvalenc Path Finder in Splunk Search 08-17-2017
1 5
1
5
bcarr12
What would be the best way to run a week to date search (timechart/bin) that "flattens" the individual days so I can ...
by bcarr12 Path Finder in Splunk Search 08-17-2017
0 1
0
1
jcftx7
I am looking at a log of users logging into machines. The two fields I am interested in are: Username and Machine nam...
by jcftx7 New Member in Splunk Search 08-17-2017
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors