Splunk Search

Splunk Search
Community Activity
kteng2024
Hi , I installed a heavy forwarder for regex processing a few source types, not for indexing. How can I know whether...
by kteng2024 Path Finder in Splunk Search 08-10-2017
0 1
0
1
auaave
Hi, How can I sort the below alphanumeric values? From To ROBOT 1 ROBOT 1 ROBOT 10 ROBOT 2 ROBOT 2 RO...
by auaave Communicator in Splunk Search 08-10-2017
0 6
0
6
ahogbin
Hello, I am trying to extract several lines of text using regex and whilst I can extract up to the first carriage re...
by ahogbin Communicator in Splunk Search 08-10-2017
1 9
1
9
ejohn
I'm trying to create a new field called TYPE, which is dependent on the word "summary" or "detail" appearing in the T...
by ejohn Path Finder in Splunk Search 08-10-2017
0 15
0
15
mkarimi17
I have a search: | tstats count WHERE earliest=-2d@d latest=now index=* by index, _time | makecontinuous span=1h _ti...
by mkarimi17 Path Finder in Splunk Search 08-10-2017
0 2
0
2
rangineniarunku
I am unable to get any values for my search when I add a field from the interesting fields list. It is happening only...
by rangineniarunku Explorer in Splunk Search 08-10-2017
0 2
0
2
sbbadri
Hi, I have a table output like below, **OS** Range1 Range2 Range3 Range4 AIX 10 ...
by sbbadri Motivator in Splunk Search 08-10-2017
0 5
0
5
nisha_kapoor
index=test TransactionId="xxx-xxx-xxx"| replace "000" with "" in Status| fields Status I want to replace the first...
by nisha_kapoor Path Finder in Splunk Search 08-10-2017
0 3
0
3
tamduong16
I have a string time in double quote and would like to convert it into duration so that I could sum it later. This is...
by tamduong16 Contributor in Splunk Search 08-10-2017
0 3
0
3
mschellhouse
I am using the following code to get a count and percentage breakdown by x and y. I would like the percent returned ...
by mschellhouse Path Finder in Splunk Search 08-10-2017
0 1
0
1
rgarbac1
This is what I tried. The query runs but the hours are not removed. index=sse_gdia_local_idx "starting from log" |e...
by rgarbac1 New Member in Splunk Search 08-10-2017
0 4
0
4
j4adam
Hello all, I have a list of hostnames in a text file that need to be in Splunk. Some of them are already in splunk a...
by j4adam Communicator in Splunk Search 08-10-2017
0 6
0
6
griffinpair
Search 1: source=*D:\\XSP\\importhelpers* source=*IH_Daily\\DebugImportHelper* End | rex field=source "importhelpers...
by griffinpair Path Finder in Splunk Search 08-10-2017
0 8
0
8
WeiseGuy
I am doing the following search: source="new_relic_insights://NRInsightsAPI_rc_ShopFront_Top10Transactions" | search...
by WeiseGuy Explorer in Splunk Search 08-10-2017
1 15
1
15
rkilen
I am trying to parse Weblogic records with a sourcetype of weblogic_stdout, but some of the logged events have multip...
by rkilen Explorer in Splunk Search 08-10-2017
0 7
0
7
srikarbaswa446
How do I get output for the following requirement? given a1=111,222,333,444,555 a2=111,222,444 output r...
by srikarbaswa446 New Member in Splunk Search 08-10-2017
0 4
0
4
knarayana
I am looking for a search to get a count of each application per day. Below is the search I have now, which gives cou...
by knarayana New Member in Splunk Search 08-10-2017
0 3
0
3
AJNZAZ
I have a python program that's generating logs with the following format START_DATE=08-AUG-2017 the problem is Splun...
by AJNZAZ Explorer in Splunk Search 08-10-2017
2 2
2
2
jalfrey
Sorry I use underscores "_" in my variable names and this forum causes those to be italics instead! So I changed all ...
by jalfrey Communicator in Splunk Search 08-10-2017
0 5
0
5
5er
Hi. I would like to search who (user) and when accessed the server (server_name) I make a search like this but I do...
by 5er New Member in Splunk Search 08-10-2017
0 4
0
4
tc641
Our Splunk expert is away  I want to see the total number servers that can communicate with splunk i.e. they are on ...
by tc641 New Member in Splunk Search 08-10-2017
0 4
0
4
matansocher
Hi, I have a table of incidents and I want to count the number of incidents opened per month. Each record updates af...
by matansocher Contributor in Splunk Search 08-10-2017
0 2
0
2
mew1033
My question is similar to this: https://answers.splunk.com/answers/35759/keping-only-most-recent-events-for-a-fixed-f...
by mew1033 Explorer in Splunk Search 08-10-2017
0 4
0
4
Kwip
My requirement is to group events (list of jobs) based on their status. The status value starts with RUNNING and ma...
by Kwip Contributor in Splunk Search 08-10-2017
0 3
0
3
bic
I have the below query which gives me the count of alerts over period of an hour, I wanted to make it as an alert by ...
by bic Explorer in Splunk Search 08-10-2017
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...