Splunk Search

Splunk Search
Community Activity
kaushik1218
Below is the example of single request with multiple lines where ServiceType is different. Required result to be a...
by kaushik1218 New Member in Splunk Search 08-15-2017
0 2
0
2
JustRoot
Hello, So currently, one of my indices logs has the file path which contains the file name but doesn't have a separa...
by JustRoot Path Finder in Splunk Search 08-15-2017
0 4
0
4
DrRich
Hi, I've written a query (see original query below) which joins 3 different event types to display A_events started...
by DrRich Explorer in Splunk Search 08-15-2017
0 6
0
6
drizzo
We're combining many types of searches into one tabled alert. We create our own variables with an eval statement and ...
by drizzo Path Finder in Splunk Search 08-15-2017
0 4
0
4
michaelrosello
Is there a way to customize the column charts label, or the y-axis? What I want to do is create a column with the co...
by michaelrosello Path Finder in Splunk Search 08-14-2017
0 4
0
4
jwalzerpitt
I have the following search in which I'm trying to sort first alphabetically and then by total, but the Processes fie...
by jwalzerpitt Influencer in Splunk Search 08-14-2017
0 7
0
7
viggor
I have a simple question: I have two variables foo and bar, each containing a set of strings, and I would like to c...
by viggor Path Finder in Splunk Search 08-14-2017
0 3
0
3
DEAD_BEEF
I have a query that shows observed category of domains (search engines, social media, streaming, etc.). I'd like to ...
by DEAD_BEEF Builder in Splunk Search 08-14-2017
0 4
0
4
gb0143
I have a log as follows 14AUG2017_12:54:44.903 3418:13 INFO filename.cpp:200 ID:abc123 contextInfo: [ peer_service...
by gb0143 New Member in Splunk Search 08-14-2017
0 1
0
1
splunk_anoosheh
When I use this command ( table ) it runs at a slow speed .... please help me. Thank you for your answer.
by splunk_anoosheh New Member in Splunk Search 08-14-2017
0 2
0
2
rens78
My search so far: index=notimportant EventID=4624 [ inputlookup users.csv | fields TargetUserName ] | chart eval(la...
by rens78 New Member in Splunk Search 08-14-2017
0 2
0
2
ejeny
Hello everyone, So what I'm trying to do with this is print out a value into a Single Value Panel (42). Depending on...
by ejeny Explorer in Splunk Search 08-14-2017
0 9
0
9
nittalasub
how to extract only decimal values in splunk ? ..example (7 divided by 2 ) = 3.5 , I need to get only 0.5 here ...wi...
by nittalasub Explorer in Splunk Search 08-13-2017
0 9
0
9
sangs8788
I have a lookup file with dates. how do i use it to set earliest and latest inorder to search for events, For exampl...
by sangs8788 Communicator in Splunk Search 08-13-2017
0 3
0
3
coenvandijk
Hello I have a string of all uppercase letters (no digits) I need a regex to insert a ":" after every second charact...
by coenvandijk Observer in Splunk Search 08-13-2017
0 8
0
8
auaave
Hi, I have the below statement with the correct statistics output. However my visualization is empty. But when I use...
by auaave Communicator in Splunk Search 08-13-2017
0 2
0
2
prashanthberam
Hi All, I want to compare result column Names which is displaying 3 kind of messages. Normal, Elevated, C...
by prashanthberam Explorer in Splunk Search 08-12-2017
0 6
0
6
jsuryaprakash
index=main (sourcetype=bb OR sourcetype=cc) type=DELETE | transaction info.agentId startswith=COMPLETED endswith=DE...
by jsuryaprakash Path Finder in Splunk Search 08-12-2017
0 1
0
1
kteng2024
Hi, For example, we have 2 universal forwarders UF1 = web01abc23 UF2 = web01cde21 Both are having same inputs.con...
by kteng2024 Path Finder in Splunk Search 08-11-2017
0 1
0
1
medveleyenet
I migrated the database "splunk/var/lib/splunk" but when I copy my configuration files, the fields and alerts disapp...
by medveleyenet New Member in Splunk Search 08-11-2017
0 1
0
1
patilsh
Hello Guys, I have a column _time Ex Values (Suppose the search has 4 events here): 2017-08-11 12:06:51 2017-08-11...
by patilsh Explorer in Splunk Search 08-11-2017
0 2
0
2
rgarbac1
I am looking for help with a case statement that looks for a field full load with a value of "running CDC only in fre...
by rgarbac1 New Member in Splunk Search 08-11-2017
0 1
0
1
kiran331
Hello, How to use Regex in props.conf to extract the fields in the below sample event with source type "syslog". 08...
by kiran331 Builder in Splunk Search 08-11-2017
0 3
0
3
pavanae
For yesterday's results we give the earliest and latest as below earliest=-1d@d latest=@d Simillarly, what could b...
by pavanae Builder in Splunk Search 08-11-2017
0 3
0
3
ibob0304
I have events which are in this format, where the time in the event is the _time. 8/11/2017 1:26:17 PM|Thread Id: 4...
by ibob0304 Communicator in Splunk Search 08-11-2017
0 3
0
3
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...