Splunk Search

Splunk Search
Community Activity
rgarbac1
This is what I tried. The query runs but the hours are not removed. index=sse_gdia_local_idx "starting from log" |e...
by rgarbac1 New Member in Splunk Search 08-10-2017
0 4
0
4
j4adam
Hello all, I have a list of hostnames in a text file that need to be in Splunk. Some of them are already in splunk a...
by j4adam Communicator in Splunk Search 08-10-2017
0 6
0
6
griffinpair
Search 1: source=*D:\\XSP\\importhelpers* source=*IH_Daily\\DebugImportHelper* End | rex field=source "importhelpers...
by griffinpair Path Finder in Splunk Search 08-10-2017
0 8
0
8
WeiseGuy
I am doing the following search: source="new_relic_insights://NRInsightsAPI_rc_ShopFront_Top10Transactions" | search...
by WeiseGuy Explorer in Splunk Search 08-10-2017
1 15
1
15
rkilen
I am trying to parse Weblogic records with a sourcetype of weblogic_stdout, but some of the logged events have multip...
by rkilen Explorer in Splunk Search 08-10-2017
0 7
0
7
srikarbaswa446
How do I get output for the following requirement? given a1=111,222,333,444,555 a2=111,222,444 output r...
by srikarbaswa446 New Member in Splunk Search 08-10-2017
0 4
0
4
knarayana
I am looking for a search to get a count of each application per day. Below is the search I have now, which gives cou...
by knarayana New Member in Splunk Search 08-10-2017
0 3
0
3
AJNZAZ
I have a python program that's generating logs with the following format START_DATE=08-AUG-2017 the problem is Splun...
by AJNZAZ Explorer in Splunk Search 08-10-2017
2 2
2
2
jalfrey
Sorry I use underscores "_" in my variable names and this forum causes those to be italics instead! So I changed all ...
by jalfrey Communicator in Splunk Search 08-10-2017
0 5
0
5
5er
Hi. I would like to search who (user) and when accessed the server (server_name) I make a search like this but I do...
by 5er New Member in Splunk Search 08-10-2017
0 4
0
4
tc641
Our Splunk expert is away  I want to see the total number servers that can communicate with splunk i.e. they are on ...
by tc641 New Member in Splunk Search 08-10-2017
0 4
0
4
matansocher
Hi, I have a table of incidents and I want to count the number of incidents opened per month. Each record updates af...
by matansocher Contributor in Splunk Search 08-10-2017
0 2
0
2
mew1033
My question is similar to this: https://answers.splunk.com/answers/35759/keping-only-most-recent-events-for-a-fixed-f...
by mew1033 Explorer in Splunk Search 08-10-2017
0 4
0
4
Kwip
My requirement is to group events (list of jobs) based on their status. The status value starts with RUNNING and ma...
by Kwip Contributor in Splunk Search 08-10-2017
0 3
0
3
bic
I have the below query which gives me the count of alerts over period of an hour, I wanted to make it as an alert by ...
by bic Explorer in Splunk Search 08-10-2017
0 1
0
1
shivi_tcs
Hi Splunkers! I am try to evaluate few things by using query below- index=* sourcetype=* | stats values(OPEN_INT...
by shivi_tcs Engager in Splunk Search 08-10-2017
0 3
0
3
sajeeshpn
What could be the reasons why scheduled reports are not getting executed all the time ? We get log messages like:- 0...
by sajeeshpn New Member in Splunk Search 08-09-2017
0 3
0
3
mrgibbon
Hi All, Im working with some vulnerability data and I'm wondering if I can sort the list I have of different vulnerab...
by mrgibbon Contributor in Splunk Search 08-09-2017
0 2
0
2
paulathome
We would like to remind Splunk users to always include an index in their queries. With over 200 indexes it is taxing...
by paulathome Path Finder in Splunk Search 08-09-2017
0 9
0
9
pushpender07
Hi All, I have a search - index=ABC sourcetype=XYZ | stats values(user), dc(user) by region | transpose header_field...
by pushpender07 Explorer in Splunk Search 08-09-2017
0 11
0
11
mkarimi17
UPDATE: I have created a search/alert that should notify me if: Index data is 0 for a particular hourIndex data cou...
by mkarimi17 Path Finder in Splunk Search 08-09-2017
0 5
0
5
mkarimi17
I have a search: | tstats count AS ThreeHourCount WHERE earliest=-2d@d latest=now index=* by index, _time span=3h ...
by mkarimi17 Path Finder in Splunk Search 08-09-2017
0 7
0
7
timyong80
Hello. I have two lookup files: Firecall.csvPrivileged.csv Both files contain a column with the same name; Account...
by timyong80 Explorer in Splunk Search 08-09-2017
0 2
0
2
splunk_95
Hi all, Having read a few similar threads I realised they do not quite ask what I need so decided to post a new thre...
by splunk_95 Explorer in Splunk Search 08-09-2017
1 14
1
14
prabu116
I have string like this 08Aug2017 10:12:55 CDT" I want date format like = 08-Aug-2017 10:12:55 CDT
by prabu116 Engager in Splunk Search 08-09-2017
0 6
0
6
Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...