Splunk Search

Splunk Search
Community Activity
gdigrego
Hello, I'm in a distributed/cluster scenario (SH, Indexers, ...) and would like to route events in different indexes...
by gdigrego Path Finder in Splunk Search 08-03-2017
0 11
0
11
katzr
I have a table that has UserID, device, and classification (1,2,3). A UserID can have multiple devices and a device c...
by katzr Path Finder in Splunk Search 08-03-2017
0 1
0
1
sjcoluccio67
I have a search query that finds users whose accounts have been locked out and then sends them an email saying so. Th...
by sjcoluccio67 Explorer in Splunk Search 08-03-2017
0 1
0
1
jofermin
I'm attempting to add a Sparkline to my transposed, timechart statistics table. I read that sparkline only works for ...
by jofermin Explorer in Splunk Search 08-03-2017
0 1
0
1
gabarrygowin
Hello all, First thanks for the participation in this forum, many of your older solutions have helped greatly in my ...
by gabarrygowin Path Finder in Splunk Search 08-03-2017
0 12
0
12
unsmoker
I have 2 tables with energy spent values by month of years, one for 2015 other for 2016. Can I put two table values i...
by unsmoker New Member in Splunk Search 08-03-2017
0 1
0
1
g038123
Hello, Hoping for some help with this. We have a Dashboard that was working, at least that's what I was told, one o...
by g038123 Explorer in Splunk Search 08-03-2017
0 11
0
11
amitca
I have a data set with columns FY15, FY16, FY17 and say FY18, now based on time of execution of query i need to fetc...
by amitca New Member in Splunk Search 08-03-2017
0 4
0
4
mpuckettsc
Looking on advice on how to use a inputlookup table value as a raw search string and still be able to include that va...
by mpuckettsc Explorer in Splunk Search 08-03-2017
1 4
1
4
ayushdimri
I have a simple query like below, where I am looking for tickets created by a group of people and then passing it to ...
by ayushdimri New Member in Splunk Search 08-03-2017
0 9
0
9
slgizmo
I am working on creation of a dash board that consists of the following search and it does function and return the in...
by slgizmo Explorer in Splunk Search 08-03-2017
0 11
0
11
raghu0463
im trying to write spl for one of the sql quires which has like declare variables and CTE tables im bit confused what...
by raghu0463 Explorer in Splunk Search 08-03-2017
0 13
0
13
andrewtrobec
Hello, I am currently using the following REGEX for PREAMBLE_REGEX in props.conf which works on Splunk 6.4.x running...
by andrewtrobec Motivator in Splunk Search 08-03-2017
0 2
0
2
bcarr12
Hi all, I am running a search that in some cases has: Field=Values In other cases, Field is completely missing from...
by bcarr12 Path Finder in Splunk Search 08-03-2017
0 3
0
3
ctallarico20
Hi, I'm looking for a way to run one summary index search on all files of the same sourcetype, and then identify indi...
by ctallarico20 Path Finder in Splunk Search 08-03-2017
1 2
1
2
jcorkey
My problem is that after I add my custom drilldown code and select an item in my results, it takes me to the specifi...
by jcorkey Explorer in Splunk Search 08-03-2017
0 3
0
3
O2Anthony
I'm an absolute Regex idiot. I'm sure this is easy if you know what you're doing. I have an IIS log file, which is w...
by O2Anthony New Member in Splunk Search 08-03-2017
0 2
0
2
iqbalintouch
I am running this query but not getting desired output. index=myapp sourcetype=log_source host="*myhost*" "Event*" A...
by iqbalintouch Path Finder in Splunk Search 08-03-2017
0 10
0
10
SathyaNarayanan
Hi, I have a field suser in my table, in that i have many values like Password Manager, Batcch , s4545 , Wb 5245 lik...
by SathyaNarayanan Path Finder in Splunk Search 08-03-2017
0 2
0
2
muralianup
I trying to write a query to check the changes in versions of a software. When using timechart (stacked) I can see mu...
by muralianup Communicator in Splunk Search 08-03-2017
0 5
0
5
arielpconsolaci
Hi fellow Splunkers. I have a scenario where my query that I want to show as a Single Value displays differently whe...
by arielpconsolaci Path Finder in Splunk Search 08-03-2017
0 4
0
4
alebaffajp
Hi, I am very new to Splunk and I would like to make a graph that shows the average value of response_time over the t...
by alebaffajp Engager in Splunk Search 08-03-2017
0 2
0
2
Mtakahashi
Dear all, I need to search all XML tagged data including nested data but I only get first data by a search command. ...
by Mtakahashi Path Finder in Splunk Search 08-02-2017
0 7
0
7
bandit
I would like to display a table of all occurrences of a change to the value of a field over a period of time. i.e. la...
by bandit Motivator in Splunk Search 08-02-2017
2 7
2
7
diliphg
I am fairly new to Splunk queries. I have below mentioned logs: INFO [HTTP-120]: 2017-08-02T18:00:03,157 - transac...
by diliphg New Member in Splunk Search 08-02-2017
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...