Splunk Search

Splunk Search
Community Activity
iqbalintouch
I am running this query but not getting desired output. index=myapp sourcetype=log_source host="*myhost*" "Event*" A...
by iqbalintouch Path Finder in Splunk Search 08-03-2017
0 10
0
10
SathyaNarayanan
Hi, I have a field suser in my table, in that i have many values like Password Manager, Batcch , s4545 , Wb 5245 lik...
by SathyaNarayanan Path Finder in Splunk Search 08-03-2017
0 2
0
2
muralianup
I trying to write a query to check the changes in versions of a software. When using timechart (stacked) I can see mu...
by muralianup Communicator in Splunk Search 08-03-2017
0 5
0
5
arielpconsolaci
Hi fellow Splunkers. I have a scenario where my query that I want to show as a Single Value displays differently whe...
by arielpconsolaci Path Finder in Splunk Search 08-03-2017
0 4
0
4
alebaffajp
Hi, I am very new to Splunk and I would like to make a graph that shows the average value of response_time over the t...
by alebaffajp Engager in Splunk Search 08-03-2017
0 2
0
2
Mtakahashi
Dear all, I need to search all XML tagged data including nested data but I only get first data by a search command. ...
by Mtakahashi Path Finder in Splunk Search 08-02-2017
0 7
0
7
bandit
I would like to display a table of all occurrences of a change to the value of a field over a period of time. i.e. la...
by bandit Motivator in Splunk Search 08-02-2017
2 7
2
7
diliphg
I am fairly new to Splunk queries. I have below mentioned logs: INFO [HTTP-120]: 2017-08-02T18:00:03,157 - transac...
by diliphg New Member in Splunk Search 08-02-2017
0 2
0
2
shanyour
I have an event with a text spans over multiple lines. it has no key-value pattern. the body string has a uuid value....
by shanyour New Member in Splunk Search 08-02-2017
0 1
0
1
AditiKhare
Hi, I am very new to splunk and wanted to know if someone can help me in groping columns fo rmy query below : source...
by AditiKhare Explorer in Splunk Search 08-02-2017
0 7
0
7
ssyed2009
Base users are unable to get results of the search. As an Admin, I am able to view the data. Search is below. I can q...
by ssyed2009 New Member in Splunk Search 08-02-2017
0 5
0
5
saadmalik83
Hello All, I am having an issue after upgrading our ES app from 4.0.0 to 4.5.2. Currently i am not getting the event...
by saadmalik83 New Member in Splunk Search 08-02-2017
0 1
0
1
raghu0463
Do i need to create separate db input for each table we are loading data from sql server into splunk
by raghu0463 Explorer in Splunk Search 08-02-2017
0 3
0
3
patelaa
I have a lookup table with user data called id_lookup.csv username,hostname,ip user1,computer1,1.1.1.1 user2,compute...
by patelaa Explorer in Splunk Search 08-02-2017
0 3
0
3
kmaron
I keep going around in circles with this and I'm getting nowhere so I'm asking for help. My events look like this: ...
by kmaron Motivator in Splunk Search 08-02-2017
0 4
0
4
DEAD_BEEF
I apologize as I feel I am missing something very basic, but for the life of me I cannot get this query to work. I h...
by DEAD_BEEF Builder in Splunk Search 08-02-2017
0 3
0
3
puneethgowda
sourcetype=XyzProd blacklist = MethodExecutionInfo(\d{8})-(\d{2}).txt|DebugInfo(\d{8})-(\d{2}).txt|CacheRefreshInfo(...
by puneethgowda Communicator in Splunk Search 08-02-2017
0 1
0
1
jofermin
After I transpose my timechart, I'm getting 3 fields under my Column that I want to get rid of: _span, _spandays, and...
by jofermin Explorer in Splunk Search 08-02-2017
0 3
0
3
wvalente
Hi Guys, I need to create an alert that returns the creation time of an account and the first login. How can I run ...
by wvalente Explorer in Splunk Search 08-02-2017
0 2
0
2
vshakur
I have a query that ends with: | chart count by suite_name, status suite_name consists of many events with a sta...
by vshakur Path Finder in Splunk Search 08-02-2017
0 2
0
2
ananthan123
Hello, All of the sudden we have some uncertain usage and trying to under the usage, here are the same lines .... ...
by ananthan123 Explorer in Splunk Search 08-02-2017
0 1
0
1
smuderasi
host=dummy | eval Pattern='arb_usg_mps%06' | where like (source,'%Pattern%') doesnot work . can you help what's wro...
by smuderasi Explorer in Splunk Search 08-02-2017
0 2
0
2
jcorkey
I am receiving the audit.log data from a universal forwarder running on a Linux box Hello below is my search string ...
by jcorkey Explorer in Splunk Search 08-02-2017
0 1
0
1
jcorkey
trying to search for when sudo user1 adds user2 to a group and I want to extract the name of the user2 that was added...
by jcorkey Explorer in Splunk Search 08-02-2017
0 1
0
1
lim2
Want to label sc_status <= 304 as Ok and sc_status >= 400 as Error and get the Ok and Error counts and table the clie...
by lim2 Communicator in Splunk Search 08-02-2017
0 1
0
1
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...