Splunk Search

Splunk Search
Community Activity
raghu0463
im trying to write spl for one of the sql quires which has like declare variables and CTE tables im bit confused what...
by raghu0463 Explorer in Splunk Search 08-03-2017
0 13
0
13
andrewtrobec
Hello, I am currently using the following REGEX for PREAMBLE_REGEX in props.conf which works on Splunk 6.4.x running...
by andrewtrobec Motivator in Splunk Search 08-03-2017
0 2
0
2
bcarr12
Hi all, I am running a search that in some cases has: Field=Values In other cases, Field is completely missing from...
by bcarr12 Path Finder in Splunk Search 08-03-2017
0 3
0
3
ctallarico20
Hi, I'm looking for a way to run one summary index search on all files of the same sourcetype, and then identify indi...
by ctallarico20 Path Finder in Splunk Search 08-03-2017
1 2
1
2
jcorkey
My problem is that after I add my custom drilldown code and select an item in my results, it takes me to the specifi...
by jcorkey Explorer in Splunk Search 08-03-2017
0 3
0
3
O2Anthony
I'm an absolute Regex idiot. I'm sure this is easy if you know what you're doing. I have an IIS log file, which is w...
by O2Anthony New Member in Splunk Search 08-03-2017
0 2
0
2
iqbalintouch
I am running this query but not getting desired output. index=myapp sourcetype=log_source host="*myhost*" "Event*" A...
by iqbalintouch Path Finder in Splunk Search 08-03-2017
0 10
0
10
SathyaNarayanan
Hi, I have a field suser in my table, in that i have many values like Password Manager, Batcch , s4545 , Wb 5245 lik...
by SathyaNarayanan Path Finder in Splunk Search 08-03-2017
0 2
0
2
muralianup
I trying to write a query to check the changes in versions of a software. When using timechart (stacked) I can see mu...
by muralianup Communicator in Splunk Search 08-03-2017
0 5
0
5
arielpconsolaci
Hi fellow Splunkers. I have a scenario where my query that I want to show as a Single Value displays differently whe...
by arielpconsolaci Path Finder in Splunk Search 08-03-2017
0 4
0
4
alebaffajp
Hi, I am very new to Splunk and I would like to make a graph that shows the average value of response_time over the t...
by alebaffajp Engager in Splunk Search 08-03-2017
0 2
0
2
Mtakahashi
Dear all, I need to search all XML tagged data including nested data but I only get first data by a search command. ...
by Mtakahashi Path Finder in Splunk Search 08-02-2017
0 7
0
7
bandit
I would like to display a table of all occurrences of a change to the value of a field over a period of time. i.e. la...
by bandit Motivator in Splunk Search 08-02-2017
2 7
2
7
diliphg
I am fairly new to Splunk queries. I have below mentioned logs: INFO [HTTP-120]: 2017-08-02T18:00:03,157 - transac...
by diliphg New Member in Splunk Search 08-02-2017
0 2
0
2
shanyour
I have an event with a text spans over multiple lines. it has no key-value pattern. the body string has a uuid value....
by shanyour New Member in Splunk Search 08-02-2017
0 1
0
1
AditiKhare
Hi, I am very new to splunk and wanted to know if someone can help me in groping columns fo rmy query below : source...
by AditiKhare Explorer in Splunk Search 08-02-2017
0 7
0
7
ssyed2009
Base users are unable to get results of the search. As an Admin, I am able to view the data. Search is below. I can q...
by ssyed2009 New Member in Splunk Search 08-02-2017
0 5
0
5
saadmalik83
Hello All, I am having an issue after upgrading our ES app from 4.0.0 to 4.5.2. Currently i am not getting the event...
by saadmalik83 New Member in Splunk Search 08-02-2017
0 1
0
1
raghu0463
Do i need to create separate db input for each table we are loading data from sql server into splunk
by raghu0463 Explorer in Splunk Search 08-02-2017
0 3
0
3
patelaa
I have a lookup table with user data called id_lookup.csv username,hostname,ip user1,computer1,1.1.1.1 user2,compute...
by patelaa Explorer in Splunk Search 08-02-2017
0 3
0
3
kmaron
I keep going around in circles with this and I'm getting nowhere so I'm asking for help. My events look like this: ...
by kmaron Motivator in Splunk Search 08-02-2017
0 4
0
4
DEAD_BEEF
I apologize as I feel I am missing something very basic, but for the life of me I cannot get this query to work. I h...
by DEAD_BEEF Builder in Splunk Search 08-02-2017
0 3
0
3
puneethgowda
sourcetype=XyzProd blacklist = MethodExecutionInfo(\d{8})-(\d{2}).txt|DebugInfo(\d{8})-(\d{2}).txt|CacheRefreshInfo(...
by puneethgowda Communicator in Splunk Search 08-02-2017
0 1
0
1
jofermin
After I transpose my timechart, I'm getting 3 fields under my Column that I want to get rid of: _span, _spandays, and...
by jofermin Explorer in Splunk Search 08-02-2017
0 3
0
3
wvalente
Hi Guys, I need to create an alert that returns the creation time of an account and the first login. How can I run ...
by wvalente Explorer in Splunk Search 08-02-2017
0 2
0
2
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...