Splunk Search

Splunk Search
Community Activity
kteng2024
index=abc source=license_usage.log type=usage | rex field=h "(ab2)(?P\w+[^\d+])" |search Group=kb01m OR Group=kb02r ...
by kteng2024 Path Finder in Splunk Search 07-25-2017
0 4
0
4
manderson7
I've been banging my head against the wall trying to get this to work, and not succeeding, obviously. I have a 217 li...
by manderson7 Contributor in Splunk Search 07-25-2017
0 2
0
2
mdsnmss
I have a user who is receiving the error: No matching fields exist [subsearch]: The lookup table <-lookup>.csv is i...
by SplunkTrust SplunkTrust in Splunk Search 07-25-2017
0 3
0
3
Kieffer87
We've recently run into some users that have run searches which resulted in Splunk Indexers crashing. I'm looking for...
by Kieffer87 Communicator in Splunk Search 07-25-2017
0 4
0
4
mdwasimkhan
Hi All, I am looking for a query which will accept multiple value subsearch output as a input of main serach, See be...
by mdwasimkhan Engager in Splunk Search 07-25-2017
0 5
0
5
dahada2010
Data received from universal forwarder is displaying as below. Please advise how to get it as normal text. --splunk-...
by dahada2010 New Member in Splunk Search 07-25-2017
0 5
0
5
wvalente
Hi, I want to run a search that alert me when a user is created and deleted in a period of time between 72 hours and...
by wvalente Explorer in Splunk Search 07-25-2017
0 2
0
2
davidda
Hi, I want to create a new field named "RequestId" from the data after "channelRequestId:" field using regex. This i...
by davidda Explorer in Splunk Search 07-25-2017
1 2
1
2
manjuase
I have a lookup with the details of server and I want to check whether that servers are up or not. if not i have to ...
by manjuase Explorer in Splunk Search 07-25-2017
1 5
1
5
oolongcat
Hi Splunk support, I have a set of log file which name as below: (today is 20170723) application_20170721.log appli...
by oolongcat New Member in Splunk Search 07-25-2017
0 3
0
3
honobe
I would like to compare the two logs and output the attachment file name to the alert if it is the same message ID. ...
by honobe Explorer in Splunk Search 07-25-2017
0 6
0
6
aab5272
I have to discard keyvalue pair from a event to null queue during index time extraction .Also there are certain key v...
by aab5272 Engager in Splunk Search 07-24-2017
0 4
0
4
jpaulovich
Hi and Thanks .. I've been researching and trying methods to do this (even tried timewrap) and am (finally) asking f...
by jpaulovich Explorer in Splunk Search 07-24-2017
0 6
0
6
Kozanic
I'm trying to set up a drill down report that will list the events of a transaction, but having issue getting the dat...
by Kozanic Path Finder in Splunk Search 07-24-2017
0 5
0
5
esweeney
Is there a search command for Splunk that will find the oldest event in the index for a host faster than letting a fu...
by esweeney Splunk Employee Splunk Employee in Splunk Search 07-24-2017
2 4
2
4
scc00
I am attempting to track user activity from vdi login to the use of a shared account to log into an application. For ...
by scc00 Contributor in Splunk Search 07-24-2017
0 7
0
7
rockyrush
I have tried head 100, but it seems like it does a regular search and then gives me 100 results because it takes the ...
by rockyrush Explorer in Splunk Search 07-24-2017
0 4
0
4
deepak02
Hi, WHAT I NEED : Formula to calculate perc95 of responseTime WHAT I HAVE: I have a summary index which gives the b...
by deepak02 Path Finder in Splunk Search 07-24-2017
0 3
0
3
mhtedford
I have two graphs. The first shows the number of survey responses by week: Here is the search: index=webex_sentime...
by mhtedford Communicator in Splunk Search 07-24-2017
0 6
0
6
drizzo
When I enter In my the following into my Search... index=* host=* sourcetype="Perfmon"Memory" collection=Memory o...
by drizzo Path Finder in Splunk Search 07-24-2017
0 1
0
1
rookie507SL
Hi guys, I'm figuring out which steps should I follow in order to perform a lookup between a url field and a url col...
by rookie507SL New Member in Splunk Search 07-24-2017
0 7
0
7
mrccasi
Hi. Is it possible to add port 1521 so that Splunk can connect to database? Thank you.
by mrccasi Explorer in Splunk Search 07-24-2017
0 3
0
3
ronaldlb80
Hi, We have MPLS connection and all our offices are getting the internet from our main office. What I want to see i...
by ronaldlb80 Engager in Splunk Search 07-24-2017
0 7
0
7
wegscd
I have a search yielding a series of events: 2017-05-15 68.222609 2017-05-16 68.243478 2017-05-17 68.276522 2017-...
by wegscd Contributor in Splunk Search 07-24-2017
0 7
0
7
jrprez1804
We have a script that pulls the disk info than the Universalforwarder reads the data and send to Splunk. With the que...
by jrprez1804 Path Finder in Splunk Search 07-24-2017
0 2
0
2
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors