Splunk Search

Splunk Search
Community Activity
mcvaylk
I'm using custom delimiters to extract fields from the logs of a rails app. Following the advice of an answer on thi...
by mcvaylk Engager in Splunk Search 07-17-2017
0 3
0
3
maximusdm
I need to create a query that will show all the cells from the table below which exceed 80%. Here is the query I w...
by maximusdm Communicator in Splunk Search 07-17-2017
0 2
0
2
maximusdm
giving the folowing scenario: ... | table Country City Population > Country City Population > ...
by maximusdm Communicator in Splunk Search 07-17-2017
0 2
0
2
ErikaE
I have dense sensor data (~75k events in a 3 week period) from multiple sensors that I would like to correlate to a s...
by ErikaE Communicator in Splunk Search 07-17-2017
0 4
0
4
davidb89
This Question is based on this question which solved my initial problem but created a new one. No matter which of thi...
by davidb89 Engager in Splunk Search 07-17-2017
0 5
0
5
mrb113
I'm trying to make a stacked column chart showing how users are changing some setting ("powerChanged") by build. Her...
by mrb113 Engager in Splunk Search 07-17-2017
0 4
0
4
alexandermunce
Hi, Our system logs events in a bizarre way in which multiple lines of data will all relate to a single transaction,...
by alexandermunce Communicator in Splunk Search 07-17-2017
0 4
0
4
matansocher
Hi, I am using sql query with dbquery to get data of an item from 2 different tables. In the first table I have the ...
by matansocher Contributor in Splunk Search 07-17-2017
0 1
0
1
prafulljha
Hi i have values in a column like AA(15), ABC(20), ADSF(90).Now i need a regular expression which gives me only value...
by prafulljha New Member in Splunk Search 07-17-2017
0 9
0
9
ddurio
I have a subset of users who should only be able to view data injected by themselves. To know the event in Splunk wa...
by ddurio Engager in Splunk Search 07-17-2017
1 3
1
3
danielsavage
So I have a search set up where I can find the cpu of a server for a given host. However, now I want to add an option...
by danielsavage New Member in Splunk Search 07-17-2017
0 6
0
6
HealyDPS
I had this search working and now it seems to have stopped gives an error. Thoughts? Search: index=symantec source...
by HealyDPS Explorer in Splunk Search 07-17-2017
0 7
0
7
jclehmuth
I keep receiving this error: The extraction failed. If you are extracting multiple fields, try removing one or more f...
by jclehmuth Path Finder in Splunk Search 07-17-2017
0 7
0
7
722624
SHOULD_LINEMERGE = true MAX_EVENTS = 99999 TRUNCATE = 9999999 SHOULD_LINEMERGE = false LINE_BREAKER = ((FAIL*)) I...
by 722624 Path Finder in Splunk Search 07-17-2017
0 7
0
7
tareddy
I am trying to obtain the DailyTransactions and WeeklyTranscations . The following is my Query -> index=INDEXA sourc...
by tareddy Explorer in Splunk Search 07-16-2017
0 3
0
3
iqbalintouch
Hi, Can anyone please help me to understand why I am seeing the results in a linear format and I can not see the res...
by iqbalintouch Path Finder in Splunk Search 07-16-2017
0 7
0
7
vikashnimoyle
index="windows_logins_test" LogName="Security" (EventCode=4624 AND EventCode!=4647) |table ComputerName when I set...
by vikashnimoyle New Member in Splunk Search 07-16-2017
0 2
0
2
kiran331
HI, How to extract the field user, action and src_ip from the below event? 05/31/2017 11:59:52 PM LogName=Applicatio...
by kiran331 Builder in Splunk Search 07-16-2017
0 3
0
3
vikasreddy
I need to extract the date from the file name,But the format of the data on different files are different for eg:D2...
by vikasreddy Explorer in Splunk Search 07-15-2017
0 7
0
7
rkaakaty
eventtype=qualys_vm_detection_event STATUS!="FIXED" | fillnull value=- PROTOCOL | dedup 1 HOST_ID, QID, PROTOCOL, ST...
by rkaakaty Path Finder in Splunk Search 07-15-2017
1 6
1
6
Rshekar19
I need to understand the backend search engine Splunk uses to retrieve the data instantly upon a search in the UI. Al...
by Rshekar19 New Member in Splunk Search 07-15-2017
0 1
0
1
GersonGarcia
All, I am running this search to build a drilldown panel in a dashboard: index=os "invoked oom-killer:" | eval stim...
by GersonGarcia Path Finder in Splunk Search 07-15-2017
0 4
0
4
cgaete
Hi, everyone When I create a field concatenated with eval, example: |eval date = day. "/" .month." /". year. | Can ...
by cgaete Explorer in Splunk Search 07-14-2017
0 3
0
3
kteng2024
Is there any way to find out the alerts and dashboards created like 5 months ago and with the respective user names?
by kteng2024 Path Finder in Splunk Search 07-14-2017
0 1
0
1
fcompagnari
I am trying to develop a search that can identify missing logs based on average of time between log entries for each ...
by fcompagnari New Member in Splunk Search 07-14-2017
0 6
0
6
Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors