Splunk Search

Splunk Search
Community Activity
mlevsh
We have multisite indexer cluster: two sites, 4 indexers per site (Splunk v. 6.5.3) Few months ago, following Splunk'...
by mlevsh Builder in Splunk Search 06-30-2017
0 1
0
1
ribeiror
Hi I have a search that needs to search in several indexes ending with several words, ex: index=stuff-xxx or index=...
by ribeiror Engager in Splunk Search 06-30-2017
0 4
0
4
EricLloyd79
Hello we are using Hunk and when we just run a query such as: index=foo sourcetype=bar we get the results easily But...
by EricLloyd79 Builder in Splunk Search 06-30-2017
0 2
0
2
yurykiselev
Hi! _time | id | exam_type | avg_reaction_time Patients pass several types of exams (exam_a, exam_b, exam_c...). E...
by yurykiselev Path Finder in Splunk Search 06-30-2017
0 4
0
4
kisfoldik
This is a typical relevant line from logs: [28/Jun/2017:07:26:04 -0400] conn=9354 op=7 msgId=8 - SRCH base="o=compan...
by kisfoldik Explorer in Splunk Search 06-30-2017
0 11
0
11
sumitkathpal
Dear Experts, Request you help to convert this below query into tstats query. index=network_proxy category="Persona...
by sumitkathpal Explorer in Splunk Search 06-30-2017
0 1
0
1
byapici
Hello, I was created new search term, but it not worked, my example; sourcetype=xxxxx earliest=01/01/2017 12:00:0...
by byapici New Member in Splunk Search 06-30-2017
0 3
0
3
rajpalyalla
Hi, How can we fetch all the occurence of GC which is greater than 300. we have some thing like below in logs. we w...
by rajpalyalla Engager in Splunk Search 06-29-2017
0 7
0
7
KrutikaDe
Hi, I am trying to extract error message and error code from logs in Splunk. I can see 2 patterns of these- pattern...
by KrutikaDe New Member in Splunk Search 06-29-2017
0 3
0
3
wuming79
I converted my timeStampLight with strftime() but all my time was formatted to 31-12-9999 23:59:59 when I table time ...
by wuming79 Path Finder in Splunk Search 06-29-2017
0 3
0
3
newbie2tech
Hi Team, Need your help with Regex to extract key value pairs. Below is sample event 2017-06-27 14:35:38.000 INFO ...
by newbie2tech Communicator in Splunk Search 06-29-2017
0 2
0
2
DataOrg
StpExfdsec Crsfseate 4 00fsdfsdggf93e1132:116fgsfs7575 2017-06-20 21:20:09 institat step definition 'Error maint...
by DataOrg Builder in Splunk Search 06-29-2017
0 2
0
2
sumanssah
Hello All, Need assistance in regex creation. I want to remove every thing before an character. Example: /REGISTR...
by sumanssah Communicator in Splunk Search 06-29-2017
0 2
0
2
exocore123
I have a bunch of log error descriptions that have unique IDs at the end of the sentences "CC declined. 123" 1 "...
by exocore123 Path Finder in Splunk Search 06-29-2017
0 11
0
11
mrtolu6
I'm trying to do a stats command to find a count of any value less than 2 counts and display all the other fields. I...
by mrtolu6 Path Finder in Splunk Search 06-29-2017
0 1
0
1
gagandeep_arora
I am looking out for a search query to fire on my search head: My intention is to find all the dashboards / reports ...
by gagandeep_arora Path Finder in Splunk Search 06-29-2017
0 5
0
5
howardroark
I am trying to plot a timechart with a the following index="ABC" cs_uri_stem = "XYZ" | timechart eval( if(match(cs_...
by howardroark Explorer in Splunk Search 06-29-2017
0 4
0
4
rkaakaty
Hello, My chart for some reason, isn't displaying the value "high" and it has the high count at the bottom of the gr...
by rkaakaty Path Finder in Splunk Search 06-29-2017
0 3
0
3
sheltomt
Background is that I'm trying to pull in LDAP full names in from one search, and match that to UID from another searc...
by sheltomt Path Finder in Splunk Search 06-29-2017
0 7
0
7
paimonsoror
Hi folks; I have the following query that i use as a base search to feed a dashboard: index=app_caspectrum sourcety...
by paimonsoror Builder in Splunk Search 06-29-2017
0 3
0
3
psangli
For example Name Code Pool Name1 100 p1 57 p32 ...
by psangli Explorer in Splunk Search 06-29-2017
0 3
0
3
benjamincortega
With log data as such: date_time server=server1 group=group1 status=statusA date_time server=server2 group=group1 st...
by benjamincortega New Member in Splunk Search 06-29-2017
0 2
0
2
GenericSplunkUs
I'm trying to replace the contents of a field to the severity based on the number (I.E. 0 to 19 with Low, 20 to 39 wi...
by GenericSplunkUs Path Finder in Splunk Search 06-29-2017
0 2
0
2
ewise1
Hi, I have a string date format that shows up when I do a search; what I did was did a field extraction and named th...
by ewise1 New Member in Splunk Search 06-29-2017
0 10
0
10
jhayIV
Is there a way to divide the addcoltotals from each case statement in the following : eval daysclass=case( NoOfDays<...
by jhayIV Engager in Splunk Search 06-29-2017
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...