Splunk Search

Splunk Search
Community Activity
ewise1
Hi, I have a date that comes in as part of a string, and it looks like "Jun 28 11:50:23 2017". How can I convert thi...
by ewise1 New Member in Splunk Search 06-28-2017
0 3
0
3
jhayIV
index=### sourcetype=####|table Server Server AppName AppProductName _time ServerRole ServerSerialNumber ServerSite |...
by jhayIV Engager in Splunk Search 06-28-2017
0 1
0
1
draracle
I have a search that returns a list with user,dc(Country),values(Country),values(src) I would like to only show resu...
by draracle Engager in Splunk Search 06-28-2017
0 1
0
1
davesplunk01
How to populate the timechart based on the input dropdown (avg, max, min, perc90). looking something like .......|...
by davesplunk01 Path Finder in Splunk Search 06-28-2017
0 1
0
1
wessam
I am facing an issue with fields command as i am generating splunk queries below .....)|fields - records2,records ...
by wessam Explorer in Splunk Search 06-28-2017
2 17
2
17
anushaashok
here is my query : index="test1" sourcetype="test2" "login success*" OR "login failed*" | timechart span=1d dc(user) ...
by anushaashok New Member in Splunk Search 06-28-2017
0 4
0
4
kennyja
I am a complete newbie to Splunk. I have an environment in which users are set "token mandatory" by default for PKI ...
by kennyja Explorer in Splunk Search 06-28-2017
0 3
0
3
carmackd
This morning I woke up to a "too many jobs in dispatch directory" message across my screen. After checking dispatch,...
by carmackd Communicator in Splunk Search 06-28-2017
3 3
3
3
abhinav_maxonic
When I sort my data by some field, by default its has limit of 10,000 rows. If I use attribute count=0 along with sor...
by abhinav_maxonic Path Finder in Splunk Search 06-27-2017
1 5
1
5
exocore123
manipulating strings, I had a post before regarding an array, but say I have a field that has value string1+string2+s...
by exocore123 Path Finder in Splunk Search 06-27-2017
0 8
0
8
gvnd
Hi, I am new to splunk.. I want to filter data at fields level instead of event levels before indexing my data. data...
by gvnd Path Finder in Splunk Search 06-27-2017
0 5
0
5
Svill321
Hello everyone, Basically exactly what the title says. I made a white list of approved accounts and would like to a...
by Svill321 Path Finder in Splunk Search 06-27-2017
0 3
0
3
synsoc
The idea is my hosts will write a status message to a log file that gets picked up by Splunk and put into a shared in...
by synsoc New Member in Splunk Search 06-27-2017
0 2
0
2
exocore123
I have a field in my logs that contains an array of string elements. Is there a way to detect for repeating strings a...
by exocore123 Path Finder in Splunk Search 06-27-2017
0 12
0
12
sieutruc
Hello, When i trigger a search like: host="win20_oslo-ifs_CC-DC" index="sqlobj" | multikv | eval BusinessEpoch=strp...
by sieutruc Contributor in Splunk Search 06-27-2017
0 4
0
4
ctripod
I have a bit of a tricky one here. I have a search which leverages an automatic lookup. One of the output fields ...
by ctripod Explorer in Splunk Search 06-27-2017
0 6
0
6
exocore123
I have a dashboard with a range of aggregation span from 1h, 1d, 7d, 1mon. And I want to change how timestamp is disp...
by exocore123 Path Finder in Splunk Search 06-27-2017
0 3
0
3
macadminrohit
LogName=Application SourceName=Oracle EventCode=0 EventType=2 Type=Error ComputerName=server1.xxx.ds.abcde.com TaskCa...
by macadminrohit Contributor in Splunk Search 06-27-2017
0 2
0
2
stephenmoorhous
I have a list of log lines which indicate an order has been placed and have a session id (sid) but no customer id (ci...
by stephenmoorhous Path Finder in Splunk Search 06-27-2017
0 1
0
1
cheyenne15
I am looking to create a search looks at after hour activities. How would you search for events from yesterday begin...
by cheyenne15 New Member in Splunk Search 06-27-2017
0 4
0
4
ericyeh1995
I would like to calculate the accumulated energy used over a period of 15 minutes. The sum has to start around min%15...
by ericyeh1995 Explorer in Splunk Search 06-27-2017
0 5
0
5
kmaron
I have a dashboard that has way too many searches on it so I was trying to split it up using a base search and the po...
by kmaron Motivator in Splunk Search 06-27-2017
1 6
1
6
aamelyan
I have a search defined like this for the alert | dbxquery connection=MyDB query=usp_Splunk_GetDataForAlert shortnam...
by aamelyan Explorer in Splunk Search 06-26-2017
0 1
0
1
pbugeja
Hi, I am very new with Regex and have been struggling with simple task. I need to change three values (Health, Audi...
by pbugeja New Member in Splunk Search 06-26-2017
0 24
0
24
jampar12
I'm new to Splunk and I have the Search where I check one Server for 7 Services and State=Stopped and run a st...
by jampar12 New Member in Splunk Search 06-26-2017
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors