Splunk Search

Splunk Search
Community Activity
curry59
Hello, Normally, I would use the following search to find my single value: | tstats latest(_time) as latest where ...
by curry59 New Member in Splunk Search 06-20-2017
0 1
0
1
deepak_dhankhar
need to evaluate the duration of last time user logged in and time now. problem I am facing is in lastTime I am getti...
by deepak_dhankhar Explorer in Splunk Search 06-20-2017
0 8
0
8
gcusello
Hi at all, I have a situation where there are around 10 users that need to use for their job two o three dashboards c...
by SplunkTrust SplunkTrust in Splunk Search 06-20-2017
0 2
0
2
ugy
Hello Team, I'd like to know about How to use inner search in tstats? I use that | tstats count from datamodel=IT...
by ugy Explorer in Splunk Search 06-20-2017
0 2
0
2
HeinzWaescher
Hi, I did not know that it is possible: | makeresults | eval fieldA=123, fieldB=456, fieldC=789 I assume that thi...
by HeinzWaescher Motivator in Splunk Search 06-20-2017
0 5
0
5
DataOrg
Modify:extended value attribut -"to be processed";Action:"will not be processed";Modify:attributs to be processed-"he...
by DataOrg Builder in Splunk Search 06-20-2017
0 1
0
1
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm trying to create a query which extracts given values...
by IRHM73 Motivator in Splunk Search 06-20-2017
0 1
0
1
m7787580
Hi Splunker, I would like to know and learn how to replace ^ns4: with < Please find below dummy data. ^ns4:Channel...
by m7787580 Explorer in Splunk Search 06-20-2017
1 7
1
7
karthi2809
rex field=_raw "MemoryUsage %(?<MemoryUtilization>[^']+)"MY result is------------ 41.4 expected result41.4 
by karthi2809 Builder in Splunk Search 06-20-2017
0 3
0
3
4myexperiment
I am looking for help to extract the values from my log files my log file has a sequence of data as follows 1.){xxx...
by 4myexperiment Explorer in Splunk Search 06-19-2017
0 2
0
2
prathapkcsc
Hi, I have a event with the column names like Type Category Count CPU in my event 1st line. I don...
by prathapkcsc Explorer in Splunk Search 06-19-2017
0 14
0
14
patilsh
Hello All, I have a data as below : Where for every callId there are list of values in next column. So I have some 1...
by patilsh Explorer in Splunk Search 06-19-2017
0 5
0
5
snehasal
Hi Everyone, I am a newbie to Splunk and need little help with the alerting system. I want to setup a real time aler...
by snehasal Explorer in Splunk Search 06-19-2017
0 2
0
2
dxw350
if I want to remove one IP address and then do a wildcard search, would that wildcard host IP search override the rem...
by dxw350 Path Finder in Splunk Search 06-19-2017
0 3
0
3
cvalenti
I have this search: index="tticket_contact_request" |eval date=strftime(_time, "%Y-%m") |stats count by des...
by cvalenti Explorer in Splunk Search 06-19-2017
0 4
0
4
rubyboomslang
Psuedocode: If dashboard token is empty, run X search. If token is not empty, run Y search. if($field$ is omitted)...
by rubyboomslang New Member in Splunk Search 06-19-2017
0 1
0
1
fooflington
I would like to record a user's department at the time of the event rather than search time. I have username => depar...
by fooflington New Member in Splunk Search 06-19-2017
0 3
0
3
niamurph
I use the following query in an attempt to view a subset of the file test10UniqueActiveUsers.csv |inputlookup test1...
by niamurph Explorer in Splunk Search 06-19-2017
0 7
0
7
vikram_m
From the log mentioned below I need to extract the field 'Response Time' and then frame a query for response time < 1...
by vikram_m Path Finder in Splunk Search 06-19-2017
0 4
0
4
DataOrg
followed the escaped error: "An error has happened executing a dash statement. hello good morning followed the escape...
by DataOrg Builder in Splunk Search 06-19-2017
0 3
0
3
pxs0514
I have a series of eval statements that I'd like to call from multiple dashboards, but have it coded in only one plac...
by pxs0514 Explorer in Splunk Search 06-19-2017
1 3
1
3
R0ss
Hello, I'm having trouble grouping errors in our Splunk logs. The date and time is appended to the error messages, m...
by R0ss Engager in Splunk Search 06-19-2017
0 2
0
2
aramirez_evolut
Tools such as graphite allow for the concept of "infinity" in charts in order to display vertical lines to be overlay...
by aramirez_evolut Engager in Splunk Search 06-19-2017
13 6
13
6
bowesmana
I have a field called Title, where it may sometimes end with the text Ends 9 P.M. or varying case related variant...
by SplunkTrust SplunkTrust in Splunk Search 06-19-2017
0 8
0
8
remoharish
I am looking for a solution to show for every latest event time and previous event time average duration (and the tim...
by remoharish Engager in Splunk Search 06-19-2017
0 1
0
1
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...