Splunk Search

Splunk Search
Community Activity
remoharish
I am looking for a solution to show for every latest event time and previous event time average duration (and the tim...
by remoharish Engager in Splunk Search 06-19-2017
0 1
0
1
DataOrg
The value '20/SEP/13' can removed The hello '28/JUN/14' can be removed The today '23/JUN/14' can be removed
by DataOrg Builder in Splunk Search 06-19-2017
0 6
0
6
dxw350
In order to coincide with an excel spreadsheet, I was hoping that Splunk table can provide two columns that our ident...
by dxw350 Path Finder in Splunk Search 06-18-2017
0 2
0
2
t_splunk_d
I am searching on an event with has on an average 25000 - 30000 characters. When I search on the auto extracted field...
by t_splunk_d Path Finder in Splunk Search 06-18-2017
0 7
0
7
mbond81
Bonus points to the folks who can help me. I'm trying to first filter (stats count) results above a threshold of 100 ...
by mbond81 Engager in Splunk Search 06-17-2017
0 8
0
8
prathapkcsc
Hi, i have a sample data file like this, all columns are tab separated TYPE Category ...
by prathapkcsc Explorer in Splunk Search 06-16-2017
0 15
0
15
roayers
i have an odd issue that i cant seem to get beyond it might be as simple as a regex change but I can seem to figure i...
by roayers Explorer in Splunk Search 06-16-2017
0 16
0
16
Chamrong
We have small lookup updated in search by outputlookup append=true This is a SMALL size Our users noticed the lookup ...
by Chamrong Explorer in Splunk Search 06-16-2017
0 6
0
6
timyong80
Hello guys, I'm having a bit of problem removing spaces in between several words in a column. For example, the User_...
by timyong80 Explorer in Splunk Search 06-16-2017
0 10
0
10
curry59
Hello, I recently setup a summary index. I'm searching with "tstats" in that summary index to get a single integer ...
by curry59 New Member in Splunk Search 06-16-2017
0 1
0
1
dxw350
In Vlookup for excel, the input is always the first column on the left. In Splunk, is this required? I am having di...
by dxw350 Path Finder in Splunk Search 06-16-2017
0 2
0
2
jkfierro
I have: sourcetype=squid_proxy | stats count, values(url) as url, sum(bytes) as bytes by client_ip Which almost ge...
by jkfierro Explorer in Splunk Search 06-16-2017
0 7
0
7
jephillips
Why would these searches return different results? I'm searching over the same time range with both. index=main sour...
by jephillips Explorer in Splunk Search 06-16-2017
0 8
0
8
andimak
Hi, I have events which look like that: a=test1 b=test2 func=test3|test4|test5 and a=test1 b=test2 func=test5 if a ...
by andimak New Member in Splunk Search 06-16-2017
0 1
0
1
aohls
I have for example something as follows, "Request X|Y|Z" where X, Y, and Z all change each time the message is displa...
by aohls Contributor in Splunk Search 06-16-2017
0 5
0
5
mehala12
Hello friends, My data is in json format and i have credit card info which i need to mask at indexer level. I tried b...
by mehala12 Explorer in Splunk Search 06-15-2017
0 6
0
6
bowesmana
I have a row in a table called DMPrice <set token="dmp">$row.DMPrice$</set> this works, however, if there is no DM...
by SplunkTrust SplunkTrust in Splunk Search 06-15-2017
0 2
0
2
rakshithreddy
Hi all I am trying to do the following search. which would result in Top 5 apiname values along with their apitime(a...
by rakshithreddy Explorer in Splunk Search 06-15-2017
0 4
0
4
AshimaE
I have multiple hosts in my result table and there is no specific sampling interval for each. However it is sure that...
by AshimaE Explorer in Splunk Search 06-15-2017
0 3
0
3
Esky73
Looking for ideas on how to correlate between an updown trap event like the one shown below - would be nice to have t...
by Esky73 Builder in Splunk Search 06-15-2017
0 1
0
1
jw44250
My Splunk Query index= index1 sourceType=source1 "Error" OR requestURl != "/test/abc" OR requestURI != "/person" ...
by jw44250 New Member in Splunk Search 06-15-2017
0 4
0
4
jw44250
My search result is like this : result 1 . message hello test helo test result 2 . message hello test helo tes...
by jw44250 New Member in Splunk Search 06-15-2017
0 13
0
13
nvegesn222
hi, from 1 search i got below results. txn ref no |amount|date and another search got the below. acct no|txn ref...
by nvegesn222 New Member in Splunk Search 06-15-2017
0 2
0
2
lordhans
I have two searches something like this: "ns=my_project" message="*RESPONSE_CODE=200*" OR "*RESPONSE_CODE=400*" METH...
by lordhans Explorer in Splunk Search 06-15-2017
0 2
0
2
crazyeva
Splunk can extract fields when events contain "key=value" strings Could I tell splunk to extract fields automatically...
by crazyeva Contributor in Splunk Search 06-15-2017
0 6
0
6
Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...