Splunk Search

Splunk Search
Community Activity
santosh_hb
Hi All, I need help in creating time chart for the following request: I have a field by name field.status that will ...
by santosh_hb Explorer in Splunk Search 04-24-2017
0 9
0
9
ewanbrown
Hi I have a query to look at the number of times a user does an event, and then get different percentiles of these. ...
by ewanbrown Path Finder in Splunk Search 04-24-2017
0 6
0
6
HeinzWaescher
Hi, Is it possible to write a search that shows all saved searches, reports & lookup tables that are shared globally...
by HeinzWaescher Motivator in Splunk Search 04-24-2017
0 3
0
3
sumangala
Hi, Is there any way that we can create lookup table for specific user? As I checked outputlookup command and it doe...
by sumangala Path Finder in Splunk Search 04-24-2017
1 9
1
9
superhm
I want to find the host IPs for three consecutive days of antivirus detection. Please help me. ex) - sourcetype: viru...
by superhm Explorer in Splunk Search 04-24-2017
0 2
0
2
xsstest
I am a splunk novice. Https://answers.splunk.com/answers/522405/why-is-there-no-data-in-my-summary-index.html URL o...
by xsstest Communicator in Splunk Search 04-23-2017
0 4
0
4
abonuccelli_spl
I am grouping time buckets using 'span' and I'd like to trim partial time buckets at the beginning and end of the sea...
by abonuccelli_spl Splunk Employee Splunk Employee in Splunk Search 04-22-2017
2 3
2
3
macadminrohit
Hi, Below is the search I am running on a set of servers in the lookup file , I don't want to run the search on all ...
by macadminrohit Contributor in Splunk Search 04-22-2017
0 7
0
7
sideview
The fieldformat command ( http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Fieldformat ) offers a ...
by SplunkTrust SplunkTrust in Splunk Search 04-22-2017
1 5
1
5
robertlynch2020
Is it possible to remove all non alpha-numeric when taking in data in the props.conf? I have tried wiht regex but i ...
by robertlynch2020 Influencer in Splunk Search 04-22-2017
0 13
0
13
happysplunkyay
I have hundreds of .tmp files that begin with evb* and exist within the "File Name" field. All I want to do is change...
by happysplunkyay New Member in Splunk Search 04-21-2017
0 8
0
8
yoho
Just wanted to share with the community the plugin and syntax highlighter I've made for VIM. To enable syntax highli...
by yoho Contributor in Splunk Search 04-21-2017
14 10
14
10
sravankaripe
Is there any option other than transaction command to measure the time between events? because i am already using tra...
by sravankaripe Communicator in Splunk Search 04-21-2017
0 1
0
1
ON34C02151009
I was asked to provide active users since December 2016. With the logs we're working with, there's really no way to ...
by ON34C02151009 Explorer in Splunk Search 04-21-2017
0 12
0
12
jhayIV
Is there a way to write an eval to pull back host name Server1 from Server1.12.city.net
by jhayIV Engager in Splunk Search 04-21-2017
0 2
0
2
joesrepsol
Looking to build a report to list all the indexes/sourcetypes in use. And be able to monitor event counts as they go ...
by joesrepsol Path Finder in Splunk Search 04-21-2017
0 8
0
8
nagarjuna280
I have some data, if the message contains a word which is in a csv file, then results should show in a table. How sho...
by nagarjuna280 Communicator in Splunk Search 04-21-2017
0 3
0
3
jian
A search for "ip=100.2.2.2" userid=foobar (identifying information has been changed) produces 5 results. However, whe...
by jian Explorer in Splunk Search 04-21-2017
0 7
0
7
RocIngersol
Hey Folks, I have a transaction search that "groups" various things of interest (5m maxspan etc ). I was wondering -...
by RocIngersol Explorer in Splunk Search 04-21-2017
0 6
0
6
prashanthberam
"cvpEditAction" : "R", "cvpEditAllowedAmount" : 333.57, Could someone please help me how to extract these? thanks.
by prashanthberam Explorer in Splunk Search 04-21-2017
0 7
0
7
pavanae
The following is the search in my Splunk. Now I am just trying to understand the structure and that condition means c...
by pavanae Builder in Splunk Search 04-21-2017
1 4
1
4
acabralg
I thought the following query would return that but I can see accounts of type "Standard User". "search host=* AND s...
by acabralg Explorer in Splunk Search 04-21-2017
0 11
0
11
kteng2024
hi, Is there a way to find out the scripts running by users on indexers because few backs when i ask a user , he tol...
by kteng2024 Path Finder in Splunk Search 04-21-2017
0 3
0
3
mdsnmss
I have a group of multivalue fields that are listed with linebreaks . I'm looking to remove the line breaks from one ...
by SplunkTrust SplunkTrust in Splunk Search 04-21-2017
1 1
1
1
biec1
I would like to count the number of times a Server went down based on up/down status field. How can i evaluate multip...
by biec1 Explorer in Splunk Search 04-21-2017
0 4
0
4
Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...