Splunk Search

Splunk Search
Community Activity
jhayIV
Is there a way to write an eval to pull back host name Server1 from Server1.12.city.net
by jhayIV Engager in Splunk Search 04-21-2017
0 2
0
2
joesrepsol
Looking to build a report to list all the indexes/sourcetypes in use. And be able to monitor event counts as they go ...
by joesrepsol Path Finder in Splunk Search 04-21-2017
0 8
0
8
nagarjuna280
I have some data, if the message contains a word which is in a csv file, then results should show in a table. How sho...
by nagarjuna280 Communicator in Splunk Search 04-21-2017
0 3
0
3
jian
A search for "ip=100.2.2.2" userid=foobar (identifying information has been changed) produces 5 results. However, whe...
by jian Explorer in Splunk Search 04-21-2017
0 7
0
7
RocIngersol
Hey Folks, I have a transaction search that "groups" various things of interest (5m maxspan etc ). I was wondering -...
by RocIngersol Explorer in Splunk Search 04-21-2017
0 6
0
6
prashanthberam
"cvpEditAction" : "R", "cvpEditAllowedAmount" : 333.57, Could someone please help me how to extract these? thanks.
by prashanthberam Explorer in Splunk Search 04-21-2017
0 7
0
7
pavanae
The following is the search in my Splunk. Now I am just trying to understand the structure and that condition means c...
by pavanae Builder in Splunk Search 04-21-2017
1 4
1
4
acabralg
I thought the following query would return that but I can see accounts of type "Standard User". "search host=* AND s...
by acabralg Explorer in Splunk Search 04-21-2017
0 11
0
11
kteng2024
hi, Is there a way to find out the scripts running by users on indexers because few backs when i ask a user , he tol...
by kteng2024 Path Finder in Splunk Search 04-21-2017
0 3
0
3
mdsnmss
I have a group of multivalue fields that are listed with linebreaks . I'm looking to remove the line breaks from one ...
by SplunkTrust SplunkTrust in Splunk Search 04-21-2017
1 1
1
1
biec1
I would like to count the number of times a Server went down based on up/down status field. How can i evaluate multip...
by biec1 Explorer in Splunk Search 04-21-2017
0 4
0
4
urapaveerapan
Hi, I tried to summary data in each assignment_group_name by month here is my code: index="snow" sourcetype="snow:...
by urapaveerapan Explorer in Splunk Search 04-21-2017
0 3
0
3
JRamirezEnosys
Hi Splunkers, I have a query that gives me the following fields I want to work with. username Country (after usin...
by JRamirezEnosys Explorer in Splunk Search 04-21-2017
0 3
0
3
nicolas_pons
Hi, I have a report (scheduled to be run every 5 minutes) that I have built, it list the number of specific events ...
by nicolas_pons New Member in Splunk Search 04-21-2017
0 3
0
3
hbusch
Hey everyone i have a little bit of a problem with some of my searches, as I am only rarely able to execute them. Sp...
by hbusch New Member in Splunk Search 04-21-2017
0 5
0
5
aywong
In my indexes.conf file (C:\Program Files\Splunk\etc\system\local) I have the attribute "maxHotIdleSecs = 86400" So ...
by aywong Path Finder in Splunk Search 04-21-2017
0 10
0
10
danielsofoulis
Hi, I am trying to setup a dropdown bar for a dashboard and would like to setup dynamic inputs based on the source lo...
by danielsofoulis Path Finder in Splunk Search 04-21-2017
0 6
0
6
viraptor
I'd like to create a chart of bin counts over time (with a span defined). Right now, I can get the result over the wh...
by viraptor New Member in Splunk Search 04-21-2017
0 4
0
4
Abarny
Hi, Can you tell me why i can't update my dynamic list on my dashboard ? I have this message : "Duplicate values cau...
by Abarny Path Finder in Splunk Search 04-21-2017
0 5
0
5
mkrauss1
Good day, i have the follwing key values: CMD=LOOK ITEM1=APPLE ITEM2=APPLE ITEM3=ORANGE STAT=0 CMD=LOOK ITEM1=APPLE ...
by mkrauss1 Explorer in Splunk Search 04-21-2017
0 5
0
5
leomedina
Hello all, I am trying new things and expanding my palate but having a problem extracting JSON. My Search: index=t...
by leomedina Explorer in Splunk Search 04-20-2017
0 6
0
6
k909
Hello, for control dhcp server, need to search "bad" mac addresses, but use whitelist . And need modify search string...
by k909 Engager in Splunk Search 04-20-2017
0 5
0
5
SplunkLunk
Greetings, In Windows, there's a nice EventID you can query to see when system, application, or security event logs ...
by SplunkLunk Path Finder in Splunk Search 04-20-2017
0 3
0
3
sravankaripe
i have to two different sourcetypes with two different key but values are same for both keys Please help me with se...
by sravankaripe Communicator in Splunk Search 04-20-2017
0 4
0
4
jovi
Hi I have logs in Splunk containing lines like this: UserPolicies=13=5|0=81540803|7=137|9=76|13=3|1=11|21=10 UserPoli...
by jovi New Member in Splunk Search 04-20-2017
0 3
0
3
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors