Splunk Search

Splunk Search
Community Activity
splunkIT
I would like to setup a scheduled alert which includes the event that triggers the alert, plus a few events prior the...
by splunkIT Splunk Employee Splunk Employee in Splunk Search 04-05-2017
0 1
0
1
explorer436
Hello, I have a log file with a bunch of entries like this: [INFO ] Wed, 5 Apr 2017 at 08:19:52 AM EDT TestClass [De...
by explorer436 New Member in Splunk Search 04-05-2017
0 1
0
1
leomedina
Hello all, I am trying to search on multiple values, which are not being populated in a field. And then renaming th...
by leomedina Explorer in Splunk Search 04-05-2017
0 3
0
3
jhayIV
I am trying to determine the days between a static date and current date in this query I added a the 2008r2 column w...
by jhayIV Engager in Splunk Search 04-05-2017
0 2
0
2
raby1996
Hello all, I was hoping I could get a bit of assistance in figuring out a rex expression I could use to extract part...
by raby1996 Path Finder in Splunk Search 04-05-2017
0 5
0
5
jayakumar89
We have 3 custom roles (user, power user and admin) and i would like to set 24hours as default search interval or blo...
by jayakumar89 Explorer in Splunk Search 04-05-2017
0 3
0
3
limalbert
Hi all, Below is how the data I have. currentDate user _time 2017-02-01 aaa 8:00:00 2017-02-01 aaa 9:12...
by limalbert Path Finder in Splunk Search 04-05-2017
0 4
0
4
nasamajh09
I would like to see in props.conf how data parsing is done My query should return results stating sourcetype ...
by nasamajh09 New Member in Splunk Search 04-05-2017
0 2
0
2
SplunkLunk
Good morning, I have the following search: index=[my index] source=[my source] sourcetype=[my sourcetype] event=log...
by SplunkLunk Path Finder in Splunk Search 04-05-2017
0 5
0
5
grittonc
Hello everyone, I have inherited shared responsibility for a Splunk instance. We recently had a user departure, and ...
by grittonc Contributor in Splunk Search 04-05-2017
0 5
0
5
sniderwj
We have a requirement to collect data from testing enclaves (that have copies of production devices) to our primary S...
by sniderwj Explorer in Splunk Search 04-05-2017
0 4
0
4
timm747747
Hi, I have the following data with the following columns, OrderNo, Transaction Start, Transaction Stop. I wrote a se...
by timm747747 Path Finder in Splunk Search 04-05-2017
1 5
1
5
Kwip
I am having lookup file with list of Jobs to be monitored. I want to create a table with the jobs name from lookup fi...
by Kwip Contributor in Splunk Search 04-05-2017
0 2
0
2
hippe21
Here's the scenario: server102 has not reported data in the last 15 minutes. I want to use my inputlookup in conjunct...
by hippe21 Explorer in Splunk Search 04-05-2017
0 10
0
10
brent_weaver
I have a source of /var/log/opscode/desired_sourcetype/current. I need to get the part of the filename that is called...
by brent_weaver Builder in Splunk Search 04-05-2017
0 6
0
6
user290317
Hi, novice splunker here. I'm having an issue in getting all the timestamps correctly parsed from the DATE and TIME ...
by user290317 Explorer in Splunk Search 04-05-2017
0 2
0
2
meenal901
Hi, I have a requirement - the user will enter a lat,lon in the filter and expects Splunk to search the "nearby 10km...
by meenal901 Communicator in Splunk Search 04-05-2017
0 1
0
1
keycoldstorage
The streamstats last function is very close to a very important tool in my workflow; however, I would like it to eval...
by keycoldstorage Explorer in Splunk Search 04-05-2017
1 4
1
4
adevi
Recently upgraded to Splunk 6.5.0. I am trying to access the first row from the search result in a dashboard. In vers...
by adevi Explorer in Splunk Search 04-04-2017
1 7
1
7
limalbert
Hi all, How to get a count of stats list that contains a specific data? Data is populated using stats and list() com...
by limalbert Path Finder in Splunk Search 04-04-2017
0 3
0
3
matansocher
I have the following search and I would like to present instead of the 40 dummy values, the actual name of the field ...
by matansocher Contributor in Splunk Search 04-04-2017
0 2
0
2
renjujacob88
Hi, I have a blacklisted inputlookup csv which contains 20000 blacklisted ip. I need to compare the inputlookup with...
by renjujacob88 Path Finder in Splunk Search 04-04-2017
0 10
0
10
sumit29
Hi All, I have a blacklisted IP CSV file (Placed in lookup folder of search(app)). I need to compare with firewall l...
by sumit29 Path Finder in Splunk Search 04-04-2017
0 4
0
4
EricLloyd79
This seems like it would be easy to figure out through search but I'm coming across a dead end. I have a transaction ...
by EricLloyd79 Builder in Splunk Search 04-04-2017
0 5
0
5
spotypoti1
This is my first attempt to create a "bigger" splunk search. I tried it the last two weeks but am stuck now. Hopefull...
by spotypoti1 Engager in Splunk Search 04-04-2017
0 4
0
4
Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...