Splunk Search

Splunk Search
Community Activity
mhqssyh
I am trying to calculate some term frequency on the field. The field is defined as follow. rex field=_raw "Notes : (...
by mhqssyh Explorer in Splunk Search 04-04-2017
1 5
1
5
rgcurry
I am wanting to create a process that will make it really simple and easy for my users to update their lookup table f...
by rgcurry Contributor in Splunk Search 04-04-2017
3 6
3
6
HeinzWaescher
Hi, is it possible to use fillnull for fields with a specific pattern? Wildcards are not working, but I want to avoi...
by HeinzWaescher Motivator in Splunk Search 04-04-2017
0 2
0
2
jhall0007
Hello, I am trying to extract and normalize some phone numbers that are appearing in inconsistent ways. Below I atte...
by jhall0007 Path Finder in Splunk Search 04-04-2017
0 3
0
3
MattLingwood
I am hitting a mental block in creating this query and wish to monitor our server performance so we have visibility o...
by MattLingwood Engager in Splunk Search 04-04-2017
0 9
0
9
goji
The date are all number field, such as cluster, field_1, field_2, field_3, field_4, field_5 1 3 ...
by goji Path Finder in Splunk Search 04-04-2017
0 4
0
4
KassandraI
Hello, I'm new to Splunk and would appreciate any help. I am trying to figure out what month had the largest percent...
by KassandraI Engager in Splunk Search 04-04-2017
0 5
0
5
k_harini
How to set earliest to 26th of previous month and latest to 25th of current month? if hard corded then 26th of Feb to...
by k_harini Communicator in Splunk Search 04-04-2017
0 5
0
5
matansocher
I have two graphs (I put example and their search code) and I want to display them on a single graph. Is there a way ...
by matansocher Contributor in Splunk Search 04-04-2017
0 4
0
4
thisissplunk
I believe commands like "transaction" work on the _time metadata field that is hidden in each event. This is similar ...
by thisissplunk Builder in Splunk Search 04-03-2017
0 1
0
1
shearsey
I have scripted output from UGE qhost command that gives memory in G (GBs) or if less than 1GB, in M (MBs). I'd like...
by shearsey New Member in Splunk Search 04-03-2017
0 3
0
3
dhartzog
Hello, I am very new to this tool. I have Splunk set up to monitor a log file and extract json being written to that...
by dhartzog New Member in Splunk Search 04-03-2017
0 3
0
3
anthony_copus
Hi, Currently I'm trying to run a query which take the results of a subsearch as a parameter as follows: index="vid...
by anthony_copus Explorer in Splunk Search 04-03-2017
0 3
0
3
shaal89
Here is the logs, event=SUCCESS_FROM_SERVICE UserID=abc currentTime=2017-03-31T05:22:52.176Z headline="[{'contentUU...
by shaal89 New Member in Splunk Search 04-03-2017
0 3
0
3
f_luciani
Hi, I have a request from a client to index the .aud files generated by Oracle. I have been searching Splunk Answers...
by f_luciani Path Finder in Splunk Search 04-03-2017
1 12
1
12
tmontney
(index="myindex" OR index="wineventlog") AND ((host=MYSERVER1 OR host=MYSERVER2) AND (EventCode=20274 OR EventCode=20...
by tmontney Builder in Splunk Search 04-03-2017
0 24
0
24
sbsbb
Is there a way to display a single row table in vertical form ? simpleresult ist like key1 key2 key3 I'd like key1 ...
by sbsbb Builder in Splunk Search 04-03-2017
0 2
0
2
SplunkLunk
Good morning, This must be really simple. I have the query: index=[my index] sourcetype=[my sourcetype] event=logi...
by SplunkLunk Path Finder in Splunk Search 04-03-2017
0 4
0
4
HeinzWaescher
Hi, Is it possible to write a search that shows the selected timeranges for all saved searches? The result table wo...
by HeinzWaescher Motivator in Splunk Search 04-03-2017
0 2
0
2
gancw1
I am trying to tabulate number of specific operation per day using this format timechart span=1d count as DLCreateCo...
by gancw1 Explorer in Splunk Search 04-03-2017
0 8
0
8
vivek_manoj
If I write a search query and want to push the search query code to my lookup. Ho to do it??
by vivek_manoj Explorer in Splunk Search 04-03-2017
0 6
0
6
njwrk
So I have splunk events and I want to display information as a time range. For example: event type1: Started proc1 id...
by njwrk Engager in Splunk Search 04-02-2017
0 3
0
3
jedatt01
I have a data source from DBX that has a field called "description" that contains a pipe separated format with header...
by jedatt01 Builder in Splunk Search 04-02-2017
0 3
0
3
stakor
I am looking for source IPs that have a high percentage of being blocked. The evaluations below work fine if I use ju...
by stakor Path Finder in Splunk Search 04-01-2017
0 1
0
1
tksre
how do i query all events with windows ID 4738 for a specific user
by tksre New Member in Splunk Search 04-01-2017
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...