Splunk Search

Splunk Search
Community Activity
jamie_leclair
This is my first time posting to the community, I hope this answer is not listed somewhere else.. if it is I have bee...
by jamie_leclair Engager in Splunk Search 03-31-2017
0 3
0
3
Nikita_Danilov
Hi all! As I understand, Splunk doesn't have any special functions for normal work with string. I need to get index ...
by Nikita_Danilov Path Finder in Splunk Search 03-31-2017
0 10
0
10
sperl
When I do a timechart - I get the max of my variable in the chart. However, if I hover over the value - the time ass...
by sperl New Member in Splunk Search 03-31-2017
0 1
0
1
vdevarayan
I have a dashboard panel that will display all events (for a given search) The result set may contain 100 or 10,000 e...
by vdevarayan Path Finder in Splunk Search 03-31-2017
3 6
3
6
sloshburch
Although this works with no issue in SPL: | rex field=fieldName "(?i)^(?P<test>.*)$" This EXTRACT-test = (?i)^(...
by sloshburch Ultra Champion in Splunk Search 03-31-2017
0 5
0
5
jplumsdaine22
In 6.5 it looks like there is a new metric event that tracks the dispatch reaper. You can view it with index=_intern...
by jplumsdaine22 Influencer in Splunk Search 03-31-2017
0 1
0
1
lksridhar
Hi Folks, Could you please help me to get the search for Ldap user logon and logoff activity on Splunk search head? ...
by lksridhar Explorer in Splunk Search 03-31-2017
0 2
0
2
sundarrajan
Hi all. Apologies for asking such an unclear and hazy question. I have a situation to show transactions in 2 differen...
by sundarrajan Path Finder in Splunk Search 03-31-2017
0 5
0
5
colinmchugo
Hi, Is there a way of discovering when an a field (e.g. like an IP address or MAC address) was first seen in the ind...
by colinmchugo Explorer in Splunk Search 03-31-2017
0 1
0
1
Norling80
Hi. I'm using the predict command to determine when my machine will run out of disk based on the historical usage, ...
by Norling80 Path Finder in Splunk Search 03-31-2017
1 5
1
5
srichansen
Hi all, I am have data about bus routes with arrival times at stops and I am trying to find the ride time between th...
by srichansen Path Finder in Splunk Search 03-31-2017
0 8
0
8
jward6004
Query : error SourceName=PaymentProcessingService Example of a common search result for under the field Exception...
by jward6004 Explorer in Splunk Search 03-30-2017
0 11
0
11
bugnet
Hi, I get send-mail logs in separated events\lines (5 events). With a unique identifier that appears in any event. ...
by bugnet Path Finder in Splunk Search 03-30-2017
0 6
0
6
ajtalbot1
What I thought was going to be a simple search: lucy | eval UsedT=UsedMB/1024/1024 | eval UsedTB=round(UsedT,1) | ...
by ajtalbot1 Engager in Splunk Search 03-30-2017
0 3
0
3
yagbootz48
Hello, Is there a way to access data in Solarwinds IPAM via Splunk? For example, if I was wondering where an ip add...
by yagbootz48 New Member in Splunk Search 03-30-2017
0 1
0
1
brent_weaver
I am in a situation where I need to rewrite metadata for each and every event. I need to rewrite index and sourcetype...
by brent_weaver Builder in Splunk Search 03-30-2017
0 3
0
3
bilchen
Hi, Is there a way for a query to take a value from lookup table and if it has a match it record down the value and c...
by bilchen New Member in Splunk Search 03-30-2017
0 3
0
3
meghnak
How to compare the row count of CSV or XLS files day over day and generate an alert if the threshold is greater than ...
by meghnak New Member in Splunk Search 03-30-2017
0 4
0
4
guimilare
Hello Splunkers. I'm indexing some SNMP data from a server. Here is one event indexed: HOST-RESOURCES-MIB::hrStorag...
by guimilare Communicator in Splunk Search 03-30-2017
0 7
0
7
vj1226
Hello, I have several lookup files in txt and it's in form like "blacksite1:123.123.123.1-123.123.123.17blacksite2:4...
by vj1226 New Member in Splunk Search 03-30-2017
0 3
0
3
nagarjuna280
index="main" | stats count by sourcetype | search count>40000, I will get 10 sourcetypes, If any source type does...
by nagarjuna280 Communicator in Splunk Search 03-30-2017
0 1
0
1
wh_ols
Currently we have a radial gauge with current stats, and a single value with the peak. Is there a way of marking the ...
by wh_ols New Member in Splunk Search 03-30-2017
0 1
0
1
sravankaripe
i want to list out the success count by time Example: index="ABC" sourcetype="XYZ" responsecode="200"| Time ...
by sravankaripe Communicator in Splunk Search 03-30-2017
0 5
0
5
ckunath
Hello, I am currently trying to set up an alert in Splunk by checking my eventdata after events that contain a list o...
by ckunath Communicator in Splunk Search 03-30-2017
0 3
0
3
gregbujak
I am trying to figure out the query that would allow me to chain a series of events together. The issue here is that ...
by gregbujak Path Finder in Splunk Search 03-30-2017
0 7
0
7
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...