Splunk Search

Splunk Search
Community Activity
robertlynch2020
Does Splunk internally know the "number_of_cpus" for the below maths? max_hist_searches = max_searches_per_cpu x num...
by robertlynch2020 Influencer in Splunk Search 03-14-2017
0 3
0
3
alexandermunce
I am working with a datasource which contains multiple instances of an XML value which exists similarly to this: (WI...
by alexandermunce Communicator in Splunk Search 03-13-2017
0 4
0
4
santorof
Trying to do an expression that would extract IP's that are below the Client IP: line. Im looking to pull out each IP...
by santorof Communicator in Splunk Search 03-13-2017
0 7
0
7
Accak
I managed to count how many events were created and completed (tickets) in last weeks (last 6 months). You can see th...
by Accak Path Finder in Splunk Search 03-13-2017
0 5
0
5
kirandvrs
I have SAR info like this and I am able to get values in table format. But I need the same values plotted in graph. I...
by kirandvrs New Member in Splunk Search 03-13-2017
0 2
0
2
jh5970
Hi all, (URL="xxx.com") OR (URL="zzz.com") index=logs | timechart span=1d dc(IP) I am trying to use above search ...
by jh5970 New Member in Splunk Search 03-13-2017
0 4
0
4
kteng2024
how to find out why an indexer is using more license than other indexers? Because i have 5 indexers, out of which 2 i...
by kteng2024 Path Finder in Splunk Search 03-13-2017
0 4
0
4
splunk_svc
Hi Splunkers. I am retrieving a field from JSON log file using rex, table and spath. Although this runs fine as a st...
by splunk_svc Path Finder in Splunk Search 03-13-2017
0 4
0
4
stwong
Hi, Sorry for the newbie question. We want to calculate percentage of time between 2 events over the entire search ...
by stwong Communicator in Splunk Search 03-13-2017
0 14
0
14
prashanthberam
Hi, i have messages like this how to setup an alert if ack message is not available in the logs for particular...
by prashanthberam Explorer in Splunk Search 03-13-2017
0 9
0
9
lbonnes
We have Multiple servers that all end with the same few letters like this. Office1Server Office2Server Remot1Serve...
by lbonnes Observer in Splunk Search 03-13-2017
0 2
0
2
jackieh00
I have 2 search search 1 index=A "testx" | stats count(user) AS total1 by _time search 2 index=B "testx" | stats c...
by jackieh00 New Member in Splunk Search 03-13-2017
0 2
0
2
bradparks
I've got a query that gives 178 results, and it ends with me filtering down to a single field, which by itself works ...
by bradparks Explorer in Splunk Search 03-13-2017
0 5
0
5
bitfhacker
Hi, I'm trying to extract two fields with this regular expression: Transaction\sID=\"(?P<Transaction_ID>\w*)\".*Ope...
by bitfhacker New Member in Splunk Search 03-13-2017
0 2
0
2
kiran331
Hi, How to write a regular expression to use to extract the domain name from the dest_host, like extracting the las...
by kiran331 Builder in Splunk Search 03-13-2017
0 6
0
6
ltemple1
Samples are collected and later manually entered into Splunk. I am interested in the time the sample was tested, not ...
by ltemple1 Engager in Splunk Search 03-13-2017
1 1
1
1
Alan_Bradley
Is it possible to limit the "export results" action to export only the fields that were presented to the client using...
by Alan_Bradley Path Finder in Splunk Search 03-13-2017
6 5
6
5
Harishma
Hi All, We have removed real-time searching capability in our enterprise but the users havent yet removed their Realt...
by Harishma Communicator in Splunk Search 03-13-2017
0 1
0
1
srichansen
Hi all, I am trying to filter results based on information in two fields and am getting no result when I used the e...
by srichansen Path Finder in Splunk Search 03-13-2017
0 8
0
8
bkumarm
we have a lookup table which is like: table: host,userid,index,status host1.dom.com,user1,idx1,Y host1.dom.com,user2,...
by bkumarm Contributor in Splunk Search 03-13-2017
0 7
0
7
splunk-support0
I have a dataset like: quarter,faculty, people 2016-Q1,LAW,2 2016-Q1,BUSINESS,11 2016-Q1,EDUCATION,2 2016-Q2,BUSINES...
by splunk-support0 Explorer in Splunk Search 03-12-2017
0 3
0
3
kmagyar
I have 27,285,464 Events from 6 sources, but the console tells me that no search results are found. Splunk Version ...
by kmagyar New Member in Splunk Search 03-12-2017
0 3
0
3
ankithreddy777
I have a event as below nam=this is org name; -this is hyta name; -this is hju name; falu= this is gao name I need ...
by ankithreddy777 Contributor in Splunk Search 03-12-2017
0 3
0
3
iKate
Hi, Basing on customers' purchases I'd like to make a proposition of what item can be probably purchased if a user ha...
by iKate Builder in Splunk Search 03-12-2017
4 4
4
4
moshiro
Need help with searching for patterns in username field values... I want to know if anyone has suggestions for the b...
by moshiro New Member in Splunk Search 03-11-2017
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...