Splunk Search

Splunk Search
Community Activity
lbonnes
We have Multiple servers that all end with the same few letters like this. Office1Server Office2Server Remot1Serve...
by lbonnes Observer in Splunk Search 03-13-2017
0 2
0
2
jackieh00
I have 2 search search 1 index=A "testx" | stats count(user) AS total1 by _time search 2 index=B "testx" | stats c...
by jackieh00 New Member in Splunk Search 03-13-2017
0 2
0
2
bradparks
I've got a query that gives 178 results, and it ends with me filtering down to a single field, which by itself works ...
by bradparks Explorer in Splunk Search 03-13-2017
0 5
0
5
bitfhacker
Hi, I'm trying to extract two fields with this regular expression: Transaction\sID=\"(?P<Transaction_ID>\w*)\".*Ope...
by bitfhacker New Member in Splunk Search 03-13-2017
0 2
0
2
kiran331
Hi, How to write a regular expression to use to extract the domain name from the dest_host, like extracting the las...
by kiran331 Builder in Splunk Search 03-13-2017
0 6
0
6
ltemple1
Samples are collected and later manually entered into Splunk. I am interested in the time the sample was tested, not ...
by ltemple1 Engager in Splunk Search 03-13-2017
1 1
1
1
Alan_Bradley
Is it possible to limit the "export results" action to export only the fields that were presented to the client using...
by Alan_Bradley Path Finder in Splunk Search 03-13-2017
6 5
6
5
Harishma
Hi All, We have removed real-time searching capability in our enterprise but the users havent yet removed their Realt...
by Harishma Communicator in Splunk Search 03-13-2017
0 1
0
1
srichansen
Hi all, I am trying to filter results based on information in two fields and am getting no result when I used the e...
by srichansen Path Finder in Splunk Search 03-13-2017
0 8
0
8
bkumarm
we have a lookup table which is like: table: host,userid,index,status host1.dom.com,user1,idx1,Y host1.dom.com,user2,...
by bkumarm Contributor in Splunk Search 03-13-2017
0 7
0
7
splunk-support0
I have a dataset like: quarter,faculty, people 2016-Q1,LAW,2 2016-Q1,BUSINESS,11 2016-Q1,EDUCATION,2 2016-Q2,BUSINES...
by splunk-support0 Explorer in Splunk Search 03-12-2017
0 3
0
3
kmagyar
I have 27,285,464 Events from 6 sources, but the console tells me that no search results are found. Splunk Version ...
by kmagyar New Member in Splunk Search 03-12-2017
0 3
0
3
ankithreddy777
I have a event as below nam=this is org name; -this is hyta name; -this is hju name; falu= this is gao name I need ...
by ankithreddy777 Contributor in Splunk Search 03-12-2017
0 3
0
3
iKate
Hi, Basing on customers' purchases I'd like to make a proposition of what item can be probably purchased if a user ha...
by iKate Builder in Splunk Search 03-12-2017
4 4
4
4
moshiro
Need help with searching for patterns in username field values... I want to know if anyone has suggestions for the b...
by moshiro New Member in Splunk Search 03-11-2017
0 4
0
4
rewritex
I can upload a lookup table .csv fine, "| lookupinput <name.csv>" also works fine. When I create an autolookup, the l...
by rewritex Contributor in Splunk Search 03-11-2017
0 6
0
6
asarran
Good Morning, Fellow Splunkers I have a field extraction that outputs four possible values [Example]: Field Extract...
by asarran Path Finder in Splunk Search 03-11-2017
0 6
0
6
jwalthour
I am trying to extract fields out of events that are tab-delimited unless there are quotes around them. For example, ...
by jwalthour Communicator in Splunk Search 03-11-2017
0 9
0
9
nunyabizness123
How would I go about parsing out/extracting the field data for the following log format? "fieldname1":"fieldvalue1",...
by nunyabizness123 New Member in Splunk Search 03-11-2017
0 2
0
2
rlseafor
sourcetype="my_sourcetype" ("Build Failed" NOT "Build Succeeded") earliest=@d+2h | rename host as "Imaging Server" | ...
by rlseafor New Member in Splunk Search 03-11-2017
0 2
0
2
jhayIV
Is there a way to determine days between with the search below? convert ctime(LastScanDate)|eval tnow = now() | conv...
by jhayIV Engager in Splunk Search 03-11-2017
0 2
0
2
shivac
12-000-000-222 for the above IP address, i want to change it to 12.000.000.222. pls help.
by shivac New Member in Splunk Search 03-11-2017
0 4
0
4
jamesar
I am wanting to extract a new field from the original source field, based on regex matches. I would then like to prep...
by jamesar Explorer in Splunk Search 03-11-2017
1 4
1
4
splunkrocks2014
Assuming I have a lookup table with movie title and location, and I got the top 5 location based on distinct title co...
by splunkrocks2014 Communicator in Splunk Search 03-11-2017
0 6
0
6
mblauw
I've just started using RegEx and I'm currently looking on a way to extract multiple events from my JSON flight infor...
by mblauw Path Finder in Splunk Search 03-11-2017
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...