Splunk Search

Splunk Search
Community Activity
sravankaripe
i want to retrieve myuserid from the below _raw event. please help me with rex in search. <name>userid</name>\n <l...
by sravankaripe Communicator in Splunk Search 03-07-2017
0 5
0
5
driekhof
Our Splunk forwarder is sending events that looks something like this: {"consumerTstamp":1488853092650,"metric":"EvT...
by driekhof Path Finder in Splunk Search 03-07-2017
0 3
0
3
gfriedmann
I have added an automatic lookup based on host value. This lookup creates the field "bettername". I want all users to...
by gfriedmann Communicator in Splunk Search 03-07-2017
1 2
1
2
drinkingjimmy
I'm working with email response data which comes into my index in individual messages. Each email message can have m...
by drinkingjimmy Explorer in Splunk Search 03-07-2017
0 5
0
5
shabdadev
Hi All, Suppose i have a dashboard containing dropdown and in dropdown i have 3 values A,B,C . When i select ...
by shabdadev Engager in Splunk Search 03-07-2017
0 2
0
2
ddrillic
Similar case to Why does my Hunk search partially completes then displays message "ChunkedOutputStreamReader: Invalid...
by ddrillic Ultra Champion in Splunk Search 03-07-2017
0 2
0
2
a212830
Hi, I have the following search to report on license utilization, for the past 30 days. The search runs at 1:00 am,...
by a212830 Champion in Splunk Search 03-07-2017
0 3
0
3
fisuser1
I’m trying to find individual run times for specific jobs in our database. Each ‘job’ consists of two ‘sub-jobs’ th...
by fisuser1 Contributor in Splunk Search 03-07-2017
0 4
0
4
ddrillic
We have Hunk on a machine of four cores only. Is there a way to use more than one search per core on Hunk? If so, how...
by ddrillic Ultra Champion in Splunk Search 03-07-2017
0 4
0
4
smcdonald20
Trying to find any DeviceId field values that appear in the ActiveSync search but NOT in the MobileIron search. What ...
by smcdonald20 Path Finder in Splunk Search 03-07-2017
0 1
0
1
guru865
Need to extract string from event and get the total count and range values . I have event logs with a "response time...
by guru865 Path Finder in Splunk Search 03-06-2017
0 5
0
5
pavanae
I am just curious to know what does it actually doing in a big splunk quary? As per the result i understood if we us...
by pavanae Builder in Splunk Search 03-06-2017
0 3
0
3
nprab428
I've created a data model and want to search it in my external Javascript. For my first attempt, a SearchManager woul...
by nprab428 Engager in Splunk Search 03-06-2017
1 2
1
2
jacqu3sy
Hi, is there a way (I'm sure there is, I'm just not seeing it), whereby I can search a lookup table for results in fi...
by jacqu3sy Path Finder in Splunk Search 03-06-2017
0 11
0
11
woodcock
I have 2 datasets: 1: Windows events to review that have a DoneBy user and a DoneTo user. 2: Work Orders in a DB that...
by Esteemed Legend in Splunk Search 03-06-2017
1 9
1
9
_jgpm_
I'm on 6.4.3. I'm trying to template a text parser in Splunk that will basically delimit sentences in many different ...
by _jgpm_ Communicator in Splunk Search 03-06-2017
0 4
0
4
saeidbsn
I'm very new to Splunk and searched a lot for this but i wasn't able to figure it out. I have events like name=x, id...
by saeidbsn New Member in Splunk Search 03-06-2017
0 2
0
2
jcspigler2010
Hello Splunkers, I am trying to compose a search to do the following and create a table based off of the results: ...
by jcspigler2010 Path Finder in Splunk Search 03-06-2017
0 5
0
5
czervos
Let's say I have a log that containts starttranscationsome other eventsend transactionsome other eventsstarttransact...
by czervos Explorer in Splunk Search 03-06-2017
0 6
0
6
Accak
I have table like this: I want to query number of completed tickets during the date that they were created. e.g:...
by Accak Path Finder in Splunk Search 03-06-2017
0 3
0
3
nicolecristobal
I have a main Dashboard name - Dispatch,and i have another dashboard with all the details for that status named-Detai...
by nicolecristobal New Member in Splunk Search 03-06-2017
0 1
0
1
Abarny
Hi, I have problem with an average, do you know how i can to do an average enter the max JourP and number where I ha...
by Abarny Path Finder in Splunk Search 03-06-2017
0 4
0
4
craighawk
index=data du= host= | timechart count by opp or index=data du= host= I am useing version 4.3.2, build 123586 I ...
by craighawk Explorer in Splunk Search 03-06-2017
1 8
1
8
rijinc
this is my query: |index = * count(search) AS "total_count" SPLITROW Test_ID SPLITROW R_S_Me SPLITROW Set SPLITROW C...
by rijinc Explorer in Splunk Search 03-05-2017
0 5
0
5
skuma30
I am having some trouble with locating the lookup files, can some one please help me?
by skuma30 New Member in Splunk Search 03-05-2017
0 6
0
6
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors