Splunk Search

Splunk Search
Community Activity
dougmartin
What is the max value for maxsearches? Is there a way to NOT have a max (set to 0 or -1)?
by dougmartin Path Finder in Splunk Search 02-28-2017
0 2
0
2
jacqu3sy
Problem with this search? Would the following search detect a malicious user, trying to connect to multiple destinat...
by jacqu3sy Path Finder in Splunk Search 02-28-2017
0 3
0
3
_jgpm_
I've looked into format and it doesn't look like I can replace the "=". I want to change ( ( DateStart="12/14/2016...
by _jgpm_ Communicator in Splunk Search 02-28-2017
0 10
0
10
plucas_splunk
I'm time-charting public transit vehicle "layover" time. ("Layover" is how long a driver takes a break upon reaching ...
by plucas_splunk Splunk Employee Splunk Employee in Splunk Search 02-28-2017
0 9
0
9
kteng2024
Hi, index=_internal source=*metrics.log group=searchscheduler | timechart partial=false span=10m sum(dispatched) su...
by kteng2024 Path Finder in Splunk Search 02-28-2017
1 2
1
2
kteng2024
hi, can i please know the query to list all the saved searches and query used for those saved searches , user id .
by kteng2024 Path Finder in Splunk Search 02-28-2017
0 1
0
1
nmohammed
Hi, Our application logs an event at the end of completion of an api call with response time in milliseconds(ms) li...
by nmohammed Builder in Splunk Search 02-28-2017
0 3
0
3
AdixitSplunk
HI All, I have a lookup table with host names value around 10 field name host. I have this search index=Application ...
by AdixitSplunk Path Finder in Splunk Search 02-28-2017
0 4
0
4
att35
Hi, We are capturing a custom log from Windows event viewer using Splunk forwarder. Most of the fields are extracted...
by att35 Builder in Splunk Search 02-28-2017
0 12
0
12
hartfoml
I have a search like this sourcetype=foo-bar category=foo | stats count by category | where count>5 I have 5 catego...
by hartfoml Motivator in Splunk Search 02-28-2017
0 8
0
8
ashishlal82
how can I use multiple values in where clause for ex:index=xyz sourcetype=abc | dedup name | where name="2009-2274"...
by ashishlal82 Explorer in Splunk Search 02-28-2017
0 3
0
3
rijinc
there are two computed dropdown, just in case i select values from one dropdown the other dropdown should be reset to...
by rijinc Explorer in Splunk Search 02-28-2017
1 1
1
1
kteng2024
hi, how can i find out whether a bucket is hot , cold ,warm bucket. For example , db_2587397960_1411235746_15480, ho...
by kteng2024 Path Finder in Splunk Search 02-28-2017
0 2
0
2
andrewtrobec
Hello All, Currently using Splunk 6.5.1. As the question implies, I have a search that uses the appendcols command ...
by andrewtrobec Motivator in Splunk Search 02-28-2017
0 9
0
9
hwakonwalk
Hi, I am using geostats command to display the location wise data for India, at zoom level 7, the maps display the da...
by hwakonwalk Path Finder in Splunk Search 02-28-2017
0 1
0
1
Accak
I have lookup table like this: locationOrFunction, asset_id London,Application for one;Application for two;Applicati...
by Accak Path Finder in Splunk Search 02-28-2017
0 1
0
1
abonuccelli_spl
Hi, I've installed Enterprise Security dedicated search head following all the best practices with beefy enough hard...
by abonuccelli_spl Splunk Employee Splunk Employee in Splunk Search 02-28-2017
2 2
2
2
Abarny
Hi guys can you tell me how i can count how many code 200 I have when i have do a mvjoin? I try with this search but ...
by Abarny Path Finder in Splunk Search 02-28-2017
0 6
0
6
tragiccode
i constantly have to filter my search results based on a static list of known Windows service names. my searches usu...
by tragiccode New Member in Splunk Search 02-28-2017
0 2
0
2
amitmenon123
I am automating a report. So for that i use 4 dump CSV files whose names i don't change. When i used to change the ...
by amitmenon123 New Member in Splunk Search 02-27-2017
0 3
0
3
jpass
I'm wondering what the most efficient way to deal events that contain values that should be grouped based on the fiel...
by jpass Contributor in Splunk Search 02-27-2017
0 6
0
6
mtrochym
Hi, I am using the below query to timechart the values of offers (STATUS=ACCEPTED) from midnight, of the current day,...
by mtrochym Observer in Splunk Search 02-27-2017
0 3
0
3
kdwsplunk
Hello, I ran a search that had 15,000+ events. The table had the same amount of results. The results were listed in ...
by kdwsplunk Explorer in Splunk Search 02-27-2017
0 2
0
2
svercelli
I'm trying to select a specific custom time range within a search after selecting a larger time range with the time p...
by svercelli Path Finder in Splunk Search 02-27-2017
0 3
0
3
kamal_jagga
Hi, We have been using the stats latest(field) for quite sometime and it worked quite well. But for a new file, some...
by kamal_jagga Contributor in Splunk Search 02-27-2017
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...