Splunk Search

Splunk Search
Community Activity
dellytaniasetia
Hi, I have a simple question, what is the difference between earliest=-15m with earliest=-15m@s? I could not find a...
by dellytaniasetia Explorer in Splunk Search 02-14-2017
0 1
0
1
mattbirk
So my data has, for example, code 001 for connected and 002 for disconnected. Also, each VPN session has a unique ses...
by mattbirk Explorer in Splunk Search 02-14-2017
1 5
1
5
murhammr
I'm having trouble converting a search string into a working regular expression in transforms.conf to send events to ...
by murhammr Path Finder in Splunk Search 02-14-2017
0 7
0
7
nravichandran
We are planning to for a F5 load-balancer to be placed in front of the search heads. For sizing, how can I find out t...
by nravichandran Communicator in Splunk Search 02-14-2017
0 2
0
2
fvegdom
When I use the following search (some criteria obfuscated for security): index=main sourcetype=transaction applicat...
by fvegdom Path Finder in Splunk Search 02-14-2017
1 19
1
19
brent_weaver
Good morning! I am having to parse out Bro log files and with the help of the forum I was more than successful at doi...
by brent_weaver Builder in Splunk Search 02-14-2017
0 3
0
3
jmaple
I'm working on creating a report to monitor VPN usage based on unique user per day. I was able to get the format I wa...
by jmaple Communicator in Splunk Search 02-14-2017
0 1
0
1
faustf
Hi guys I'm not an expert of Splunk. I was wondering if I can use a lookup to reference fields that are stored into ...
by faustf Communicator in Splunk Search 02-14-2017
0 1
0
1
chengyu
My raw data: Feb 7 18:18:23 impact 1 Gbps/137.54 Kpps, importance 2... Feb 7 18:18:23 impact 3600 Mbps/137.54 Kpps...
by chengyu Path Finder in Splunk Search 02-13-2017
0 5
0
5
raghav130593
I have a query where I am performing regex matching on two different fields, field1 and field2. index=proxylogs uri!=...
by raghav130593 Explorer in Splunk Search 02-13-2017
0 4
0
4
pradeep577
Hi All, I am planning to start learning about Splunk. I wanted to know the difference between Splunk and HP Arcsight...
by pradeep577 Path Finder in Splunk Search 02-13-2017
2 3
2
3
JRougeau
How can I show results for a field that is disabled and not re-enabled in a certain amount of time? I want to be ale...
by JRougeau Engager in Splunk Search 02-13-2017
0 1
0
1
ivanayala
I am trying to limit the number of results shown when I use the values command. Here is my search: index="mydata" e...
by ivanayala New Member in Splunk Search 02-13-2017
0 7
0
7
mpatel11
hi, looking to do a stats count something like below. Field1: A,B A B,A B,A,C A,C each row accounts for different...
by mpatel11 Explorer in Splunk Search 02-13-2017
0 2
0
2
sravankaripe
Please help me with rex i have key and value in json format {"context":{<!-- --> "sessionID":"1234567890", "eve...
by sravankaripe Communicator in Splunk Search 02-13-2017
0 14
0
14
Stevensmith529
Hello i have been trying to figure this out for days now. i have logs coming in from multiple sources that only dis...
by Stevensmith529 New Member in Splunk Search 02-13-2017
0 5
0
5
LANGLEYJ
I have a list of Hostnames in a CSV. There are 2 fields 1) cn (hostname) and 2) ComputerType. I would like to compare...
by LANGLEYJ New Member in Splunk Search 02-13-2017
0 1
0
1
sunitakesam
log file:testscripts.log Date &#61; 02/10/17 14:15:00,script &#61; testscript, id &#61; 29251, log&#61;Script started Date &#61; 02/10/1...
by sunitakesam New Member in Splunk Search 02-13-2017
0 6
0
6
msachdeva3
eval test_time &#61; time() - _time | search (test_time &gt; 1800 AND test_time &lt; 86400)| I'm trying to see if the events i...
by msachdeva3 Explorer in Splunk Search 02-13-2017
0 2
0
2
ssrdc
Hi all First search is ( host&#61;wjb2* NOT host&#61;wjb2stl22 NOT host&#61;wjb2*23 NOT host&#61;wjb2*24 NOT host&#61;wjb2*25 NOT ho...
by ssrdc New Member in Splunk Search 02-13-2017
0 1
0
1
clashley
I'll start with what works: If I do a search ERROR host&#61;"foobar0*" The wildcard(*) expands and I get a list of re...
by clashley Explorer in Splunk Search 02-13-2017
1 9
1
9
jplumsdaine22
Can a Splunk search tell you anything about love? Share your valentine's day searches here. Here's one to get you st...
by jplumsdaine22 Influencer in Splunk Search 02-13-2017
0 3
0
3
adamsmith47
I've recently installed the Tenable Nessus app, which is doing most of it's search-time field extractions using the "...
by adamsmith47 Communicator in Splunk Search 02-13-2017
0 3
0
3
hwakonwalk
I am very new to Splunk and have a requirement to show current values of multiple fields in a single table, my data g...
by hwakonwalk Path Finder in Splunk Search 02-13-2017
0 3
0
3
sureshbabu123
I have a scenario here. I have data in my local Splunk for time range from 6-Nov-2015 11:45 UTC to 10-Nov-2015 13:45...
by sureshbabu123 New Member in Splunk Search 02-13-2017
0 6
0
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...