Splunk Search

Splunk Search
Community Activity
TiagoTLD1
Hello I have a UF that will send the data to another UF. I want to send the data uncooked to the second UF, and only...
by TiagoTLD1 Communicator in Splunk Search 02-15-2017
0 2
0
2
ringbbg
can [if , then ] only be used inside of a search string (w/eval) ? im asking coz i have a dual drop down setup. The...
by ringbbg Engager in Splunk Search 02-15-2017
0 2
0
2
AkritiParida
I need to predict/forecast the actual cost which will be incurred in the future sprints depending upon the hourly cha...
by AkritiParida Engager in Splunk Search 02-15-2017
0 1
0
1
harsush
host=aa* | search env=CERT (job=AJOB OR job= BJOB OR job= CJOB ) | eval desired_time=strftime(_time, "%d/%m/%Y %I:%M:...
by harsush Path Finder in Splunk Search 02-15-2017
0 6
0
6
pradyprakhar
For example: action actual_action process user hostname Time Event 1: allowed Left alone ...
by pradyprakhar New Member in Splunk Search 02-15-2017
0 2
0
2
mcronkrite
Why do some splunk users say that the | pivot command isn't for ninjas? Which is better then, pivot, datamodel, tstat...
by mcronkrite Splunk Employee Splunk Employee in Splunk Search 02-15-2017
2 4
2
4
rhfiberlight
I have a search that works correctly when specific field values are entered but would like to create a report for the...
by rhfiberlight Engager in Splunk Search 02-15-2017
0 3
0
3
justinfranks
Hello Peoples.. I have this issue with a search, here is the search that I am performing. source="*playbackinit.log...
by justinfranks Path Finder in Splunk Search 02-15-2017
0 11
0
11
spammenot66
In Splunk, is there a way to format data that normally contains user, month-year, hits, clicks to display multiple v...
by spammenot66 Contributor in Splunk Search 02-15-2017
0 2
0
2
rodiers01
Good afternoon all I'm just looking for a search that will search for anyone that has logged in to a web site, from ...
by rodiers01 New Member in Splunk Search 02-15-2017
0 6
0
6
bcusick
Hi, I'm thinking this has a simple solution..Is there anyway to show a table in descending order by count? Currentl...
by bcusick Communicator in Splunk Search 02-15-2017
0 5
0
5
sravankaripe
Help me with Rex "keys":"values" "SSOUSERDATA":"INDV=12345678|ONE|testd44|ABCD,ABCD_ABCDABCD" "X-comGlobalSessionI...
by sravankaripe Communicator in Splunk Search 02-15-2017
0 5
0
5
aselios
Hello everyone!!! This is a search that I was used to setting up a report with acceleration. But in the Report Accel...
by aselios Engager in Splunk Search 02-15-2017
0 2
0
2
rbal_splunk
I am trying to figure out if the Splunk is sending Search Bundles very often and if these are full or delta?
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 02-15-2017
1 1
1
1
dbcase
Hi, I have the below log data. It appears to be all one line. What I'd like to do is: Have a separate event every...
by dbcase Motivator in Splunk Search 02-15-2017
0 4
0
4
dfenko
I have a data set that gives me an entry for each time a company runs a report in my system. I can easily put togethe...
by dfenko Explorer in Splunk Search 02-15-2017
0 2
0
2
kteng2024
Hi, How to calculate the truncate value ? is it calculated based on the log size and max_events ? if yes , can anyo...
by kteng2024 Path Finder in Splunk Search 02-15-2017
0 1
0
1
ajdyer2000
Hi I have a search that returns a field called "Administrators" Administrators \DomainAdmins \Backup Group \Eventl...
by ajdyer2000 Path Finder in Splunk Search 02-15-2017
0 8
0
8
rbal_splunk
My searches are failing with the following errors in splunkd.log. I have one Search Head and 26 indexers. In the Sear...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 02-15-2017
13 5
13
5
sravankaripe
i have two indexes i have Sid common in both i want to display Sid and Did in a table. Please help me with join con...
by sravankaripe Communicator in Splunk Search 02-15-2017
0 5
0
5
nburgess1
Hi, I have a field called "OrgCode" with data like "L6" "L9" "G6" "K6" "K4", which is departments L G and K. I nee...
by nburgess1 Explorer in Splunk Search 02-15-2017
0 4
0
4
sravankaripe
"sessionID":"ABCDFE-112451x55-3734-4601-82a9-7ab6c5151d85" "sessionID":"123456789012" "sessionID":"12dsfvvxv3" Pleas...
by sravankaripe Communicator in Splunk Search 02-15-2017
0 2
0
2
nivethainspire_
I need to write a rex command for the below log, Please help me out. log: xxx,xxx, D_Name="sag01 "TCC - QA - ORAA cv...
by nivethainspire_ Explorer in Splunk Search 02-15-2017
0 4
0
4
rsathish47
HI All, How to pass regular expression to the variable to match command? Please help.. in Following search qu...
by rsathish47 Contributor in Splunk Search 02-15-2017
0 3
0
3
giorgio_adami_m
I want to override the Host value at search time, not at index time because I need to override it just in the context...
by giorgio_adami_m Path Finder in Splunk Search 02-15-2017
2 6
2
6
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...