Splunk Search

Splunk Search
Community Activity
srinivasup
hi there, i would like to write a search to find out dashboard runtime. index=_internal source=*splunkd_ui_access....
by srinivasup Explorer in Splunk Search 02-08-2017
0 3
0
3
prateedshetty
The query I use is- sourcetype=iis URL_root=abc "https://www.abc.com"|stats dc(SessionId) as TotalVisits, dc(userid)...
by prateedshetty Path Finder in Splunk Search 02-08-2017
0 2
0
2
ibmrakesh
Hi All, I am new to the Splunk world and pls help me to explore. I have a product.csv files which contains 6 fields ...
by ibmrakesh Explorer in Splunk Search 02-08-2017
0 2
0
2
RiccardoV
Hi, I have a quite big csv file (~20Mb) and I changed the max_memtable_bytes to 100Mb in my limits.conf file. My sear...
by RiccardoV Communicator in Splunk Search 02-08-2017
2 4
2
4
srinathd
I have a field which have multilines, how to split this field delimited by timestamp into separate lines 2017/02/06 ...
by srinathd Contributor in Splunk Search 02-07-2017
0 3
0
3
Hung_Nguyen
I have a query where I need to break up the provided time range into 2 period so I can see the delta between the peri...
by Hung_Nguyen Path Finder in Splunk Search 02-07-2017
1 3
1
3
meduriphani
Hi, I am looking for any sample code in any language/script that shows an actual use case of dispatch.data_format fo...
by meduriphani New Member in Splunk Search 02-07-2017
0 2
0
2
SplotchySplunkS
I'm trying to make one search that will accomplish the following: Total Login Attempts: DC(USERID) WHERE ACTIVITY = ...
by SplotchySplunkS Engager in Splunk Search 02-07-2017
0 14
0
14
paramagurukarth
I am new to splunk... How to get List of realtime searches and the macro/savedSearch that runs on it? Is there any s...
by paramagurukarth Builder in Splunk Search 02-07-2017
0 6
0
6
lee_melvin
I want to group events describing backup job status with other events describing the volumes being backed up. The da...
by lee_melvin Path Finder in Splunk Search 02-07-2017
0 3
0
3
ajdyer2000
Hi I have a search with a field called "Apps". I would like to be able to remove the leading numeric values. I woul...
by ajdyer2000 Path Finder in Splunk Search 02-07-2017
0 6
0
6
arrowecssupport
We are using Splunk to alert when we see specific events in our logs. There are hundreds of different log events we m...
by arrowecssupport Communicator in Splunk Search 02-07-2017
0 3
0
3
ICAP_RND
When using transaction, SPLUNK always use _time of the 1st event I need to extract the time of the second event in a...
by ICAP_RND Engager in Splunk Search 02-07-2017
0 4
0
4
mbolostk
I know it's possible to put CIDR ip ranges in a lookup table. However, my question is, what if I do not have access ...
by mbolostk Explorer in Splunk Search 02-07-2017
3 1
3
1
burras
I'm attempting to develop a chart for one of my engineering teams that shows peak utilization across multiple sites o...
by burras Communicator in Splunk Search 02-07-2017
0 5
0
5
pkeller
Looking at the Daily License Usage panel on the "Previous 30 Days" tab under Licensing, I see that the base search is...
by pkeller Contributor in Splunk Search 02-07-2017
0 1
0
1
gsolomon11
I'm using the following search to generate the table below: rex "<status>(?<status>.*?)<"| search status=Incomplete ...
by gsolomon11 New Member in Splunk Search 02-07-2017
0 2
0
2
gowen
If I go into the License Manager, it shows me a simple progress bar of "Volume used today". For pool "auto generated...
by gowen Path Finder in Splunk Search 02-07-2017
2 11
2
11
pm771
I have a working query, but since this is the first time I used stats as a replacement for join / transaction so I wo...
by pm771 Communicator in Splunk Search 02-07-2017
0 7
0
7
sravankaripe
i want to find the difference b/w starttime and _time. "StartTime":"2017-02-03 09:51:54.595" (String) End...
by sravankaripe Communicator in Splunk Search 02-07-2017
0 4
0
4
prashanthberam
i have logs like this for each req..... 2016-11-09 12:57:18,855 CorrelationID=2469bae9-fe14-4e67-b345-95d652f4a868,...
by prashanthberam Explorer in Splunk Search 02-07-2017
0 2
0
2
kbarker302
My raw data looks like this: Timestamp Field1 Field2 Field3 2017-01-01 AAA Key1 Key1val 2017-01-...
by kbarker302 Communicator in Splunk Search 02-07-2017
0 2
0
2
rgsage
We are on Splunk 6.2.1. This is all in Splunk search... I have a macro with lookup which works fine in a simple sea...
by rgsage Path Finder in Splunk Search 02-07-2017
0 10
0
10
ruchigpt527
I tried this in eval expression for removing spaces... trim(SWFT_TRN) but it's not working fine..
by ruchigpt527 New Member in Splunk Search 02-07-2017
0 1
0
1
nairri
A reboot cured the above issue( In title), which is far from ideal. See the below lines logged in 'Splunkd.log' on t...
by nairri New Member in Splunk Search 02-07-2017
0 3
0
3
Get Updates on the Splunk Community!

Blueprints for High-Maturity Operations: Splunk Lantern Articles on SOAR, ES 8.4, ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...