Splunk Search

Splunk Search
Community Activity
westonaj1
Hi, assume I have the following type of data for pressure sensors in multiple sites. What we need to do (preferably ...
by westonaj1 Engager in Splunk Search 02-05-2017
0 4
0
4
scanxer1
am new to Splunk and have a very basic search that give output as below for vpn users.. User Group ASA_Device ...
by scanxer1 New Member in Splunk Search 02-05-2017
0 1
0
1
benazir
Hi , I have a sql query , Count distinct CHNL where MSG_NUM like 'cma%' group by MSG_TM. Result should get display ...
by benazir Explorer in Splunk Search 02-05-2017
1 3
1
3
Hung_Nguyen
My website has multiple widgets owned by various team and hosted on various CDN. I want to see the error rate by widg...
by Hung_Nguyen Path Finder in Splunk Search 02-04-2017
0 12
0
12
jward6004
How to use regular expression for an Exception message from a Source=Windows:Application to cut the beginning of the ...
by jward6004 Explorer in Splunk Search 02-03-2017
0 1
0
1
zeinstein
Expected result: I have a panel displaying a line chart, the user can access (without the "Edit" option) the pre-set ...
by zeinstein Path Finder in Splunk Search 02-03-2017
0 4
0
4
sujith0311
Hi all, I have a regular expression ^(.*)bytes read (?P\d+) written (?P\d+)$, where i edited the proper regular exp...
by sujith0311 New Member in Splunk Search 02-03-2017
0 5
0
5
rajgowd1
Hi, i am trying to display success,error and others with percentage in a table but application name is not displaying...
by rajgowd1 Communicator in Splunk Search 02-03-2017
0 4
0
4
kteng2024
I have enabled forceTimeBasedAutoLB on universal forwarder, but i want check whether that forwarder is making use of...
by kteng2024 Path Finder in Splunk Search 02-03-2017
0 1
0
1
lumpymilk
When extracting the request or cookie from httpd logs I'm having problems capturing an entire request when the reques...
by lumpymilk Explorer in Splunk Search 02-03-2017
0 5
0
5
demkic
Hi all, I am having trouble figuring out how to multiply the number of events by the values that are given in the f...
by demkic Explorer in Splunk Search 02-03-2017
0 3
0
3
jayj
Here is my query. sourcetype="access_combined" product_name=* action=purchase | chart count over product_name by act...
by jayj New Member in Splunk Search 02-03-2017
0 5
0
5
vijaykumartcs
There are c/d/e/f/p disk in servers, i want to set alert for the servers whose drive utilization is 60% and above.....
by vijaykumartcs Explorer in Splunk Search 02-03-2017
0 2
0
2
ktn01
Hello, I have to index only events that contains the string "$$log$$". I try with a transforms like [ignore] REGEX =...
by ktn01 Path Finder in Splunk Search 02-03-2017
0 2
0
2
karthikeyan_k14
In my field value are unstructured, few of the strings having space at beginning. Do anyone help, how to eliminate th...
by karthikeyan_k14 New Member in Splunk Search 02-03-2017
0 1
0
1
dcroteau
Has anyone know how to "decouple" or separate the ordering of a chart Legend with the actual chart? I've looked at "...
by dcroteau Splunk Employee Splunk Employee in Splunk Search 02-03-2017
0 4
0
4
rajgowd1
Hi, i am trying to implement visualization using flame graph, i was able to download flames code from git. can someo...
by rajgowd1 Communicator in Splunk Search 02-03-2017
1 1
1
1
dan_pudwell
I'm trying to determine whether a field has a value but my search isn't giving me expected results, I've tried this: ...
by dan_pudwell Explorer in Splunk Search 02-03-2017
0 3
0
3
snetuschil
Hi, I have a data that looks like this: ---------- *ID1 field1=value1&field2=value2&field3=value3* --------...
by snetuschil New Member in Splunk Search 02-03-2017
0 5
0
5
harshal_chakran
Hi, I have a sample dataset as follows: PROCCESS_NAME STATUS p1 PASS p2 PASS p3 PASS ...
by harshal_chakran Builder in Splunk Search 02-02-2017
0 4
0
4
ofgem_bird
I have a script that generates the time offset of a server from it's source, however, what I want to be able to do is...
by ofgem_bird Engager in Splunk Search 02-02-2017
0 1
0
1
medveleyenet1
My search throws empty time-related fields and I want to fill that compo with the current time
by medveleyenet1 New Member in Splunk Search 02-02-2017
0 1
0
1
MonkeyK
I have a lookup table with IP address indicators that I would like to be alerted on whether the IP address is the sou...
by MonkeyK Builder in Splunk Search 02-02-2017
1 8
1
8
maximusdm
hello, I need to extract the strings between both pipes " | | ", for instance, here are a few sample strings: (someti...
by maximusdm Communicator in Splunk Search 02-02-2017
0 10
0
10
ankithreddy777
Hi, below is the stanza in transforms.conf. [rfc5424_header] REGEX = <(\d+)>\d{1}\s{1}\S+\s{1}\S+\s{1}(\S+)\s{1}...
by ankithreddy777 Contributor in Splunk Search 02-02-2017
0 1
0
1
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...
Top Solution Authors