Splunk Search

Splunk Search
Community Activity
sujith0311
Hi all,I'm pretty new to splunk and having my hands on it. My question is , I have a index=sftp and user as some xyz....
by sujith0311 New Member in Splunk Search 02-09-2017
0 3
0
3
locose
The following searches work : | tstats `xxxx_summaries_only` avg(All_Performance.Memory.swap_free) AS swap_free FRO...
by locose Path Finder in Splunk Search 02-09-2017
0 7
0
7
sohrab
Hi I am wondering what percentile implementation does Splunk use (used by stats, etc.). It does not always return th...
by sohrab Explorer in Splunk Search 02-09-2017
4 4
4
4
AdixitSplunk
HI All, I need some help in setting alerts for a condition, where I'm using a simple Splunk search to get whether t...
by AdixitSplunk Path Finder in Splunk Search 02-09-2017
0 3
0
3
ankithreddy777
I have did index time extractions for fields. I have stored them in _meta. But when I search for the extracted fiel...
by ankithreddy777 Contributor in Splunk Search 02-08-2017
0 5
0
5
praveenbandi
number of lines from file is not matching in the count, want to check each events number of lines. ?
by praveenbandi Explorer in Splunk Search 02-08-2017
0 2
0
2
nawazns5038
index=* | stats values(source),values(sourcetype),count(sourcetype) by host ....query i used host values(s...
by nawazns5038 Builder in Splunk Search 02-08-2017
0 3
0
3
vzed
I'm trying to figure out a way to get the closest log record to a user input timestamp. I'm thinking about making a d...
by vzed Engager in Splunk Search 02-08-2017
0 8
0
8
dbcase
Hi, I'm trying to extract two fields from the below data 02-08 07:33:41.211 E/Rules_LightBaseAction( 2660): com.ico...
by dbcase Motivator in Splunk Search 02-08-2017
0 4
0
4
HeinzWaescher
Hi, my events can include a fieldname with a pattern like: product_type_a product_type_b product_type_c To group c...
by HeinzWaescher Motivator in Splunk Search 02-08-2017
0 7
0
7
anantdeshpande
index=idx_cibca__prod:- Has data from database having all fields but not CUST_NAME ie why we used join idx_cibca_look...
by anantdeshpande Path Finder in Splunk Search 02-08-2017
1 4
1
4
simin67rose
HI I want to know why this code is not working index="malecious_url" OR index="surikata" |fields http2,http | wh...
by simin67rose New Member in Splunk Search 02-08-2017
0 1
0
1
ash2l
How do I use a regular expression to extract all 22 entries of Message field with left boundry = "Messages": [ righ...
by ash2l Path Finder in Splunk Search 02-08-2017
0 6
0
6
arjangoos
Hi, I want to combine to searches: index=bla | stats count(al_responsecode) as "Total per responseCode al" by al_re...
by arjangoos Path Finder in Splunk Search 02-08-2017
0 1
0
1
maximusdm
hi there, the 1st and 3rd statement is wrong and the 2nd might be correct. Here is what I am trying to do: Current M...
by maximusdm Communicator in Splunk Search 02-08-2017
0 5
0
5
srinivasup
hi there, i would like to write a search to find out dashboard runtime. index=_internal source=*splunkd_ui_access....
by srinivasup Explorer in Splunk Search 02-08-2017
0 3
0
3
prateedshetty
The query I use is- sourcetype=iis URL_root=abc "https://www.abc.com"|stats dc(SessionId) as TotalVisits, dc(userid)...
by prateedshetty Path Finder in Splunk Search 02-08-2017
0 2
0
2
ibmrakesh
Hi All, I am new to the Splunk world and pls help me to explore. I have a product.csv files which contains 6 fields ...
by ibmrakesh Explorer in Splunk Search 02-08-2017
0 2
0
2
RiccardoV
Hi, I have a quite big csv file (~20Mb) and I changed the max_memtable_bytes to 100Mb in my limits.conf file. My sear...
by RiccardoV Communicator in Splunk Search 02-08-2017
2 4
2
4
srinathd
I have a field which have multilines, how to split this field delimited by timestamp into separate lines 2017/02/06 ...
by srinathd Contributor in Splunk Search 02-07-2017
0 3
0
3
Hung_Nguyen
I have a query where I need to break up the provided time range into 2 period so I can see the delta between the peri...
by Hung_Nguyen Path Finder in Splunk Search 02-07-2017
1 3
1
3
meduriphani
Hi, I am looking for any sample code in any language/script that shows an actual use case of dispatch.data_format fo...
by meduriphani New Member in Splunk Search 02-07-2017
0 2
0
2
SplotchySplunkS
I'm trying to make one search that will accomplish the following: Total Login Attempts: DC(USERID) WHERE ACTIVITY = ...
by SplotchySplunkS Engager in Splunk Search 02-07-2017
0 14
0
14
paramagurukarth
I am new to splunk... How to get List of realtime searches and the macro/savedSearch that runs on it? Is there any s...
by paramagurukarth Builder in Splunk Search 02-07-2017
0 6
0
6
lee_melvin
I want to group events describing backup job status with other events describing the volumes being backed up. The da...
by lee_melvin Path Finder in Splunk Search 02-07-2017
0 3
0
3
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...