Splunk Search

Splunk Search
Community Activity
kbarker302
My raw data looks like this: Timestamp Field1 Field2 Field3 2017-01-01 AAA Key1 Key1val 2017-01-...
by kbarker302 Communicator in Splunk Search 02-07-2017
0 2
0
2
rgsage
We are on Splunk 6.2.1. This is all in Splunk search... I have a macro with lookup which works fine in a simple sea...
by rgsage Path Finder in Splunk Search 02-07-2017
0 10
0
10
ruchigpt527
I tried this in eval expression for removing spaces... trim(SWFT_TRN) but it's not working fine..
by ruchigpt527 New Member in Splunk Search 02-07-2017
0 1
0
1
nairri
A reboot cured the above issue( In title), which is far from ideal. See the below lines logged in 'Splunkd.log' on t...
by nairri New Member in Splunk Search 02-07-2017
0 3
0
3
smcdonald20
I have a list of dates like below: 20170201 20171201 20171225 How can I convert this into a time value that i can s...
by smcdonald20 Path Finder in Splunk Search 02-07-2017
0 2
0
2
dkikan
Hi, I can find the top events but I want to see all those events that are contributing say 80% of the total. e.g. the...
by dkikan Engager in Splunk Search 02-07-2017
0 1
0
1
sundarrajan
Currently I am trying to find the max of field (which is already a sum of 2 different fields). The problem unfolds as...
by sundarrajan Path Finder in Splunk Search 02-07-2017
0 5
0
5
Shisa
Hi I'm looking for a sample search that calculates count of events which match within 500m radius of lat/long on loo...
by Shisa Explorer in Splunk Search 02-07-2017
0 2
0
2
doksu
Any plans to output ISO-3166 alpha codes from the iplocation command @arahut_splunk, or should we implement a maxmind...
by doksu Contributor in Splunk Search 02-06-2017
0 1
0
1
rbathla
I have close to 2000 URLs I want to search in one source. Is it possible to do it in one query by using lookup and wh...
by rbathla New Member in Splunk Search 02-06-2017
0 4
0
4
splunker1981
Hello all, At a loss trying to accomplish the following: I would like to compare three fields in the same index (te...
by splunker1981 Path Finder in Splunk Search 02-06-2017
0 3
0
3
dbcase
Hi, I have this work in progress query index=betats source="*top.csv" | dedup PREMISE_FK COMMAND PID | where COMMAN...
by dbcase Motivator in Splunk Search 02-06-2017
0 4
0
4
matthewb4
Lets say it is 2/6/17 at 2:18am and I have the following query... ... earliest=-1d@m | bin _time span =10m ... I w...
by matthewb4 Path Finder in Splunk Search 02-06-2017
0 2
0
2
mdelwaide
We recently onboarded some applications' logs, and at our client request, we had to put a custom field to have the ap...
by mdelwaide Path Finder in Splunk Search 02-06-2017
0 9
0
9
saikamaldidigam
I would like to show results group by "SLA Request Key". I am able to view sample Data-2 but not Sample Data-1 Samp...
by saikamaldidigam New Member in Splunk Search 02-06-2017
0 5
0
5
umsundar2015
Hi, I am using around 8 indexes to create a summary index. But after creating the summary index, i am seeing the dat...
by umsundar2015 Path Finder in Splunk Search 02-06-2017
0 3
0
3
burras
I'm attempting to build out a capacity chart that shows total elements used in a system and predicts the future count...
by burras Communicator in Splunk Search 02-06-2017
0 3
0
3
sravankaripe
please help me with rex i want to retrieve java.net.SocketTimeoutException: Read timed out from below _raw "msgConte...
by sravankaripe Communicator in Splunk Search 02-06-2017
0 9
0
9
kiran331
How to use tstats to show the last event and event time from 30 hosts (in lookup)? If I can't use tstats, is there an...
by kiran331 Builder in Splunk Search 02-06-2017
0 1
0
1
sravankaripe
Please help me with regular expression i want to extract a1234567 "INDV=1234566|RSPAR|a1234567|RSPAR"
by sravankaripe Communicator in Splunk Search 02-06-2017
0 3
0
3
lloydknight
Here's my search: base search | rex "^(?<field1>[^:]+):\|:(?<field2>[^:]+):\|:(?<field3>[^:]+):\|:" The logs are ...
by lloydknight Builder in Splunk Search 02-06-2017
0 3
0
3
jw44250
I want to know how can i create regular expressions for the following exceptions... java.io.IOException java.lang.E...
by jw44250 New Member in Splunk Search 02-06-2017
0 6
0
6
JeroenDenBoer
All, i've got a strange issue regarding lookup tables. ((and seen in two lookup tables now) I have a lookup table "s...
by JeroenDenBoer Explorer in Splunk Search 02-06-2017
0 2
0
2
guilpink
Hello Community, I have a strange behavior with a command when it is on the search field of a Dashboard. In my comm...
by guilpink New Member in Splunk Search 02-06-2017
0 2
0
2
cyphertek
Hello Splunk peoples! Would someone please help me figure out how to use timechart to find IIS time_taken by locatio...
by cyphertek Explorer in Splunk Search 02-05-2017
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...