Splunk Search

Splunk Search
Community Activity
Jason
I have some data that has been ingested quickly/badly, so there are multiple lines per event. Rather than reindex it,...
by Jason Motivator in Splunk Search 01-06-2017
0 1
0
1
TISKAR
Hey Splunkers: I indexed my data, and I worked quietly, but today I ran the same query, output is : "no results foun...
by TISKAR Builder in Splunk Search 01-06-2017
0 4
0
4
pradeep577
Hi, I'm new to Splunk area. We have integrated Splunk with ironports. I need to search number of history to a parti...
by pradeep577 Path Finder in Splunk Search 01-05-2017
0 2
0
2
alexandermunce
I am working with a set of transactions data where in each transaction could relate to any of our numerous systems/pr...
by alexandermunce Communicator in Splunk Search 01-05-2017
0 13
0
13
guna1390
I have a field here like total_time which has 100+ values (0.125,2.25,etc). I want the result like the field total_...
by guna1390 New Member in Splunk Search 01-05-2017
0 2
0
2
vrmandadi
Hello Experts, Below is the sample event event_type: LogMessage ip: xx.x.xx.xx job: router_z1 jo...
by vrmandadi Builder in Splunk Search 01-05-2017
0 7
0
7
Justin1224
Within a search I was given at work, this line was included in the search: estdc(Threat_Activity.threat_key) I found...
by Justin1224 Communicator in Splunk Search 01-05-2017
1 3
1
3
RayLio
Hello splunkfans, i'm kind of running out of ideas and this is my first contact to streamstats.  I am working on a ...
by RayLio New Member in Splunk Search 01-05-2017
0 3
0
3
franksteinar
Hi, I have one field with values for each month, and this eval gives me the current month name(current February); e...
by franksteinar New Member in Splunk Search 01-05-2017
0 8
0
8
daniel333
Hello, Is there a way to get a RSS or email notification when a new notable suppression is created or enabled in ES...
by daniel333 Builder in Splunk Search 01-05-2017
0 2
0
2
vchinnadurai
I am trying to extract fields from Oracle Diagnostic logs for Hyperion Essbase as each event will have values in diff...
by vchinnadurai New Member in Splunk Search 01-05-2017
0 6
0
6
Mathanjey
Can you help suggesting options to add commas to the calculated fields Example : chart count as TotalCnt, people OVE...
by Mathanjey Explorer in Splunk Search 01-05-2017
0 4
0
4
MonkeyK
I am trying to summarize network traffic to or from an IP address. I would like to look for daily patterns and thoug...
by MonkeyK Builder in Splunk Search 01-05-2017
0 6
0
6
DanielWick
I have multiple events that are related by a similar sessionID. One event contains an employerCode, which is what I w...
by DanielWick New Member in Splunk Search 01-05-2017
0 1
0
1
fisuser1
Looking to build a macro on an ugly search for some of our clients. Multiple clients use this same search, therefore...
by fisuser1 Contributor in Splunk Search 01-05-2017
0 2
0
2
smruti13
eval range=case( start_time=="ZERO_TIME","All Time", start_time!="ZERO_TIME" AND ctime - strptime(start_time, "%a %b...
by smruti13 Observer in Splunk Search 01-05-2017
0 4
0
4
mani2004_maddy
I need help on setting up the conditional search on my application logs for stop (Application Stopped) & start (Appli...
by mani2004_maddy New Member in Splunk Search 01-05-2017
0 3
0
3
JLIVE101
Similar to how timechart sum() by ip | addtotals which adds a "Totals" Column to a timechart, how can you add an aver...
by JLIVE101 Engager in Splunk Search 01-05-2017
0 2
0
2
sivapuvvada
I have upgraded my Splunk version to 6.5.1 from 6.4. After this, I observed the "search" command is not working. Is ...
by sivapuvvada Path Finder in Splunk Search 01-05-2017
0 5
0
5
kalyanilandge
Hi Team, I have data like below: \launching VM Initializing Wed 2017-01-04 02:22:48 Going-stop Wed ...
by kalyanilandge New Member in Splunk Search 01-05-2017
0 4
0
4
prajesh
I have tried using join to detect the common field from lookup but i need not find the fields that are not present us...
by prajesh New Member in Splunk Search 01-05-2017
0 1
0
1
the_wolverine
According to this blog post: http://blogs.splunk.com/2014/03/18/time-based-load-balancing/ Using this setting Splu...
by the_wolverine Champion in Splunk Search 01-05-2017
1 4
1
4
hemendralodhi
Hello, I have extracted field which contains application response time in below format. Format: 00:00:00.000 00:00...
by hemendralodhi Contributor in Splunk Search 01-05-2017
0 6
0
6
HeinzWaescher
Hi, in my searches I want to filter my events when the field "Version" has specific values. The list of values I wan...
by HeinzWaescher Motivator in Splunk Search 01-05-2017
3 5
3
5
antoniofacchi
Hi, for a SLA project, I'm using Splunk to read Nagios the availability status of some services. Using the condit...
by antoniofacchi New Member in Splunk Search 01-04-2017
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...