Splunk Search

Splunk Search
Community Activity
HeinzWaescher
Hi, I'm calculating the calenderweek with this: | eval calenderweek=strftime(_time,"%Y-%V") For some reason for 2...
by HeinzWaescher Motivator in Splunk Search 01-04-2017
0 1
0
1
tomasmoser
Hi Team, I need to aggregate sequences of all consecutive events with a field Door=''Open" delimited with sequence o...
by tomasmoser Contributor in Splunk Search 01-04-2017
0 3
0
3
umsundar2015
Hi, My problem is "undefined" word is displayed when i opened in search bar. In turn it gives some random values as...
by umsundar2015 Path Finder in Splunk Search 01-04-2017
0 3
0
3
jturner900
I'm trying to swap the roles of two columns. Normally, there is one "key" in the first column for every group of "va...
by jturner900 Explorer in Splunk Search 01-03-2017
0 1
0
1
ynegoro
I'd like to get contents between fields. Here is a sample log. CheckPointCount=N/A,CheckPointRestart=no,CheckPointIn...
by ynegoro New Member in Splunk Search 01-03-2017
0 2
0
2
kbaden
Hi I am currently using transaction to generate a report on length of user session, which is working well. The next ...
by kbaden Explorer in Splunk Search 01-03-2017
0 2
0
2
chvnc
req_event_id field has values like: PL-ADMIN-11004.30A5748A69B1:AEECB6513 PL-ADMIN-11004.30A5748A69B1:AEEC909E6 PL-A...
by chvnc Explorer in Splunk Search 01-03-2017
0 3
0
3
HeinzWaescher
Hi, is it possible to extract key value pairs out of a multivalue field like this: multivaluefield: sales:100 ,refu...
by HeinzWaescher Motivator in Splunk Search 01-03-2017
0 6
0
6
HCadmins
eventtype=cv "Source Client"=* "Destination Client"=slc-p-res* OR dab* Duration=* | convert ctime(_time) | convert du...
by HCadmins Communicator in Splunk Search 01-03-2017
0 1
0
1
rajgowd1
Hi, I have a search which displays content in a table format. Here is the search and I would like to show them in sc...
by rajgowd1 Communicator in Splunk Search 01-03-2017
0 11
0
11
James_wang
Hi Support, Host, Key, Value A, Username, root A, Address, 1.1.1.1 A, Type, AIX B, Username, admin B, Address, 2.2.2...
by James_wang Engager in Splunk Search 01-03-2017
2 2
2
2
asarran
Hey Fellow Splunkers I would like to total multiple values for the same fields. field="Fruits" Within this field...
by asarran Path Finder in Splunk Search 01-03-2017
0 3
0
3
ankithreddy777
I have a xml message with multiple lines. How can we extract entire data into a field?
by ankithreddy777 Contributor in Splunk Search 01-03-2017
0 1
0
1
twinspop
I am an admin. People can share with me. But any time I share a search via the share widget on the search screen, the...
by twinspop Influencer in Splunk Search 01-03-2017
0 2
0
2
leo_wang
Hi, As. title. I know I could use "predict" command to predict the value of my data. But I have some data which are ...
by leo_wang Path Finder in Splunk Search 01-03-2017
0 1
0
1
maryang
Below is the my query: index=app splunk_server_group=CWE sourcetype=ELMTP99 host="CHE-elmAPP0" source="C:\TPles\ELMgF...
by maryang New Member in Splunk Search 01-03-2017
0 2
0
2
robjordan_boa
It's quite easy to report in splunk on what type of events you have but how to report on what types of events you don...
by robjordan_boa Explorer in Splunk Search 01-03-2017
0 10
0
10
AdixitSplunk
HI , I have this query where i want my data in a specific format . Here under each POD there are some 3-4 hosts ,who...
by AdixitSplunk Path Finder in Splunk Search 01-03-2017
0 3
0
3
gcusello
Hi at all, I'm using Splunk 6.5.1. I extracted eight fields from a sourcetype. I'm trying to show them in a table and...
by SplunkTrust SplunkTrust in Splunk Search 01-03-2017
0 5
0
5
tenorway
Hi there! I am trying to achieve the following: Detect users that are unwillingly logged out of my web site. If the...
by tenorway Path Finder in Splunk Search 01-03-2017
0 4
0
4
wbfoxii
Our administrator is trying to forward data from \Lotus\Domino\Data\IBM_TECHNICAL_SUPPORT\console.log using the Unive...
by wbfoxii Communicator in Splunk Search 01-03-2017
0 3
0
3
cheung_bea
So I currently have a csv table of users and click events related to purchases on an app. The table goes something li...
by cheung_bea Engager in Splunk Search 01-02-2017
0 2
0
2
avaishsplunk
Hello, a In my search query below, I am unable to set the value of stats count as 0 in case there are no events for t...
by avaishsplunk Path Finder in Splunk Search 01-02-2017
0 24
0
24
rajgowd1
HI, we have log which has some key value pairs and one of the key is instance which has values like 0,1,2 when ever t...
by rajgowd1 Communicator in Splunk Search 01-02-2017
0 4
0
4
rajkumar_2
Hi, This an output from a summary index. From this table, we need to filter based on which exception not occurred...
by rajkumar_2 New Member in Splunk Search 01-02-2017
0 9
0
9
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...